Privacy Policy
1. Definitions
The following terms, which we use in our Privacy Policy, are defined in Article 4 of the GDPR. This is only an excerpt from Article 4 of the GDPR. You can view all definitions in the GDPR (available here).
Personal Data (Article 4(1) of the GDPR)
Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing (Art. 4(2) GDPR)
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure; the alignment or combination; the restriction, erasure, or destruction.
Pseudonymization (Art. 4(5) GDPR)
Pseudonymization involves the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures that ensure the personal data is not attributed to an identified or identifiable natural person.
Controller (Art. 4(7) GDPR)
The controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States.
A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Third Party (Art. 4(10) GDPR)
A third party is a natural or legal person, public authority, agency, or other body, other than the data subject, the controller, the processor, and the persons authorized to process the personal data under the direct responsibility of the controller or the processor.
Consent (Art. 4(11) GDPR)
Consent of the data subject means any freely given, specific, in an informed and unambiguous manner, in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.
Company (Art. 4(18) GDPR)
An “enterprise” means a natural or legal person engaged in an economic activity, regardless of its legal form, including associations or partnerships that regularly engage in an economic activity.
2. Controller pursuant to Art. 4(7) of the GDPR
WIGO-Zelte GmbH & Co. KG
Industriestraße 35-37
37235 Hessisch Lichtenau
Phone: 05602 91 73 8 – 0
Fax: 05602 91 73 8 – 36
E-Mail:info@wigo-zelte.de
You can view our complete legal notice here:
https://wigo-zelte.de/impressum/
3. Data Protection Officer
Heinz Walter
Management Consulting
Rothe Lache 3
63457 Hanau
Phone: 06181/9069987
Fax: 06181/5790746
Cell: 0171/8022910
You can contact our Data Protection Officer at the following email address: walter-eschwege@t-online.de
4. Legal Basis for Processing
For each processing activity described in our Privacy Policy, we will inform you of the corresponding legal basis on which the processing is carried out. Processing is considered lawful in the following cases:
You have given us your consent to process your personal data for one or more specific purposes (Art. 6(1)(a) GDPR).
There is a contract between you and us, and the processing is necessary for the performance of that contract, or the processing is necessary for the implementation of precontractual measures taken at your request (Art. 6(1), first sentence, lit. b GDPR).
Processing is necessary for compliance with a legal obligation to which we are subject (Art. 6(1), first sentence, lit. c GDPR).
The protection of your vital interests or those of another natural person requires processing (Art. 6(1), first sentence, lit. d GDPR).
The performance of a task carried out in the public interest or the exercise of official authority entrusted to us requires processing (Art. 6(1), sentence 1, lit. e GDPR).
Processing is necessary to protect our legitimate interests or those of a third party, unless your interests or fundamental rights and freedoms that require the protection of personal data override those interests (Art. 6(1), first sentence, lit. f GDPR).
5. Data Retention / Data Deletion
Within the scope of the processing activities described in our Privacy Policy, we will inform you of the corresponding retention period or the time at which data will be deleted or blocked. If no explicit retention period is specified, the data will be deleted or blocked as soon as the purpose or legal basis for its storage no longer applies.
Data may be retained beyond the defined periods if legal provisions to which we are subject (e.g., Section 147 of the German Fiscal Code (AO), Section 247 of the German Commercial Code (HGB)) provide for a different retention period.
At the end of the retention period, the personal data will be deleted or blocked, unless further storage is required by us based on a legal basis. In addition, storage beyond the specified period is possible in the event of a (potential) legal dispute with you or other legal proceedings.
6. Disclosure of Personal Data
If your personal data is disclosed, you will be informed accordingly in the relevant section of our Privacy Policy. If your personal data is transferred outside the European Economic Area and thus to so-called third countries, you will be informed accordingly in the relevant section of our Privacy Policy. As a general rule, we only transfer personal data to third countries where an adequate level of protection has been confirmed by the European Commission or where we can ensure that the personal data will be handled with due care based on contractual agreements or other appropriate safeguards.
