Privacy policy


Privacy Policy:

Status: 06/2018

We process personal data (hereinafter referred to as "data") of users only to the extent necessary to provide a functional and convenient website and our content and services.

Processing" means the collection, use, transfer and/or storage of such data. According to the Basic Data Protection Regulation (hereinafter referred to as "DSGVO"), "personal data" is basically all data with which a natural person can be identified. The exact definitions of the terms are set out in Art. 4 DSGVO.

The following explanations will inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, about the purposes and means of processing which we alone or jointly with others decide to use, as well as about the components of third parties who process data on their own responsibility, which we may use for optimisation and quality of use:

_________________________________________

A) Information on the person responsible

B) Rights of the user

C) Information on data processing

_________________________________________

A) Information on the person responsible

The person responsible (hereinafter referred to as "Provider") within the meaning of the DSGVO and other national data protection laws of the member states as well as other data protection regulations:

CarPoint GmbH
Hollow Cobble Way 16
76189 Karlsruhe

Phone: + 49/ (0)721/ 982120
Fax: + 49/ (0)721/ 9821226
e-mail: info@carpoint.de

 

B) Rights of the user

The user has the right to the processing of his personal data as described below by the provider,

  1. to obtain confirmation as to whether the data concerning him are being processed and to receive precise information about these data and further information and copies of the data in accordance with Art. 15 DSGVO;
  2. to demand the immediate correction of incorrect data concerning him or the completion of such data in accordance with Art. 16 DSGVO;
  3. to demand that the data relating to him be deleted immediately in accordance with Art. 17 DSGVO, or alternatively, if further processing is necessary in accordance with Art. 17 para. 3 DSGVO, to demand a restriction on the processing of the data in accordance with Art. 18 DSGVO;
  4. to receive the data relating to him and provided by him in accordance with Art. 20 DSGVO and to demand their transfer to other responsible parties;
  5. to lodge a complaint with the supervisory authority pursuant to Art. 77 DSGVO if the user believes that the processing of his data by the provider violates the DSGVO.

_________________________

6. The user can fundamentally object to the future processing of the data concerning him/her, which is carried out by a person responsible on the basis of Art. 6 Para. 1 letter f DSGVO, at any time in accordance with Art. 21 DSGVO. The objection may in particular be made against processing for the purposes of direct advertising.

_________________________

7. The provider is also obliged to notify all recipients of the data to whom the data has been disclosed by him of any correction or deletion of the personal data or any restriction on processing which is carried out on the basis of Article 16 DSGVO, Article 17 paragraph 1 DSGVO and Article 18 DSGVO. This obligation does not apply in the event that such communication proves impossible or involves disproportionate effort. The user has the right to obtain information regarding these recipients.

 

C) Information on data processing

As far as no detailed information is given in the following regarding the individual data processing, the user data processed by the provider will be deleted or blocked as soon as the purpose of the storage no longer applies and no legal storage obligations oppose the deletion. 

Server data

For communication and security reasons, the following data, among others, is collected during the visit to the website, which the user's Internet browser transmits to the provider or to his web space provider (so-called server log files):

  • Browser type and version;
  • the operating system used;
  • website from which the user has switched to the provider's website (referrer URL);
  • website that the user visits;
  • date and time of access;
  • Internet Protocol (IP) address of the user.

The data is also stored temporarily. This data is not stored together with other personal data of the user. The legal basis for temporary storage is Art. 6 para. 1 lit. f DSGVO on the basis of the legitimate interest in improving the stability, functionality and security of the website.

Nach spätestens sieben Tagen werden die Daten gelöscht. Daten, deren weitere Aufbewahrung zu Beweiszwecken erforderlich ist, sind bis zur endgültigen Klärung des jeweiligen Vorfalls von der Löschung ausgenommen.

 

Cookies

a) 'session' cookies/ 'persistent' cookies

The provider uses so-called cookies on his website. Cookies are small text files or other storage technologies that the Internet browser used by the user places and stores on the terminal device. These cookies process certain user information to an individual extent, such as browser and location data and IP address values.

The processing allows the provider to make his website more user-friendly, effective and secure. For example, the processing of "session" cookies enables the reproduction of content in different languages or, if necessary, the use of a shopping basket function.

