ISSUE DATE: 02/2020
CHANGE TO COOKIE SETTINGS
Personal data is understood as information that can be used to identify a person, i.e. information that can be traced back to a specific person. This typically includes name, E-mail address or telephone number. In addition, purely technical data that can be assigned to a person is also considered as personal data.
Kettler Alu-Rad GmbH
Longericher Straße 2
50739 Köln, Germany
Tel.: +49 (0) 6805 / 6008 3000
Data protection officer contact details
Our data protection officer can be contacted as follows:
ED Computer & Design GmbH & Co. KG
51149 Köln, Germany
Tel.: +49 (0) 221 28 88 77 66
You have the right to request information about the personal data stored about you free of charge (provided that no new circumstances have arisen, we may charge a fee from the second information request within 12 months). You also have the right to rectify incorrect data, restrict the processing of data that is too extensive or has been incorrectly processed and delete personal data that has been unlawfully processed or stored for too long (insofar as this does not conflict with any legal requirement to retain data and there are no other reasons in accordance with Art. 17 Para. 3 of the GDPR). You also have the right to transfer all data you have provided to us in a standard file format (right to data portability).
If you have the right to object to individual procedures, we will specify this within the description thereof.
To exercise your rights, please send an E-mail to firstname.lastname@example.org
You also have the right to complain to our supervisory authority. This is the North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information. For more information, please visit https://www.ldi.nrw.de.
Voluntary provision of data
SSL or TLS encryption
For security reasons and to protect the transfer of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses an SSL or TLS encryption. You can recognise an encrypted connection through a change from "http://" to "https://" and the padlock symbol in the browser address bar.
If SSL or TLS encryption is activated, data you transfer to us cannot be read by third parties.
General information about cookies
Cookies are small text files which are stored on your end device by the browser when you visit our website. This enables individual services of a website to "recognise" you and "remember" the settings you have made. On the one hand, this serves the user-friendliness of websites and thus the users (e.g. saving login data). On the other hand, cookies are used to collect statistical data on website usage and use the obtained data for analysis and advertising purposes.
Cookies are also used to store information on how the website is displayed when you visit our website, such as your preferred language or region. If the information of a settings cookie is lost, the website may become more difficult to use, but usually does not lead to failure. Most users' browsers have a settings cookie. Your browser sends this cookie to our website with requests. The settings cookie in your browser may save your settings and other information, especially your preferred language (e.g. English) and the country version.
Some cookies are automatically deleted from your end device as soon as you leave the website (so-called session cookie). Other cookies are stored for a specific period, which is never more than two years (persistent cookies). We also use so-called third-party cookies, which are managed by third parties in order to offer or use certain services.
You can manage how cookies are used. Most browsers have an option to restrict or completely prevent the storage of cookies. However, it should be noted that without cookies, the use and especially the ease of use are restricted.
Personal data is processed on this website as part of the following procedures:
Ordering goods and services
Profiling and scoring
Server log files
Google Maps API
Cookies for improving user-friendliness
- Ordering goods and services
If you want to order or book something via our website, you will be asked to enter some personal details. Required details include your title, first name, surname, street, postcode and city, billing address (street, house number, postcode, city, region), payment details, telephone number and E-mail address. These details are obligatory in order to enable us to carry out the contract with you.
As part of order or booking execution, we pass on your personal data to our logistics service providers, IT service providers and the specialist dealers responsible for carrying out your order, in addition to payment service providers or your bank in order to execute the contract with you.
The account details and order information are processed in accordance with Art. 6 Para. 1 lit. b of the GDPR. This authorisation allows the processing of personal data for the purpose of contract fulfilment.
Duration of data storage
The personal data stored when ordering goods is deleted when you have received the goods and the warranty period has expired. This period is usually two years and commences with the delivery of the item. For tax reasons, we are also legally obliged to store transaction-related data for ten years.
We use the E-mail address you specify to send you the newsletter and other information relevant to your interests, providing you have given your consent.
This data is processed based on your consent given when you registered for the newsletter. In accordance with Art. 6 Para. 1 lit. a of the GDPR, data processing is allowed if you have given your consent thereto for one or more specific purposes. When requesting the newsletter, you gave the following declaration of consent:
- □ I agree to the use of my contact details for advertising purposes for bicycle-related services and products. For this purpose, my data will also be forwarded to ZEG Zweirad-Einkaufs-Genossenschaft eG, Longericher Straße 2, 50739 Köln, Germany, data protection officer email@example.com. In future, I would like to receive information and advice on these new offers and services by post, E-mail, telephone or SMS. My data will only be transferred to others for the purposes of order data processing. I am aware that the collection, processing and use of my data is voluntary.
I can revoke this consent at any time with future effect without any negative consequences for me. To do this, simply send an E-mail to: firstname.lastname@example.org. In the event of revocation, my data will be deleted when my declaration of revocation is received.
