Dashboard

Privacy Policy

On this page, we have compiled the legally required information on the General Data Protection Regulation EU 2016/679 in order to make it clear to you how seriously we take the handling of your personal data (data for short).

We as the data controller (or service providers used - e.g. providers) explain to you in a transparent and comprehensible form what data we process from you and why, how long we store your data and with what right we do so. Speaking of rights: You also have rights when it comes to your data.

Because we know that such legal texts are usually long, too technical and incomprehensible, we have prepared a short form for you. If you want to know exactly what you need to know, you will find a link to the detailed instructions at the end.

(We use the following terms in a gender-neutral way.)

Short version:

1. Who is responsible for processing your data?

Responsible is:

SACO Air GmbH
represented by: Andreas Papathanasiou, Harald Pahl
Nordportbogen 2a
22848 Norderstedt
Telefon +49 40 500 196 0
Fax +49 40 500 196 383
E-Mail ham@sacoair.com

Data protection officer is:

Frank Kowalski (FK-Datenschutz UG)
Tangstedter Weg 38E
22851 Norderstedt
Phone +49 40 943 63 764
E-Mail kowalski@fk-datenschutz.de

2. Why is what data collected from you?

Every time you visit a website, a shortened version of your IP address is collected. This is not technically possible in any other way. Technically necessary cookies are set - this is also not possible in any other way in order to ensure that the page is set up smoothly.

On other sub-pages, you have the option of viewing a map from GoogleMaps or an image video (embedded on YouTube). These are third-party services to which your connection data is automatically transmitted.

If you want to register as a customer with us, we need additional data to be able to better classify you. Here you also have the choice of a newsletter subscription. We protect ourselves from registration robots by running a protective query (reCaptcha) in the background.

3. How long will your data be stored?

In principle, we do not store your data for longer than we need it. However, there are legal regulations that stipulate a retention period, e.g.: 10 years for accounting records. After expiry of the respective retention periods, your data is automatically deleted, provided there is no further contractual relationship. However, we have no influence on the storage period of third-party providers.

4. With which right do we process your data?

With the right of legitimate interest (Art. 6 para. 1 lit. f DSGVO), we process your IP address to ensure the smooth operation of the website. All data that we collect in the course of registration are processed by us in order to initiate pre-contractual measures (Art.6 para.1 lit. b DSGVO).

At the same time, we are legally obliged to collect data in connection with invoices (Art.6 para.1 lit.c DSGVO). We explicitly point out all further processing and, if necessary, obtain your consent separately (Art.6 para.1 lit. a DSGVO).

5. What rights do you have in relation to the processing of your data?

Art. 13 GDPR states that you have rights at all times in relation to the processing of your personal data - these are listed in more detail in the articles below:

  • Right of access (Art.15 GDPR): if we process data about you, you have the right to obtain from us in writing any information relating to the points just listed.
  • Right to rectification (Art. 16 DSGVO): if we process incorrect data about you, you have the right to have us rectify it.
  • Right to erasure or "right to be forgotten" (Art. 17 DSGVO): if you request the erasure of your data, we will of course comply with this, provided that there are no legal requirements to the contrary.
  • Right to restrict processing (Art. 18 DSGVO): this restricts the further use of your data - but not its storage. This only makes sense in exceptional cases, e.g. if you are still asserting rights against us.
  • Right to data portability (Art. 19 DSGVO): means that we will provide you with your data in a common format upon request.
  • You also have a right to object (Art. 21 GDPR): usually this right is associated with direct marketing / unlawful commercial emails or automated processing such as profiling (Art.22 GDPR).

If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, please feel free to write to us or our data protection officer.

Last but not least, you have the right to complain to the competent supervisory authority - the following data protection authority is competent for our company:

Schleswig-Holstein Data Protection Authority
State Commissioner for Data Protection: Marit Hansen
Holstenstraße 98
24103 Kiel
Telephone : 04 31/988-12 00
E-Mail: mail@datenschutzzentrum.de
Website: https://www.datenschutzzentrum.de

Inhaltsverzeichnis

Introduction

We have written this data protection notice in order to explain to you, in accordance with the requirements of the General Data Protection Regulation EU 2016/679 and applicable national laws (BDSG-neu), which personal data (data for short) we process as the responsible party, will process in the future and what lawful options you have.