The "persistent" cookies allow the website to recognize the user via his browser during a timely repeated visit to the website.

If personal data are processed by these cookies for the purpose of contract initiation or contract processing, the legal basis for processing is Art. 6 para. 1 lit. b DSGVO.

If the processing does not have the purpose of initiating or processing a contract, the processing serves the legitimate interest of the provider in improving the functionality of the website and is based on the legal basis of Art. 6 para. 1 lit. f DSGVO.

The "session" cookies are deleted when the user closes his browser. The "persistent" cookies are automatically deleted after a period specified by the provider. This period varies depending on the cookie, but does not exceed a period of one day.

b) Cookies from third party providers

If necessary, cookies from third parties are also used on the provider's website. These third parties are partner companies with whom the provider cooperates for the purpose of advertising, analysis or the functionality of the website. Should this be the case, the purposes and legal basis of the corresponding processing are set out in the following statements.

c) Possibility of removal

The user can prevent or restrict the installation of cookies by means of a corresponding setting in the browser. Already stored cookies can also be deleted at any time. The settings for this depend on the respective browser. In the case of flash cookies, processing cannot be prevented by the browser settings, but by the corresponding setting of the flash player. If the user prevents or restricts the installation of cookies, this may mean that not all functions of the website can be fully used.

Contract execution

a) Processing

The personal data provided by the user for the purpose of purchasing goods or services will be processed by the provider for the purpose of contract implementation. The data is required for the conclusion of the contract; without the provision of the data, the conclusion of the contract is not possible. The legal basis for the processing is Art. 6 para. 1 lit. b DSGVO. After complete processing of the contract, the user's data will be deleted with regard to tax and commercial law retention periods.

b) Passing on

The user's personal data will be passed on to a service provider used for the processing of the purchase of goods or services, to the transport company commissioned with the delivery or to the financial service provider within the framework of the contract processing, insofar as this is necessary for the processing, delivery or payment of the goods.

The legal basis for the transfer of data is Art. 6 para. 1 lit. b DSGVO.

 

Note about PayPal:

If the customer chooses the payment service provider PayPal, PayPal may ask for creditworthiness for certain payment methods also chosen by the customer. For more information on the processing of the customer's personal data by PayPal, please see https://www.paypal.com/de/webapps/mpp/ua/privacy-full .

 

Customer account

Should the user register for a customer account with the provider, the data entered in the course of this registration (e.g. name, address, e-mail address) will be collected and stored exclusively for the fulfilment of a contract or the implementation of pre-contractual measures and for the general administration of the customer relationship (e.g. retrieval of previous orders or notepad function). With the registration, the IP address and the date and time of registration are also stored. The data will not be passed on to third parties.

The legal basis is Art. 6 Para. 1 lit. a DSGVO if the user has given his consent. During the registration process, the user's express consent to the above processing may be obtained and reference will be made to this data protection declaration. The data thus collected will be used exclusively for the aforementioned purpose. It will not be passed on to third parties.

If the opening of the customer account serves the fulfilment of a contract or the implementation of pre-contractual measures, the additional legal basis is Art. 6 para. 1 lit. b DSGVO.

The user can revoke a granted consent for the customer account at any time by notifying the provider in accordance with Art. 7 Para. 3 DSGVO. The data processed in connection with this will be deleted as soon as their processing is no longer necessary. If the data is required for the fulfilment of a contract or for the implementation of pre-contractual measures, the user's data will be deleted upon expiry of the retention periods under tax and commercial law.

 

Contact requests

If the user contacts the provider - via contact form or e-mail - the personal data of the user entered on this occasion will be used to process the request. The data is required to answer the enquiry. Without the provision of the data, an answer is not possible or only possible to a limited extent.

If the contact request serves the fulfilment of a contract or the implementation of pre-contractual measures, the legal basis is Art. 6 para. 1 lit. b DSGVO.

The user's data will be deleted if the user's enquiry has been finally answered and no legal storage obligations, e.g. in the case of subsequent contract implementation, stand in the way. 

