Privacy Policy
On this page, we have compiled the legally required information on the General Data Protection Regulation EU 2016/679 in order to make it clear to you how seriously we take the handling of your personal data (data for short).
We as the data controller (or service providers used - e.g. providers) explain to you in a transparent and comprehensible form what data we process from you and why, how long we store your data and with what right we do so. Speaking of rights: You also have rights when it comes to your data.
Because we know that such legal texts are usually long, too technical and incomprehensible, we have prepared a short form for you. If you want to know exactly what you need to know, you will find a link to the detailed instructions at the end.
(We use the following terms in a gender-neutral way.)
Short version:
1. Who is responsible for processing your data?
Responsible is:
Data protection officer is:
2. Why is what data collected from you?
Every time you visit a website, a shortened version of your IP address is collected. This is not technically possible in any other way. Technically necessary cookies are set - this is also not possible in any other way in order to ensure that the page is set up smoothly.
On other sub-pages, you have the option of viewing a map from GoogleMaps or an image video (embedded on YouTube). These are third-party services to which your connection data is automatically transmitted.
If you want to register as a customer with us, we need additional data to be able to better classify you. Here you also have the choice of a newsletter subscription. We protect ourselves from registration robots by running a protective query (reCaptcha) in the background.
3. How long will your data be stored?
In principle, we do not store your data for longer than we need it. However, there are legal regulations that stipulate a retention period, e.g.: 10 years for accounting records. After expiry of the respective retention periods, your data is automatically deleted, provided there is no further contractual relationship. However, we have no influence on the storage period of third-party providers.
4. With which right do we process your data?
With the right of legitimate interest (Art. 6 para. 1 lit. f DSGVO), we process your IP address to ensure the smooth operation of the website. All data that we collect in the course of registration are processed by us in order to initiate pre-contractual measures (Art.6 para.1 lit. b DSGVO).
At the same time, we are legally obliged to collect data in connection with invoices (Art.6 para.1 lit.c DSGVO). We explicitly point out all further processing and, if necessary, obtain your consent separately (Art.6 para.1 lit. a DSGVO).
5. What rights do you have in relation to the processing of your data?
Art. 13 GDPR states that you have rights at all times in relation to the processing of your personal data - these are listed in more detail in the articles below:
- Right of access (Art.15 GDPR): if we process data about you, you have the right to obtain from us in writing any information relating to the points just listed.
- Right to rectification (Art. 16 DSGVO): if we process incorrect data about you, you have the right to have us rectify it.
- Right to erasure or "right to be forgotten" (Art. 17 DSGVO): if you request the erasure of your data, we will of course comply with this, provided that there are no legal requirements to the contrary.
- Right to restrict processing (Art. 18 DSGVO): this restricts the further use of your data - but not its storage. This only makes sense in exceptional cases, e.g. if you are still asserting rights against us.
- Right to data portability (Art. 19 DSGVO): means that we will provide you with your data in a common format upon request.
- You also have a right to object (Art. 21 GDPR): usually this right is associated with direct marketing / unlawful commercial emails or automated processing such as profiling (Art.22 GDPR).
If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, please feel free to write to us or our data protection officer.
Last but not least, you have the right to complain to the competent supervisory authority - the following data protection authority is competent for our company:
Inhaltsverzeichnis
Introduction
We have written this data protection notice in order to explain to you, in accordance with the requirements of the General Data Protection Regulation EU 2016/679 and applicable national laws (BDSG-neu), which personal data (data for short) we process as the responsible party, will process in the future and what lawful options you have.
Data protection notices are usually very technical and full of legal jargon. We, on the other hand, inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis.
Scope of application
This data protection notice applies to all personal data processed by us in the company. By personal data, we mean information within the meaning of Art. 4 No. 1 DSGVO, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this data protection notice includes:
- all online presences that we operate
- E-mail communication
Definitions
The data protection information of SACO Air GmbH is based on the terms used by the European Directive and Ordinance Maker when issuing the Basic Data Protection Regulation (DSGVO). In order to ensure consistent use of language, we would like to explain the terms used in advance.
We use the following terms, among others, in this privacy notice:
- (a) personal data
Personal data means any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- (b) person concerned
Data subject means any identified or identifiable natural person whose personal data are processed by the controller.
- c) Processing
Processing is any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, archiving or destruction.