Data protection notices are usually very technical and full of legal jargon. We, on the other hand, inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis.

Scope of application

This data protection notice applies to all personal data processed by us in the company. By personal data, we mean information within the meaning of Art. 4 No. 1 DSGVO, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this data protection notice includes:

  • all online presences that we operate
  • E-mail communication

Definitions

The data protection information of SACO Air GmbH is based on the terms used by the European Directive and Ordinance Maker when issuing the Basic Data Protection Regulation (DSGVO). In order to ensure consistent use of language, we would like to explain the terms used in advance.

We use the following terms, among others, in this privacy notice:

  • (a) personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  • (b) person concerned

Data subject means any identified or identifiable natural person whose personal data are processed by the controller.

  • c) Processing

Processing is any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, archiving or destruction.

  • (d) restriction of processing

Restriction of processing is the marking of stored personal data with the aim of limiting their future processing.

  • e) Profiling

Profiling is any form of automated processing of personal data which consists in using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or change of location.

  • f) Pseudonymisation

Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

  • (g) controller or person responsible for processing

The controller or person responsible for processing is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for under Union or Member State law.

  • (h) Processors

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

  • i) Recipient

A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. However, public authorities that may receive personal data in the context of a specific investigative task under Union or Member State law shall not be considered as recipients.

  • j) Third

Third party means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorised to process the personal data under the direct responsibility of the controller or the processor.

  • k) Consent

Consent shall mean any freely given specific and informed indication of the data subject's wishes in the form of a statement or other unambiguous affirmative act by which the data subject signifies his or her agreement to the processing of personal data relating to him or her.

Storage period

The fact that we only store personal data for as long as is absolutely necessary for the provision of our services and products applies as a general criterion with us. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.

Should you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as soon as possible and insofar as there is no obligation to store it.

We will inform you about the specific duration of the respective data processing below, provided we have further information on this.

Rights under the General Data Protection Regulation

According to Article 13 of the GDPR, you have the following rights to ensure fair and transparent processing of data.

According to Article 15 of the GDPR, you have the right to know whether we are processing data about you. If this is the case, you have the right to receive a copy of the data and the following information:

  • the purpose for which we carry out the processing;
  • the categories, i.e. the types of data that are processed;
  • who receives this data and if the data is transferred to third countries, how security can be guaranteed;
  • how long the data will be stored;
  • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
  • that you can complain to a supervisory authority (link to this authority can be found below);
  • the origin of the data if we have not collected it from you;
  • whether profiling is carried out, i.e. whether data is automatically evaluated to arrive at a personal profile of you.

You have a right to rectify data under Article 16 of the GDPR, which means that we must correct data if you find errors.

According to Article 17 of the GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.

According to Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.

According to Article 19 of the GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request.

According to Article 21 of the GDPR, you have a right to object, which, once enforced, entails a change in processing.

If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then check as soon as possible whether we can legally comply with this objection.

If data is used to carry out direct marketing, you can object to this type of data processing at any time. We are then no longer allowed to use your data for direct marketing.

If data is used to carry out profiling, you can object to this type of data processing at any time. We are then no longer allowed to use your data for profiling.

You may have the right under Article 22 of the GDPR not to be subject to a decision based solely on automated processing (for example profiling).

Data transfer to third countries

We only transfer or process data to countries outside the EU (third countries) if you consent to this processing, if this is required by law or contractually necessary and in any case only to the extent that this is generally permitted. Your consent is in most cases the most important reason for us to have data processed in third countries. Processing personal data in third countries such as the US, where many software vendors provide services and have their server locations, may mean that personal data is processed and stored in unexpected ways.

We expressly point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. Data processing by US services (such as GoogleMaps or Youtube) may result in data not being processed and stored anonymously. Furthermore, US government authorities may be able to access individual data. In addition, it may happen that collected data is linked to data from other services of the same provider, provided you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.

We will provide you with more detailed information about data transfers to third countries, where applicable, at the appropriate points in this privacy notice.

Data processing security

To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In this way, we make it as difficult as possible for third parties to infer personal information from our data.

