Zollstock block01 419 1 1

Data Privacy Statement

Privacy policy

Obligation to provide information when personal data are collected from the data subject.

1. responsible person and contact data
The person responsible for the processing is the company Pickawood GmbH (hereinafter referred to as the person responsible) and processes the data provided by the data subject (hereinafter referred to as the customer) in accordance with the provisions of the European Data Protection Basic Regulation (hereinafter referred to as the DSGVO). 

The contact details of the person responsible are as follows:
Address: Rödingsmarkt 20, 20459 Hamburg, Germany
Phone: 040 / 524 77 770
Telephone number for Austrians (AT): 0 72 08 / 81 53 7
Phone number for Swiss (CH): 0 43 50 / 80 96 5
Fax: 040 / 22 81 70 34-9
Email: [email protected] 

2. data protection commissioner
The data protection officer of the responsible person is Dr. Martin Bahr.

The contact details of the data protection officer are as follows:
Address: Dr. Bahr Consulting GmbH, Mittelweg 41a, 20148 Hamburg, Germany
Phone: 040 / 555 98 300
E-mail: [email protected]

3. purpose and legal basis
The processing of the customer's personal data is necessary for the fulfilment of a contract to which the customer is a party or for the implementation of pre-contractual measures, which take place at the customer's request. This applies in particular to the registration for the newsletter as well as the saving of product configurations. The legal basis for this processing is Art. 6 Para. 1 b) DSGVO. 

In the event that the customer uses the contact form or the live chat or contacts the responsible person in any other way, in particular by e-mail, telephone, fax or post, the personal data will be used exclusively to process his enquiry. Legal basis for this processing is the consent of the customer according to Art. 6 para. 1 a) DSGVO.

In the other cases in which personal data are processed, the processing is carried out in order to safeguard the legitimate interests of the person responsible, namely to analyse the use of the website using web analysis tools (see point 4.3) or to detect, limit or eliminate malfunctions or errors on the website. The legal basis for this processing is Art. 6 para. 1 f) DSGVO. The person responsible refers to the customer's right of objection. Further information can be obtained from the customer under point 9 of this declaration.

4. recipient of the personal data
The customer's personal data transmitted to the responsible person will be made available to the following recipients as follows: 

4.1 Fulfilment of the contract or execution of pre-contractual measures:
In order to fulfil the contract or to carry out pre-contractual measures, the personal data of the Customer, which are transmitted to the responsible person, will be made accessible to the following recipients:
- CRM Software Provider
- Databases + Data hosting provider
- email service provider
- IT service provider
- Web Analytics Software Provider
- web hosting provider
- banks
- fiscal authorities
- Manufacturers + Producers
- logistics service provider
- management service provider
- fitters + assembly service providers
- payment service provider
- tax consultant 
- telephone provider

Personal data will not be made accessible to third parties without the written consent of the customer, unless this is required by law.

 

4.2. Dispatch of an order and payment by credit card:

For payments made with a credit card, your data will be forwarded to our payment provider Wirecard Bank AG. You will find detailed information on this at https://www.wirecardbank.de/DSGVO

 

4.3 Use of the contact form, the live chat or in the context of any other contact:

If the contact form is used, the personal data of the customer, which are transmitted to the responsible person, will be made accessible to the following recipients:
- CRM Software Provider
- web hosting provider

In case of using the live chat, the personal data of the customer, which will be transmitted to the responsible person, will be made accessible to the following recipients:
- CRM Software Provider

In the case of contact by telephone, the personal data of the customer, which are transmitted to the responsible person, are made accessible to the following recipients:
- Telecommunications provider

In the case of contact by fax, the personal data of the customer, which are transmitted to the responsible person, are made accessible to the following recipients:
- Telecommunications provider

In the case of contact by e-mail, the personal data of the customer, which are transmitted to the responsible person, are made accessible to the following recipients:
- CRM Software Provider
- email service provider

In the case of contact by mail, the personal data of the customer, which are transmitted to the responsible person, are made accessible to the following recipients:
- CRM Software Provider

Personal data will not be made accessible to third parties without the written consent of the customer, unless this is required by law.

4.4 Website analysis:
In order to analyse the use of the website, the personal data of the customer, which will be communicated to the responsible person, will be made available to the following recipients. The Customer may prevent the collection of such data by the aforementioned analysis services by clicking on the following link. An opt-out cookie is set to prevent the future collection of his data when visiting this website: Disable Analysis Services (DisableAllTracking)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website, such as your IP address, your browser settings and preferences, is stored on your computer.

- Browser type/version,
- operating system used,
- referrer URL (the previously visited page),
- Host name of the accessing computer (IP address),
- Time of the server request,

are usually transferred to a Google server and stored there. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google. We have also added the code "anonymizeIP" to Google Analytics on this website. This guarantees the masking of your IP address so that all data is collected anonymously. Only in exceptional cases is the full IP address transmitted to a Google server and shortened there. 