- (d) restriction of processing
Restriction of processing is the marking of stored personal data with the aim of limiting their future processing.
- e) Profiling
Profiling is any form of automated processing of personal data which consists in using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or change of location.
- f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
- (g) controller or person responsible for processing
The controller or person responsible for processing is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for under Union or Member State law.
- (h) Processors
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- i) Recipient
A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. However, public authorities that may receive personal data in the context of a specific investigative task under Union or Member State law shall not be considered as recipients.
- j) Third
Third party means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorised to process the personal data under the direct responsibility of the controller or the processor.
- k) Consent
Consent shall mean any freely given specific and informed indication of the data subject's wishes in the form of a statement or other unambiguous affirmative act by which the data subject signifies his or her agreement to the processing of personal data relating to him or her.
Legal basis
In the following data protection notices, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the data protection basic regulation, which enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU data protection basic regulation online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
- 1. Consent (Article 6(1)(a) DSGVO): You have given us your consent to process data for a specific purpose. An example would be the storage of your entered data of a contact form.
- 2. Contract (Article 6(1)(b) DSGVO): In order to fulfil a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a sales contract with you, we need personal information in advance.
- 3. Legal obligation (Article 6(1)(c) DSGVO): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
- 4. Legitimate interests (Article 6(1)(f) DSGVO): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website in a secure and economically efficient manner. This processing is therefore a legitimate interest.
Further conditions such as the performance of recordings in the public interest and the exercise of public authority as well as the protection of vital interests do not generally occur with us. If such a legal basis should be relevant, it will be indicated at the appropriate place.
In addition to the EU Regulation, national laws also apply - in Germany, the Federal Data Protection Act, or BDSG-neu for short, applies.
If other regional or national laws apply, we will inform you about them in the following sections.
Storage period
The fact that we only store personal data for as long as is absolutely necessary for the provision of our services and products applies as a general criterion with us. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
Should you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as soon as possible and insofar as there is no obligation to store it.
We will inform you about the specific duration of the respective data processing below, provided we have further information on this.
Rights under the General Data Protection Regulation
According to Article 13 of the GDPR, you have the following rights to ensure fair and transparent processing of data.
According to Article 15 of the GDPR, you have the right to know whether we are processing data about you. If this is the case, you have the right to receive a copy of the data and the following information:
- the purpose for which we carry out the processing;
- the categories, i.e. the types of data that are processed;
- who receives this data and if the data is transferred to third countries, how security can be guaranteed;
- how long the data will be stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can complain to a supervisory authority (link to this authority can be found below);
- the origin of the data if we have not collected it from you;
- whether profiling is carried out, i.e. whether data is automatically evaluated to arrive at a personal profile of you.
You have a right to rectify data under Article 16 of the GDPR, which means that we must correct data if you find errors.
According to Article 17 of the GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.
According to Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.
According to Article 19 of the GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
According to Article 21 of the GDPR, you have a right to object, which, once enforced, entails a change in processing.
If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then check as soon as possible whether we can legally comply with this objection.
If data is used to carry out direct marketing, you can object to this type of data processing at any time. We are then no longer allowed to use your data for direct marketing.
If data is used to carry out profiling, you can object to this type of data processing at any time. We are then no longer allowed to use your data for profiling.
You may have the right under Article 22 of the GDPR not to be subject to a decision based solely on automated processing (for example profiling).
Data transfer to third countries
We only transfer or process data to countries outside the EU (third countries) if you consent to this processing, if this is required by law or contractually necessary and in any case only to the extent that this is generally permitted. Your consent is in most cases the most important reason for us to have data processed in third countries. Processing personal data in third countries such as the US, where many software vendors provide services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. Data processing by US services (such as GoogleMaps or Youtube) may result in data not being processed and stored anonymously. Furthermore, US government authorities may be able to access individual data. In addition, it may happen that collected data is linked to data from other services of the same provider, provided you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.
We will provide you with more detailed information about data transfers to third countries, where applicable, at the appropriate points in this privacy notice.
Data processing security
To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In this way, we make it as difficult as possible for third parties to infer personal information from our data.
TLS encryption with https
TLS, encryption and https sound very technical and they are. We use HTTPS (the Hypertext Transfer Protocol Secure stands for "secure hypertext transfer protocol") to transfer data tap-proof on the internet. This means that the complete transmission of all data from your browser to our web server is secured - no one can "listen in".