TLS encryption with https

TLS, encryption and https sound very technical and they are. We use HTTPS (the Hypertext Transfer Protocol Secure stands for "secure hypertext transfer protocol") to transfer data tap-proof on the internet. This means that the complete transmission of all data from your browser to our web server is secured - no one can "listen in".

In this way, we have introduced an additional layer of security and fulfil data protection by design of technology Article 25(1) DSGVO) https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32016R0679&from=DE&tid=311881264. By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data.

You can recognise the use of this data transmission protection by the small lock symbol at the top left of the browser, to the left of the internet address (e.g. beispielseite.de) and the use of the scheme https (instead of http) as part of our internet address.

Communication

When you contact us and communicate by phone, email or online form, personal data may be processed.

The data is processed for the handling and processing of your question and the related business transaction. The data will be stored for this duration or as long as required by law.

Persons concerned

All those who seek contact with us via the communication channels provided by us are affected by the aforementioned processes.

Phone

When you call us, the call data is stored pseudonymously on the respective end device and with the telecommunications provider used. In addition, data such as name and telephone number can subsequently be sent by e-mail and stored for the purpose of responding to enquiries. The data is deleted as soon as the business case has been completed and legal requirements permit.

E-Mail

If you communicate with us by e-mail, data may be stored on the respective end device (computer, laptop, smartphone,...) and data is stored on the e-mail server. The data is deleted as soon as the business case has been completed and legal requirements permit.

Registration form

You have the option of registering for our customer portal on our homepage. For this purpose, we require your personal data in order to be able to reasonably create you as a customer. The data will not be passed on to third parties and will be stored for as long as we are contractually or legally obliged to do so. If no business transaction is concluded, your data will be deleted at regular intervals.

Newsletter subscription

In the course of registering for our customer portal, you also have the option of registering to receive our newsletter. By registering, you consent to the processing of the data required for this purpose. The data will not be passed on to third parties and will remain stored for as long as we are contractually or legally obliged to do so. Should no business transaction come about, your data will be deleted at regular intervals. You can unsubscribe from the newsletter at any time. For this purpose, you will find an "unsubscribe" link at the end of each newsletter for easy technical implementation.

Legal basis

The processing of data is based on the following legal bases:

  • Art. 6 para. 1 lit. a DSGVO (consent): You give us your consent to store your data and to use it for purposes related to the business case;
  • Art. 6 para. 1 lit. b DSGVO (contract): There is a need for the performance of a contract with you or a processor such as the telephone provider or we need to process the data for pre-contractual activities, such as the preparation of an offer;
  • Art. 6 para. 1 lit. f DSGVO (Legitimate Interests): We want to operate customer enquiries and business communication in a professional framework. For this purpose, certain technical facilities such as e-mail programmes, exchange servers and mobile phone operators are necessary in order to be able to operate the communication efficiently.

Cookies

What are cookies?

Our website uses HTTP cookies to store user-specific data. Below we explain what cookies are and why they are used so that you can better understand the following privacy notice.

Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, effectively the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified. Cookies store certain user data about you, such as language or personal page settings. When you return to our site, your browser transmits the "user-related" information back to our site. Thanks to the cookies, our website knows who you are and offers you the setting you are used to. In some browsers, each cookie has its own file, in others, such as Firefox, all cookies are stored in a single file.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie is to be evaluated individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programmes and do not contain viruses, Trojans or other "pests". Cookies also cannot access information on your PC.

Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this “user-specific” information back to our site. Thanks to cookies, our website knows who you are and provides you with the settings you’re used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

What are the different types of cookies?

The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy notice. At this point, we would like to briefly discuss the different types of HTTP cookies.

One can distinguish between 4 types of cookies:

Essential cookies

These cookies are necessary to ensure basic website functionality. For example, these cookies are needed when a user places a product in the shopping cart, then continues surfing on other pages and later goes to the checkout. These cookies do not delete the shopping cart even if the user closes his browser window.

Purposeful cookies

These cookies collect information about user behaviour and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behaviour of the website with different browsers.

Targeting cookies

These cookies provide a better user experience. For example, entered locations, font sizes or form data are saved.

Advertising cookies

These cookies are also called targeting cookies. They are used to deliver customised advertising to the user. This can be very practical, but also very annoying.

Purpose of processing via cookies

The purpose ultimately depends on the cookie in question. You can find more details about this from the manufacturer of the software that sets the cookie.