7. Collection of Personal Data
Below, we will inform you about the collection of personal data (such as name, email address, mailing address, or user behavior).
7.1. Use of Our Website for Informational Purposes Only
If you neither register on our website (for example, by subscribing to a newsletter) nor otherwise provide us with data (for example, by using a contact form), we collect only the personal data transmitted from your browser to our server. This data is technically necessary for us to make the website available to you while ensuring a secure and stable display. It consists of the following information, which is derived from a log file entry:
Internet Protocol address (IP address)
Time and date of the respective access
Time zone difference from Greenwich Mean Time (GMT)
The specific page accessed
Access status / Hypertext Transfer Protocol (HTTP)
Amount of data transferred
Website from which our website was accessed (referrer URL)
Internet browser used (including language and version)
Operating system used
The legal basis for collecting the listed data is Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring error-free connection establishment and convenient use of our website, as well as in analyzing system stability and security and using the data for other administrative purposes.
7.2. Contact via Email
When you contact us via the email address provided in Section 2 or other email addresses of our company published on our website, we will store your email address as well as any other contact information contained in your email (e.g., your name or phone number) will be stored by us to process your inquiry. This data will be deleted immediately as soon as further storage is no longer necessary. If there are statutory retention periods regarding the data, the data will be subject to an appropriate restriction on processing rather than deletion. The legal basis for processing the data depends on the reason for sending the email and is derived from Article 6(1)(b) of the GDPR or Article 6(1)(f) of the GDPR; meaning it is either carried out to fulfill the contract concluded with you and to meet our (pre)contractual obligations, or is based on our legitimate interest in contacting prospective customers of our service.
7.3. Contact Form – Product Inquiries
When you contact us via the “Product Questions” contact form available on our website, we store and process the contact information you provide in order to handle your inquiry. Depending on the reason for contacting us, the legal basis for processing the data is either Article 6(1)(b) of the GDPR or Article 6(1)(f) of the GDPR; meaning it is done either to fulfill the contract concluded with you and to meet our (pre)contractual obligations, or it is based on our legitimate interest in contacting prospective customers of our services/products.
8. Cookies
We use cookies on our website. Cookies are small, browser-specific text files that are stored on your hard drive. This allows the entity that sets the respective cookie to receive certain information; however, it does not enable programs to be executed or viruses to be transmitted. Cookies are divided into the following categories:
First, they are distinguished based on who set the respective cookie (website operators in the form of first-party cookies or third parties in the form of third-party cookies).
Then there is a distinction based on the duration of storage.
There are transient cookies that are automatically deleted when you close your browser; this primarily applies to so-called session cookies, which store a session ID. These session cookies allow your computer to be recognized if you visit our website again using the same browser during the same session. When you close the browser or log out, these temporary cookies are deleted.
In addition, there are so-called persistent cookies, which are stored for a longer period (up to two years). However, the period until deletion varies from cookie to cookie. You can manually delete these cookies at any time via your browser settings.
Another group consists of so-called Flash cookies. These are cookies tied to the Flash Player that store the technical data required to play video or audio content (e.g., image quality or network speed), , and typically do not have an automatic expiration date; instead, they store the necessary data regardless of the browser used. Some browsers (e.g., Firefox) allow you to delete Flash cookies along with other cookies.
Furthermore, cookies are classified based on their function, which is most relevant from a data protection perspective.
Technical (essential) cookies are cookies that are necessary to perform basic functions of the website (e.g., saving a product that has been added to the shopping cart).
Performance cookies collect information about website usage and any errors that occur. This is anonymous information used to improve the website.
Advertising cookies or targeting cookies make it possible to display personalized advertisements (including those from third-party providers) to website users and to measure the effectiveness of these ads.