In this way, we have introduced an additional layer of security and fulfil data protection by design of technology Article 25(1) DSGVO) https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32016R0679&from=DE&tid=311881264. By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission protection by the small lock symbol at the top left of the browser, to the left of the internet address (e.g. beispielseite.de) and the use of the scheme https (instead of http) as part of our internet address.
Communication
When you contact us and communicate by phone, email or online form, personal data may be processed.
The data is processed for the handling and processing of your question and the related business transaction. The data will be stored for this duration or as long as required by law.
Persons concerned
All those who seek contact with us via the communication channels provided by us are affected by the aforementioned processes.
Phone
When you call us, the call data is stored pseudonymously on the respective end device and with the telecommunications provider used. In addition, data such as name and telephone number can subsequently be sent by e-mail and stored for the purpose of responding to enquiries. The data is deleted as soon as the business case has been completed and legal requirements permit.
If you communicate with us by e-mail, data may be stored on the respective end device (computer, laptop, smartphone,...) and data is stored on the e-mail server. The data is deleted as soon as the business case has been completed and legal requirements permit.
Registration form
You have the option of registering for our customer portal on our homepage. For this purpose, we require your personal data in order to be able to reasonably create you as a customer. The data will not be passed on to third parties and will be stored for as long as we are contractually or legally obliged to do so. If no business transaction is concluded, your data will be deleted at regular intervals.
Newsletter subscription
In the course of registering for our customer portal, you also have the option of registering to receive our newsletter. By registering, you consent to the processing of the data required for this purpose. The data will not be passed on to third parties and will remain stored for as long as we are contractually or legally obliged to do so. Should no business transaction come about, your data will be deleted at regular intervals. You can unsubscribe from the newsletter at any time. For this purpose, you will find an "unsubscribe" link at the end of each newsletter for easy technical implementation.
Legal basis
The processing of data is based on the following legal bases:
- Art. 6 para. 1 lit. a DSGVO (consent): You give us your consent to store your data and to use it for purposes related to the business case;
- Art. 6 para. 1 lit. b DSGVO (contract): There is a need for the performance of a contract with you or a processor such as the telephone provider or we need to process the data for pre-contractual activities, such as the preparation of an offer;
- Art. 6 para. 1 lit. f DSGVO (Legitimate Interests): We want to operate customer enquiries and business communication in a professional framework. For this purpose, certain technical facilities such as e-mail programmes, exchange servers and mobile phone operators are necessary in order to be able to operate the communication efficiently.
Webhosting
What is web hosting?
When you visit websites nowadays, certain information - including personal data - is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, by the way, we mean the totality of all web pages on a domain, i.e. everything from the home page (homepage) to the very last subpage (like this one). By domain we mean, for example, www. beispiel.de or www. musterbeispiel.com.
When the browser on your computer (desktop, laptop, smartphone) connects and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data, on the other hand, the web server must also store data for a while to ensure proper operation.
Why do we process personal data?
The purposes of the data processing are:
- Professional hosting of the website and safeguarding of the operation
- to maintain operational and IT security
- Anonymous evaluation of access behaviour to improve our offer and, if necessary, for criminal prosecution or the pursuit of claims.
What data is processed?
Even while you are visiting our website right now, our web server, which is the computer on which this website is stored, usually automatically stores data such as
- the complete Internet address (URL) of the website accessed (e.g. https://www.beispielwebsite.de/beispielunterseite.html?tid=311881264)
- Browser and browser version (e.g. Chrome 100)
- the operating system used (e.g. Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen.html/)
- The host name and IP address of the device being accessed (e.g. COMPUTERNAME and 194.23.43.121).
- Date and time
- in files, the so-called web server log files
How long is data stored?
As a rule, the above data is stored for a fortnight and then automatically deleted. We do not pass on this data, but are obliged to hand over your data to the authorities on request in the event of unlawful conduct.
Legal basis
The lawfulness of the processing of personal data in the context of web hosting results from Art. 6 para. 1 lit. f DSGVO (protection of legitimate interests), because the use of professional hosting with a provider is necessary to present the company on the Internet in a secure and user-friendly manner and to be able to pursue attacks and claims from this if necessary.
There is a contract on commissioned processing between us and the hosting provider in accordance with Art. 28 f. DSGVO, which ensures compliance with data protection and guarantees data security.