What data is processed?

We only use essential cookies to ensure a smooth page load.

Storage period of cookies

The storage period depends on the cookie. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.

Our cookies are deleted after 4 weeks or after the end of the session.

You can also influence the storage period yourself. You can manually delete all cookies at any time via your browser (see also "Right of objection" below). Furthermore, cookies that are based on consent will be deleted at the latest after revocation of your consent, whereby the legality of the storage remains unaffected until then.

Right of objection - how can I delete cookies?

You decide how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to find out which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, activate and manage cookies in Chrome

Safari: Managing Cookies and Website Data with Safari

Firefox: Delete cookies to remove data that websites have placed on your computer.

Internet Explorer: Deleting and managing cookies

Microsoft Edge: Delete and manage cookies

If you generally do not want cookies, you can set up your browser so that it always informs you when a cookie is to be set. In this way, you can decide for each individual cookie whether you allow the cookie or not. The procedure varies depending on the browser. It is best to search for the instructions in Google with the search term "Delete Cookies Chrome" or "Deactivate Cookies Chrome" in the case of a Chrome browser.

Legal basis

The so-called "Cookie Guidelines" have been in place since 2009. These state that the storage of cookies requires your consent (Article 6 para. 1 lit. a DSGVO). Within the EU countries, however, there are still very different reactions to these directives. In Germany, the Cookie Directives have not been implemented as national law. Instead, this directive was largely implemented in § 15 para.3 of the German Telemedia Act (TMG).

On 1 December 2021, the Telecommunications and Telemedia Data Protection Act (TTDSG) came into force. This law comes alongside the scope of the GDPR and aims to prevent unwanted access to information stored on computers, tablets or mobile phones.

In future, consent must always be obtained when using technologies such as cookies, web storage, browser fingerprinting, etc. - regardless of whether personal data is processed in the process. The further explanations on the principles of the need for consent are described in Section 25 (1) and (2) TTDSG.

For absolutely necessary cookies, even where there is no consent. there are legitimate interests (Article 6(1)(f) DSGVO), which in most cases are of an economic nature. We want to provide visitors to the website with a pleasant user experience and for this purpose certain cookies are often absolutely necessary. If cookies are used that are not absolutely necessary, this is only done with your consent. The legal basis in this respect is Art. 6 Para. 1 lit. a DSGVO in conjunction with §25 TTDSG.

Webhosting

What is web hosting?

When you visit websites nowadays, certain information - including personal data - is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, by the way, we mean the totality of all web pages on a domain, i.e. everything from the home page (homepage) to the very last subpage (like this one). By domain we mean, for example, www. beispiel.de or www. musterbeispiel.com.

When the browser on your computer (desktop, laptop, smartphone) connects and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data, on the other hand, the web server must also store data for a while to ensure proper operation.

Why do we process personal data?

The purposes of the data processing are:

  1. Professional hosting of the website and safeguarding of the operation
  1. to maintain operational and IT security
  1. Anonymous evaluation of access behaviour to improve our offer and, if necessary, for criminal prosecution or the pursuit of claims.

What data is processed?

Even while you are visiting our website right now, our web server, which is the computer on which this website is stored, usually automatically stores data such as

  • the complete Internet address (URL) of the website accessed (e.g. https://www.beispielwebsite.de/beispielunterseite.html?tid=311881264)
  • Browser and browser version (e.g. Chrome 100)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen.html/)
  • The host name and IP address of the device being accessed (e.g. COMPUTERNAME and 194.23.43.121).
  • Date and time
  • in files, the so-called web server log files

How long is data stored?

As a rule, the above data is stored for a fortnight and then automatically deleted. We do not pass on this data, but are obliged to hand over your data to the authorities on request in the event of unlawful conduct.

Legal basis

The lawfulness of the processing of personal data in the context of web hosting results from Art. 6 para. 1 lit. f DSGVO (protection of legitimate interests), because the use of professional hosting with a provider is necessary to present the company on the Internet in a secure and user-friendly manner and to be able to pursue attacks and claims from this if necessary.

There is a contract on commissioned processing between us and the hosting provider in accordance with Art. 28 f. DSGVO, which ensures compliance with data protection and guarantees data security.