Sharing cookies connect the website to other services (e.g., social media platforms).
We automatically use only technical cookies—that is, cookies that are essential for the operation of our website—based on our legitimate interest within the meaning of Article 6(1)(f) of the GDPR, in order to design our website effectively and continuously improve it.
Please note that you can prevent cookies from being stored at any time by adjusting your browser settings accordingly. We have compiled further information regarding the most common browsers below; however, please note that this may limit the functionality of our website.
Mozilla Firefox: https://support.mozilla.org/de/kb/verbesserter-schutz-aktivitatenverfolgung-desktop
Microsoft Edge: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Google Chrome: https://support.google.com/chrome/answer/95647
Opera: https://help.opera.com/de/latest/web-preferences/#cookies
Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
9. Matomo (Web Tracking)
Matomo
This website uses the open-source web analytics service Matomo.
With the help of Matomo, we are able to collect and analyze data about how visitors use our website. This allows us, among other things, to determine when specific pages were viewed and from which region the visitors are coming. In addition, we collect various log files (e.g., IP address, referrer, browsers and operating systems used) and can measure whether our website visitors perform certain actions (e.g., clicks, purchases, etc.).
The use of this analytics tool is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, to the extent that the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
IP Anonymization
We use IP anonymization when analyzing data with Matomo. In this process, your IP address is truncated before analysis so that it can no longer be uniquely associated with you.
Cookie-Free Analysis
We have configured Matomo so that it does not store any cookies in your browser.
Hosting
We host Matomo with the following third-party provider:
Panzer Design GmbH
Kemnather Str. 12b
92681 Erbendorf
Data Processing
We have entered into a data processing agreement (DPA) with the provider listed above. This is a contract required by data protection law that ensures the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
10. Google Maps
We integrate Google Maps into our website using the Google API (the acronym API stands for Application Programming Interface). This is a programming interface that enables us to integrate third-party services into our website. You can access the privacy policy for the Google API service here: Vhttps://developers.google.com/terms/api-services-user-data-policy
We use Google Maps only if you have given us your explicit consent to do so via our consent tool (Art. 49(1)(a) GDPR). With your consent, your data will then be transferred to the United States and thus to a non-adequate third country. There is currently neither an EU adequacy decision for the United States nor any other suitable safeguards in place. The protection of your data cannot be guaranteed in the United States. The United States does not currently have a level of data protection equivalent to that of the EU. Therefore, the transfer involves corresponding risks. In particular, there are no guarantees that government agencies will not access your transferred data. For example, it cannot be ruled out that U.S. authorities may access your data based on Section 702 of the Foreign Intelligence Surveillance Act (FISA for short; roughly translated as the “Foreign Intelligence Surveillance Act,” a law governing foreign intelligence and counterintelligence in the United States) may access your data.
In this context, we expressly draw your attention to the fact that, as an EU citizen, you have no effective legal recourse against the processing of your data by U.S. authorities under FISA. If you give your consent, you do so with full knowledge of these risks, which you thereby consciously accept. You may revoke your consent at any time by clicking the “Revoke / Change Privacy Settings” button located in the footer of our website.
This is an interactive map service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal notice: https://www.google.de/intl/de/contact/impressum.html. The parent company of this Ireland-based entity is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”). Google’s privacy policy can be accessed here: https://policies.google.com/privacy?hl=deWennWhen you visit a subpage on which Google Maps is embedded, Google receives information about this visit, and the personal data specified in this Privacy Policy is transmitted to Google even if you are merely using the website for informational purposes. This transfer serves to create a user profile by Google and occurs regardless of whether you have a Google account. However, if you have an account and are logged into it when you visit a subpage that incorporates Google Maps, this data will be associated with your account. Google stores this data and uses it for advertising and/or market research purposes, such as delivering targeted advertising.