On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity and provide other services to the website operator in connection with website activity and internet usage. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

In addition, you can prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address) and Google from processing this data by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en. As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent Google Analytics from collecting data by clicking on this link. An opt-out cookie is set that prevents your data from being collected in the future when you visit this website. The opt-out cookie applies only to this browser and only to our website and is placed on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. You will find information on how to integrate the opt-out cookie at: https://developers.google.com/analytics/devguides/collection/gajs/?hl=en#disable].

We continue to use Google Analytics to evaluate data from double-click cookies and AdWords for statistical purposes. If you do not wish this to happen, you can deactivate it using the ad preferences manager (http://www.google.com/settings/ads/onweb/?hl=en).

Further information on data protection in connection with Google Analytics can be found in the Google Analytics help (https://support.google.com/analytics/answer/6004245?hl=en). 

Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA
This website uses web analysis functions of Facebook (pixels) to measure and optimize the control of campaigns via the Facebook platforms (Facebook and Instagram). Through the integration of this tool, Facebook receives the IP address and has the possibility to set cookies at the customer. If you have a Facebook account and are logged in there, Facebook can assign the visit to our website to your Facebook profile. For more information about Facebook's collection and use of data, your rights in this regard, and how Facebook can protect your privacy, please see Facebook's privacy policy at www.facebook.com/privacy/explanation. 

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
This website uses web analysis functions from Microsoft (Bing Ads) to measure and optimize the control of advertisements via search engines such as Bing and Yahoo. Through the integration of this tool, Microsoft receives the IP address and has the possibility to set cookies at the customer. Microsoft ensures that this information remains anonymous and cannot be used to identify individuals. Further information can be found at https://advertise.bingads.microsoft.com/de-de/ressourcen/richtlinien/privacy-policy and https://privacy.microsoft.com/de-de/privacystatement 

drtv.agency, Herdweg 101, 70193 Stuttgart, Germany
On our website we use an analysis tool of the drtv.agency, Herdweg 101, 70193 Stuttgart (in the following: "drtv"). The analysis takes place by two pixels (one pixel is a 1x1 pixel graphic used for tracking), which enable us to process your geolocation (country and city), your device model as well as other device information, operating system and browser, how you found us, page views, page types (e.g. start page or product page), time spent per page, if applicable your order number, purchased products and other information about the products (article number, name, price, quantity). The IP address and other personal data will not be stored.

Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe
We use Hotjar (www.hotjar.com) in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices (in particular device's IP address (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar’s privacy policy: https://www.hotjar.com/legal/policies/privacy You can opt-out to the creation of a user profile, Hotjar’s storing of data about your usage of our site and Hotjar’s use of tracking cookies on other websites by following this opt-out link (https://www.hotjar.com/legal/compliance/opt-out). 

Personal data will not be made accessible to other third parties without the written consent of the customer, unless this is required by law. 

4.5 Google Fonts:
For the integration of external fonts by Google Fonts, personal data of the customer is made accessible to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland. This website uses Google Fonts to integrate external fonts. Google provides the fonts for this purpose. When the customer accesses this website, the required fonts are loaded into the customer's browser cache to correctly display the texts and fonts on the page. For this purpose, the usual information when calling up a website, in particular the IP address of the customer and the referrer URL, is transmitted to a server of Google Ireland Limited. The customer receives further information under https://developers.google.com/fonts/faq and in the data security explanation of Google https://policies.google.com/privacy?hl=en. Without the written consent of the customer, the personal data will not be made accessible to other third parties, unless this is required by law.

5. cookies On different pages
On various pages, the responsible person uses cookies to make visiting his web pages attractive and to enable the use of certain functions. Cookies are small text files that are stored on the visitor's computer. Most of the cookies used by the responsible person are deleted from the visitor's hard drive at the end of the browser session (so-called session cookies). Other cookies remain on the visitor's computer and enable the responsible person to recognize the visitor's computer during the next visit (so-called permanent cookies). Of course, the customer can reject the cookies at any time, provided that the browser used permits this. 

6. third country transfer
Within the scope of using the web analysis tools Facebook (pixels) and Microsoft (Bing Ads) as well as Cloudflare and Zendesk, personal data is transferred to the USA. The addresses of the providers can be found under point 4.3.

An adequacy decision of the European Commission is missing. However, all providers are members of the EU-US Privacy Shield. Further information on the EU-US Privacy Shield can be found at the URL: https://www.privacyshield.gov 

7. storage duration
With the complete execution of the contract, which also includes the complete payment of the agreed remuneration, the customer's data, which must be stored for legal reasons, will be blocked. These data are no longer available for further use. Once the legal reason has ceased to exist, these blocked data will be deleted.