Duration of data storage
The personal data stored as part of a newsletter subscription is deleted when you successfully unsubscribe from the newsletter.
When you contact us (for example by E-mail or through the use of our contact forms), the information you provide will be processed for the purpose of processing the enquiry and for any follow-up questions that arise.
Any information provided when contacting us is processed based on Art. 6 Para. 1 lit a and lit. f of the GDPR. This authorisation allows the processing of personal data on the basis of your consent and within the framework of the "legitimate interest" of the data controller, unless outweighed by your fundamental rights, freedoms or interests. Our legitimate interest lies in processing the contact. You can object to this data processing at any time if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: email@example.com.
Duration of data storageThe personal data stored through your contact with us will be deleted once the reason for contact has been completely resolved and the specific instance of contact is not expected to be relevant in the future.
- Profiling und scoring
We process your data from your order together with data that we have obtained from browsing or other sources in order to develop offers for you that are tailored to your interests and to evaluate and assess our own services ("profiling"). In individual cases, we also use the data available to us (e.g. via credit agencies), to calculate the probability of a customer fulfilling their payment obligations ("scoring"). The scoring includes data on aspects such as employment, occupation, employer experience from previous business relationships or credit reports. The scoring is based on recognised mathematical and statistical calculation processes. The values determined this way help us with risk management and decision-making when concluding contracts.
As part of the processing, the recipient groups specified in section 1 will receive your data. Our payment service providers also carry out scoring in individual cases.Legal basis
The legal basis for the processing of this data is Art. 6 Para. 1 lit f. of the GDPR. This authorisation allows the use of personal data within the framework of the "legitimate interest" of the data controller, unless outweighed by your fundamental rights, freedoms or interests. Our legitimate interest lies in the improvement of our services as well as risk management and prevention. You can object to this data processing if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: firstname.lastname@example.org.
Duration of data storageWe delete your data when it is no longer required to process the contract (scoring) or is no longer required for our performance improvement; in the latter case, however, whenever you have exercised your right to object.
- Server log files
Each time the website is accessed, we automatically collect a series of technical data that constitutes personal data.
- User's IP address
- Name of website or file accessed
- Date and time of access
- Amount of data transferred
- Notification of successful retrieval
- Browser type and version
- User's operating system
- User's end device, including MAC address
- Referrer URL (the previously visited page)
This data will not be merged with any other personal data that you actively provide on the website. Server log files are collected for the purpose of managing the website and identifying and preventing unauthorised access.
The personal data in log files is processed in accordance with Art. 6 Para. 1 lit. f of the GDPR. This authorisation allows the processing of personal data within the framework of the "legitimate interest" of the data controller, unless outweighed by your fundamental rights, freedoms or interests. Our legitimate interest lies in simpler administration and the possibility to detect and trace hacking. You can object to this data processing at any time if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: email@example.com.
What are IP addresses?
IP addresses are assigned to every device that is connected to the Internet (e.g. smartphone, tablet, PC). The specific IP address depends on the Internet access via which your device is currently connected to the Internet. This can be the IP address assigned to you by our Internet provider, for instance when you are connected to the Internet via WLAN at home. However, it can also be an IP address assigned by your mobile network provider or the IP address of a provider of a public or private WLAN connection or other type of Internet access. In its most common current form (IPv6), IP addresses consist of four blocks of digits. In most cases, as a private user you will not use a constant IP address, as this is only assigned to you temporarily by your provider (so-called "dynamic IP address"). With a permanently assigned IP address (so-called "static IP address"), it is easier to clearly assign user data. Except for the purpose of tracking unauthorised access to our website, we do not use this data in relation to specific persons, and only evaluate on an anonymous basis which of our websites are preferred, how frequently they are accessed every day and similar.
Our website already supports the new IPv6 addresses. If you already have an IPv6 address, you should be aware of the following:
The IPv6 address consists of eight blocks of four. Like the entire IPv4 address, the first four blocks are typically dynamically assigned for private users. However, the last four blocks of an IPv6 address (the so-called "interface identifier") are determined by the end device, which you use to browse the website. Unless otherwise configured by your operating system, the so-called MAC address is used for this. The MAC address is a kind of serial number, which is assigned once for each IP-enabled device worldwide. Therefore, we do not save the last four blocks of your IPv6 address. In general, we recommend that you activate the so-called "privacy extensions" in order to improve the anonymisation of the last four blocks of your IPv6 address. Most common operating systems have a "privacy extensions" function, although in some cases it is not set in the factory defaults.
Duration of data storageThe server log files with the aforementioned data are automatically deleted after 2 years at the latest. We reserve the right to save the server log files for a longer period if facts exist that suggest that unauthorised access has taken place (such as a hacking attempt or a so-called DDOS attack).
- Google Analytics
This website uses Google Analytics, a web analysis service by Google Inc. ("Google"). Google Analytics sets several "cookies" to identify your browser.