11. Instagram Feed
We embed posts from our Instagram profile on our website. Instagram is a social network operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; legal notice: https://www.facebook.com/terms. The privacy policy can be accessed here: https://www.facebook.com/about/privacy. The parent company of this Ireland-based entity is: Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. When you visit a page that includes Instagram posts, the personal data specified in this privacy policy is transmitted to Facebook (and thus, if applicable, to an unsecured third country) if you are using the website for informational purposes only.
We use Instagram only if you have given us your explicit consent to do so via our consent tool (Art. 49(1)(a) GDPR). With your consent, your data will then be transferred to the United States and thus to a non-adequate third country. There is currently neither an EU adequacy decision nor any other suitable safeguards in place for the United States. The protection of your data cannot be guaranteed in the United States. The United States does not currently have a level of data protection equivalent to that of the EU. Therefore, the transfer involves corresponding risks. In particular, there are no guarantees regarding the prevention of access to your transferred data by government agencies. For example, it cannot be ruled out that U.S. authorities may access your data based on Section 702 of the Foreign Intelligence Surveillance Act (FISA for short; roughly translated as the “Foreign Intelligence Surveillance Act,” a law governing foreign intelligence and counterintelligence in the United States) may access your data. In this context, we expressly draw your attention to the fact that, as an EU citizen, you have no effective legal recourse against the processing of your data by U.S. authorities under FISA. If you give your consent, you do so with full knowledge of these risks, which you thereby consciously accept. You may revoke your consent at any time by clicking the “Revoke / Change Privacy Settings” button located in the footer of our website.
12. YouTube
We embed YouTube videos on our website. YouTube is a video portal operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal notice: https://www.google.de/intl/de/contact/impressum.html. The parent company of this Ireland-based entity is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”). Google’s privacy policy can be accessed here: https://policies.google.com/privacy?hl=de.
We have implemented the videos in “enhanced privacy mode,” which ensures that data is not transferred to the U.S.—and thus to an unsafe third country—until you begin playing the video. When you visit a subpage that contains a YouTube video and play it, Google receives information about this visit, and the personal data specified in this privacy policy is transferred to Google (and thus, if applicable, to a non-EU country) even if you are merely browsing the website. This transfer serves to create a user profile by Google and occurs regardless of whether you have a Google account. However, if you have an account and are logged into it when accessing a subpage that contains an embedded YouTube video, this data is associated with your account. This data is stored by Google and used for advertising and/or market research purposes, such as the delivery of tailored advertising. Regarding data storage, please refer to Google’s policy, available at: https://policies.google.com/technologies/retention?hl=de.
We use YouTube only if you have given us your explicit consent to do so via our consent tool (Art. 49(1)(a) GDPR). With your consent, your data will then be transferred to the United States and thus to a non-adequate third country. There is currently neither an EU adequacy decision for the United States nor any other suitable safeguards. The protection of your data cannot be guaranteed in the United States. The United States does not currently have a level of data protection equivalent to that of the EU. Therefore, the transfer involves corresponding risks. In particular, there are no guarantees that government agencies will not access your transferred data. For example, it cannot be ruled out that U.S. authorities may access your data under Section 702 of the Foreign Intelligence Surveillance Act (FISA for short; roughly translated as the “Foreign Intelligence Surveillance Act,” a law governing foreign intelligence and counterintelligence in the United States) may access your data.
In this context, we expressly draw your attention to the fact that, as an EU citizen, you have no effective legal recourse against the processing of your data by U.S. authorities based on FISA. If you give your consent, you do so with full knowledge of these risks, which you thereby consciously accept. You may revoke your consent at any time by clicking the “Revoke / Change Privacy Settings” button located in the footer of our website.
13. Hosting
Our website is hosted by HB-Internetservice GmbH & CO. KG, Bahnhofstr. 22a, 34369 Hofgeismar, Legal Notice: https://www.brielmedia.de/impressum/. When you visit our website, the personal data specified in this Privacy Policy is transmitted to the host if you are using the website for informational purposes only. The host’s server locations are exclusively in Germany. You can find the host’s privacy policy here: https://www.brielmedia.de/dsvgo-datenschutzgrundverordnung/
14. Your Rights
Below, we explain your rights under the GDPR. You can access the full text of the GDPR here.