The legal basis can also be a consent of the user according to Art. 6 para. 1 lit. a DSGVO. Within the framework of the contact form, the user's consent to the above processing may be obtained and reference is made to this data protection declaration.

The user can revoke a granted consent for the contact request at any time according to Art. 7 para. 3 DSGVO by notifying the provider. The data processed in connection with this will be deleted as soon as their processing is no longer necessary.

 

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter "Google".

Google is certified according to the "EU-US Privacy Shield" and thus guarantees compliance with the data protection regulations of the EU when processing data in the USA.  

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Google Analytics serves the provider to analyse the use of the website. The legal basis for this is Art. 6 para. 1 lit. f DSGVO. The provider has a legitimate interest in the analysis, optimisation and economic operation of the website.

Information, such as time, place and frequency of the user's website visit, including the user's IP address, is transferred to a Google server in the USA and stored there.

The provider uses Google Analytics with an anonymisation function for this purpose. By this addition, IP address in this case is already shortened by Google within member states of the European Union or in other states of the agreement on the European Economic Area.

Google will use the data thus collected to evaluate the user's visit to the website and compile reports on website activities for the provider. In addition, the data will be used to provide further services associated with the use of the website and the Internet. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf.

Google will, according to its own information, under no circumstances connect the IP address of the user with other Google data. Google offers further information, in particular on the possibilities of preventing the use of data, under the following link: https://www.google.com/intl/de/policies/privacy/partners

Google also offers a deactivation add-on for the most common browsers, which gives the user more control over what information is collected by Google about the website the user visits. The add-on informs the JavaScript (ga.js) of Google Analytics that no information about the website visit should be transmitted to Google Analytics. However, the deactivation add-on for browsers of Google Analytics does not prevent information from being transmitted to the provider or to other web analysis services that may be used by the provider and that are listed in this privacy policy. Further information on installing the browser add-on can be found at the following link:  Browser add-on for deactivating Google Analytics

Alternatively, the future analysis of the site visit by Google Analytics can be deactivated by "clicking" on the following link. By "clicking" on the link, a so-called "opt-out cookie" is set, with the consequence that the analysis of the page visit on the provider's website is prevented in the future:

Activate "Opt-Out-Cookie" for Google Analytics

Please note: If the user deletes the cookies in his browser settings, the opt-out cookie is usually also deleted and may have to be reactivated by the user.

Google Maps

The provider uses the component "Google Maps" of the company Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter "Google", to provide directions to the location.

Google is certified in accordance with the "EU-US Privacy Shield" and thus guarantees compliance with EU data protection regulations when processing data in the USA.

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

When the "Google Maps" component is called up, Google sets cookies in order to process user settings and data when displaying the page and the associated functions on which the "Google Maps" component is integrated. It cannot be ruled out that external Google servers in the USA may be used for this purpose.

The legal basis for this is Art. 6 para. 1 lit. f DSGVO. The provider has a legitimate interest in optimising the functionality of the website.

Through the connection, Google can recognize from which website an inquiry is sent and to which IP address the representation of the approach is transmitted.

If the user does not agree with this processing, it is possible to prevent the installation of cookies by adjusting the browser settings accordingly. For further details, please refer to the "Cookies" section above.

The use of "Google Maps" and the information obtained via "Google Maps" is subject to the Google Terms of Use and the additional terms and conditions for Google Maps.

Google offers further information, in particular on the possibilities of preventing the use of data, at the following links:

https://policies.google.com/privacy

https://adssettings.google.com/authenticated.

 

Google reCAPTCHA

In order to ensure that interactions on the website are carried out by persons and not by automated processing (for example by "bots"), the provider uses the "reCAPTCHA" component of the company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter "Google".

Google is certified in accordance with the "EU-US Privacy Shield" and thus guarantees compliance with EU data protection regulations when processing data in the USA.

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

This function enables Google to recognize from which website a request is sent and with which IP address the "reCAPTCHA" input box is used. In addition to the IP address, Google may collect other information necessary for the function of the service.

The legal basis for this is Art. 6 para. 1 lit. f DSGVO. The legitimate interest of the provider is to ensure the availability of the website and to prevent spam.

Google offers further information on the general handling of user data under the following link: https://policies.google.com/privacy