In the event that the customer uses the contact form or the live chat or otherwise contacts the responsible person, the personal data will be used for the duration of the processing of the request. Subsequently, the data which must be kept for legal reasons will be blocked. These data are no longer available for further use.

The person responsible is subject to various storage and documentation obligations, including those arising from the German Commercial Code (HGB) and the Fiscal Code (AO). The periods for storage and documentation specified there are between two and ten years.

Finally, the storage period is also assessed according to the statutory limitation periods, which, for example, according to §§ 195 et seq. of the German Civil Code (BGB) can generally be three years, but in certain cases also up to thirty years. Otherwise, personal data will be deleted unless the customer has expressly consented to the further processing and use of his data.

The personal data stored for the purpose of identifying, limiting or eliminating faults or errors on the website will be deleted after seven days at the latest.

The personal data collected using Google Analytics will be stored for a period of 50 months after the last session of the visitor.

8. data protection rights
Every customer has the right to information pursuant to Article 15 DSGVO, the right to correction pursuant to Article 16 DSGVO, the right to deletion pursuant to Article 17 DSGVO, the right to restriction of processing pursuant to Article 18 DSGVO, the right to objection pursuant to Article 21 DSGVO and the right to data transfer pursuant to Article 20 DSGVO. The restrictions under §§ 34 and 35 BDSG apply to the right to information and the right to cancellation. In addition, there is a right of appeal to a data protection supervisory authority (Article 77 DSGVO in conjunction with § 19 BDSG). 

The customer can find the legal texts here https://dsgvo-gesetz.de/

Corresponding requests are to be directed to the address mentioned under point 1 or to [email protected]

9. right of objection and other rights
If the customer has given his consent to the processing of his personal data for one or more specific purposes, the customer is entitled to revoke the consent with effect for the future.

In particular, the customer has the right against the processing of personal data for the analysis of the website or to detect, limit or eliminate faults or errors on the website, the right to object to the processing at any time free of charge with effect for the future. This can be done by sending an e-mail to [email protected] or to the address given in point 1.

Without prejudice to any other administrative or judicial remedy, any data subject shall have the right to complain to a supervisory authority, in particular in the Member State in which he or she is staying, at his or her place of work or at the place where the alleged infringement is alleged to have occurred, if he or she considers that the processing of his or her personal data has infringed this Regulation. 

A competent authority is, for example, the Hamburg Commissioner for Data Protection and Freedom of Information, Klosterwall 6 (Block C), 20095 Hamburg, Germany. However, the customer can also choose another one. 

10. obligation to provide data
The following information is mandatory (mandatory information):
10.1 Fulfilment of the contract:

The specification of the following data is mandatory for the conclusion of a contract (mandatory data):
- Salutation
- First name and surname
- Company (if available)
- Address (street, house number, postcode, city, country)
- telephone number
- email address

For the use of the newsletter and the saving of product configurations, the following data is mandatory:
- E-mail address

All other information is not required for the conclusion of the contract and is therefore voluntary.

If the mandatory information required for the conclusion of the contract is not provided, the contract will not be concluded. The non-disclosure of the voluntary information has no influence on the conclusion of the contract. 

10.2 Use of the contact form, the live chat or the processing of any other request:

For the processing of a general inquiry in the context of the contact form the indication of the following data is compellingly necessary (obligation data):
- First name
- Surname
- Email address
- Message

For the processing of the request in the context of the live chat, the following data is mandatory (mandatory data):
- Message

If the live chat is not occupied by an employee, the same data will be requested as in the contact form.

In order to process a telephone enquiry, the following data must be entered (mandatory data):
- Your name
- Telephone number

In order to process an enquiry by fax, the following data is mandatory (mandatory data):
- Name
- Fax number

In order to process an inquiry by e-mail, the following data must be entered (mandatory data):
- Name
- Email address

In order to process a postal request, the following data must be entered (mandatory data):
- Name of the request
- Address

All other information is not required for the processing of a request and is therefore voluntary.

If the mandatory data required for the processing of a request are not provided, the contact request will not be processed. Failure to provide voluntary information does not affect the processing of the request.

10.3 Website analysis:

The following data is mandatory for the recognition, limitation or elimination of faults or errors on the website (mandatory data):
- IP address

All other information is not required for the detection, limitation or elimination of faults or errors on the website and is therefore voluntary.

If the mandatory information required for the detection, limitation or elimination of faults or errors on the website is not provided, this website cannot be used. 

The deactivation of data transmission within the framework of Google Analytics has no effect on the use of this website. 

11. automated decision making
An automated form of decision including profiling does not take place.

 

SERVICE