Right of Access under Art. 15(1) of the GDPR
You have the right to request confirmation from us as to whether we are processing personal data concerning you. If this is the case, in addition to the right to access this personal data, you have the right to information regarding the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients to whom your personal data has been or will be disclosed (in particular recipients in third countries or international organizations), the storage period or criteria for determining the storage period, the existence of a right to rectification or erasure of the personal data concerning you or the right to restrict processing on our part, as well as the existence of a right to object to such processing, the existence of a right to lodge a complaint with a supervisory authority, all available information regarding the origin of the data (in the event that it was not collected by us), the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding the logic involved, as well as the scope and intended consequences of such processing.
Right to Rectification under Article 16 of the GDPR
You have the right to request that we promptly rectify inaccurate personal data concerning you and complete any incomplete personal data concerning you.
Right to erasure (“right to be forgotten”) under Article 17(1) of the GDPR
You have the right to request that we erase personal data concerning you without undue delay. However, pursuant to Article 17(3) of the GDPR, this right does not apply if the processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, or for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing under Article 18(1) of the GDPR
You have the right to request that we restrict the processing of your personal data if you contest the accuracy of your personal data (the restriction applies for the duration necessary to allow us to verify the accuracy), the processing of your personal data is unlawful and you oppose its erasure, we no longer need your personal data for the purposes of processing, but you need it to assert, exercise, or defend legal claims, or you have objected to the processing pursuant to Article 21(1) of the GDPR (this restriction applies until it is determined whether our legitimate interests override yours).
Right to Data Portability under Article 20 of the GDPR
You have the right to receive from us the personal data concerning you in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller without hindrance on our part (or to request that we transmit it directly to another controller, provided this is technically feasible), if our processing was based on consent or a contract, or was carried out using automated means.
Right to Withdraw Consent Pursuant to Article 7(3) of the GDPR
You have the right to withdraw consent you have previously given at any time with future effect, so that data processing based on that consent can no longer continue in the future; however, this does not affect the lawfulness of the processing carried out prior to your withdrawal.
Right to lodge a complaint under Article 77 of the GDPR
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. As a general rule, you may contact the supervisory authority in your usual place of residence, your place of work, or the location of the alleged violation. Further information on this is available on the website of the Federal Commissioner for Data Protection and Freedom of Information.
15. Right to Object
In addition to the rights mentioned above, you also have the right to object at any time to the processing of your personal data that is carried out on the basis of the performance of a task carried out in the public interest or in the exercise of official authority (Art. 6(1), first sentence, (e) of the GDPR) or to safeguard our legitimate interests (Article 6(1), first sentence, letter f of the GDPR), provided there are grounds for this arising from your specific situation. In the event of an objection, no further processing of the personal data will take place, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims. If your personal data is processed for the purpose of direct marketing or profiling—provided there is a connection to direct marketing—you have a general right to object without having to provide reasons based on your specific situation. If you object, we will immediately cease processing your personal data for these purposes. To exercise your right to withdraw consent or to object, simply send an emailto an:info@wigo-zelte.de
16. Data Security
Our website uses the TLS 1.3 (Transport Layer Security) encryption and communication protocol. Through the TLS certificate we use—issued by a certification authority—we enable encrypted data exchange between the web browser and the web server, ensuring that sensitive data cannot be read by third parties. We use the method with the highest encryption level supported by your browser; this is typically 256-bit encryption. The higher the bit count, the longer the key, and thus the better the protection against third parties.
This privacy policy was createdspecifically for this website by Frame for Business GmbH in cooperation with Schützle Rechtsanwaltsgesellschaft mbH.