The information generated by the cookies about your use of this website is usually transmitted to a Google server in the USA and stored there. However, we have activated the IP anonymisation function on this website so that your IP address is shortened beforehand by Google within member states of the European Union or in other contracting parties of the Agreement on the European Economic Area. For more information on the implementation of this function, please visit:
https://developers.google.com/analytics/devguides/collection/analyticsjs/ip-anonymization. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and Internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
The processing of personal data by Google Analytics is based on Art. 6 Para. 1 lit. f of the GDPR. This authorisation allows the processing of personal data within the framework of the "legitimate interest" of the data controller, unless outweighed by your fundamental rights, freedoms or interests. Our legitimate interest lies in the analysis of the use of our website. You can prevent the transmission of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available via the following link: http://tools.google.com/dlpage/gaoptout?hl=de. You can still object to this data processing at any time if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: firstname.lastname@example.org.
Duration of data storage
The personal reference is immediately prevented by the partial deletion of the IP addresses, meaning that only statistical data is stored.
- Google Maps API
This website uses the Google Maps service via an API. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the functions of Google Maps, it is necessary to save your IP address. This information will generally be transmitted to a Google server in the USA and saved there. The provider of this website has no influence on this data transfer.Legal basis
The processing of personal data by Google Maps API is based on Art. 6 Para. 1 lit. f of the GDPR. This authorisation allows the processing of personal data within the framework of the "legitimate interest" of the data controller, unless outweighed by your fundamental rights, freedoms or interests. Our legitimate interest lies in the improvement of our website and offer by showing where we can be reached. For more information on data processing by Google, please visit https://policies.google.com/privacy?hl=de. You can also change your personal settings there. You can still object to this data processing at any time if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: email@example.com.
Duration of data storageThe personal reference is immediately prevented by the partial deletion of the IP addresses, meaning that only statistical data is stored.
- Cookies and plug-ins to improve user-friendliness
To do this, we use the following cookies:
- There is an opt-out option at https://policies.google.com/technologies/ads?hl=de.
b) The Google Tag Manager uses small code elements to measure traffic and visitor behaviour, record the impact of online advertising and social channels, use remarketing and targeting, and to test and optimise the website. These code elements are used by our agencies on a pseudonymous basis to display advertising.
- There is an opt-out option at https://policies.google.com/technologies/ads?hl=de.
The aforementioned cookies are saved in accordance with Art. 6 Para. 1 lit. f of the GDPR. In all cases, the data is pseudonymous and enables statistical classification into a specific user group (e.g. gender, age, place of residence or profession). No personal reference is made and we do not use a comprehensive advertising network. You can still object to this data processing at any time if justified by your specific circumstances that argue against data processing. To do this, simply send an E-mail to: firstname.lastname@example.org.
Duration of data storage
The data will be deleted after 2 years at the latest
Data processing through social networks
We maintain publicly accessible profiles on social networks. The social networks we use are listed below.
Social networks like Facebook, Google+, etc. may carry out a comprehensive analysis of your user behaviour if you visit their website or another website with integrated social media content (such as Like buttons or ad banners). Visiting our social media presence triggers numerous data privacy-related processes. In specific:
With the help of data collected this way, the operators of the social media channels can create user profiles that store your preferences and interests. This enables interest-related advertising to be shown to you both inside and outside the respective social media platform. If you have an account on the respective social network, the interest-based advertising can be displayed on all devices on which you are logged in.
Legal basisOur social media presences aim to ensure that we have the widest possible representation on the Internet. This is our legitimate interest in accordance with Art. 6 Para. 1 lit. f of the GDPR. The analysis processes initiated by social networks may have different legal bases, which must be specified by the operators of the social networks (e.g. consent as defined in Art. 6 Para. 1 lit a. of the GDPR).
Data controller and assertion of rights
If you visit one of our social media profiles (e.g. Facebook), we are jointly responsible together with the operator of the social media platform for all data processing operations triggered during your visit. You may exercise your rights (of information, correction, deletion, restriction of processing, data portability and complaint) both against us and the operator of the corresponding social media platform (e.g. Facebook).
Please note that despite the shared responsibility with social media platform operators, we do not have full influence over the data processing done by social media platforms. Our scope is largely based on the company policy of the corresponding provider.
Duration of data storage
The data collected directly by us via our social media profile will be deleted from our systems as soon as the purpose for their storage no longer applies or you request its deletion or revoke your consent to storage. Saved cookies will remain on your device until your delete them. Mandatory statutory provisions, especially regarding retention periods, remain unaffected.
List of social networks
We have a profile on Facebook. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, collected data will also be transferred to the USA and other third countries.
We have concluded an agreement with Facebook on joint processing (controller addendum). This agreement stipulates which data processing we or Facebook are responsible for when you visit our Facebook profile. You can view this agreement via the following link https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings yourself in your user account. To do this, click on the following link and log in: https://www.facebook.com/settings?tab=ads.