Current as of 21 Oct 2024
Privacy Policy
Your privacy is important to us at Cert-Rep. We respect your privacy regarding any information we may collect from you across our website.
1) Introduction and Contact Details of the Responsible Party
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data includes all data that can be used to personally identify you.
1.2 The responsible party for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is TerrainQ Solutions UG (limited liability), Franz-Ehrlich-Straße 12, 12489 Berlin, Germany, Tel.: +49 30 27692390, Email: info@cert-rep.com. The person responsible for processing personal data is the individual or legal entity that decides, either alone or jointly with others, on the purposes and means of processing personal data.
2) Data Collection When Visiting Our Website
2.1 When using our website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to the server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website:
-
The website visited
-
Date and time of access
-
Amount of data sent in bytes
-
Source/referral from which you reached the site
-
Browser used
-
Operating system used
-
IP address used (if applicable: in anonymized form)
Processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be shared or used in any other way. However, we reserve the right to retrospectively check the server log files if there are concrete indications of illegal use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser bar.
3) Hosting & Content Delivery Network
3.1 Amazon Web Services
For hosting our website and displaying its content, we use the system of the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.
All data collected on our website is processed on the provider's servers.
We have signed a data processing agreement with the provider to ensure the protection of our website visitors' data and to prevent unauthorized disclosure to third parties.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
3.2 Wix
For hosting our website and displaying its content, we use the system of the following provider: Wix HQ, 6350671, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel.
Data is also transferred to: Wix Inc., 500 Terry A. Francois Boulevard, San Francisco, California 94158, USA.
All data collected on our website is processed on the provider's servers.
We have signed a data processing agreement with the provider to ensure the protection of our website visitors' data and to prevent unauthorized disclosure to third parties.
For data transfers to the provider's location, an adequate level of data protection is guaranteed by a decision of the European Commission.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
3.3 Google Cloud CDN
We use a content delivery network provided by: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
This service enables us to deliver large media files, such as graphics, content, or scripts, faster through a network of regionally distributed servers. Processing is carried out to safeguard our legitimate interest in improving the stability and functionality of our website under Art. 6(1)(f) GDPR.
Data may also be transferred to: Google LLC, USA.
We have signed a data processing agreement with the provider to ensure the protection of our website visitors' data and to prevent unauthorized disclosure to third parties.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period, allowing the saving of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser’s cookie settings.
If personal data is processed by individual cookies that we use, processing is carried out in accordance with Art. 6(1)(b) GDPR either for the performance of the contract, in accordance with Art. 6(1)(a) GDPR in the case of consent, or in accordance with Art. 6(1)(f) GDPR to safeguard our legitimate interests in providing the best possible functionality of the website as well as a customer-friendly and effective design of the website visit.
You can configure your browser to notify you when cookies are set, allow you to decide individually whether to accept cookies, or reject cookies in certain cases or generally.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contacting Us
When contacting us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your inquiry and only to the extent necessary for this purpose.
The legal basis for processing this data is our legitimate interest in responding to your inquiry in accordance with Art. 6(1)(f) GDPR. If your inquiry is aimed at concluding a contract, an additional legal basis for the processing is Art. 6(1)(b) GDPR. Your data will be deleted when it is clear that the matter in question has been fully resolved, provided there are no legal retention obligations.
6) Data Processing for Order Handling
6.1 To the extent necessary for the performance of the contract for delivery and payment purposes, the personal data we collect will be passed on to the assigned transport company and financial institution under Art. 6(1)(b) GDPR.
If we are obligated under a corresponding contract to provide you with updates for goods with digital elements or for digital products, we will process the contact details you provided during the order (name, address, email) to inform you about upcoming updates in the legally prescribed period via an appropriate communication method (e.g., by mail or email) in accordance with our legal information obligations under Art. 6(1)(c) GDPR. Your contact details will be strictly used for communications about the updates we owe and will only be processed to the extent necessary for that purpose.
In order to process your order, we also work with the following service providers who support us fully or partially in the execution of contracts. Personal data is transferred to these service providers as described below.
6.2 Use of Payment Service Providers (Payment Services)
-
Stripe
This website offers one or more online payment methods from the following provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
If you choose a payment method offered by the provider where you pay in advance (e.g., credit card payment), your payment data provided during the order process (including name, address, bank and card details, currency, and transaction number) as well as information about your order will be transferred to the provider for payment processing under Art. 6(1)(b) GDPR. The transfer of your data is solely for the purpose of processing the payment and only to the extent necessary for that purpose.
If you choose a payment method where the provider makes an advance payment (e.g., invoice or installment purchase, direct debit), you will be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and, if applicable, data related to an alternative payment method).
To safeguard our legitimate interest in determining our customers' payment ability, this data is transferred to the provider for a credit check under Art. 6(1)(f) GDPR. The provider checks based on the personal data provided, as well as other data (such as shopping cart, invoice amount, order history, and payment experience), whether the selected payment option can be granted in relation to payment and/or default risk.
The credit report may contain probability values (so-called score values). Where score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical method. Address data is included, among other things, in the calculation of score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if it is necessary for the contractual payment processing.
7) Web Analytics Services
7.1 Google Analytics 4
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables us to analyze your use of our website.
By default, Google Analytics 4 sets cookies when you visit the website, which are small text files stored on your device and collect certain information. This information includes your IP address, which, however, is truncated by Google to exclude direct personal identification.
The information is transmitted to and processed on Google’s servers. Transfers to Google LLC in the USA may also occur.
Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website and internet usage. The IP address transmitted by your browser in the context of Google Analytics and truncated will not be merged with other Google data. Data collected via Google Analytics 4 will be stored for two months and then deleted.
All the aforementioned processing, particularly the setting of cookies on your device, only takes place if you have given us your express consent in accordance with Art. 6(1)(a) GDPR. Without your consent, Google Analytics 4 will not be used during your visit. You can withdraw your consent at any time with future effect by deactivating this service via the “Cookie Consent Tool” provided on the website.
We have signed a data processing agreement with Google to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.
Further legal information regarding Google Analytics 4 can be found at: https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de, and https://policies.google.com/technologies/partner-sites.
Demographic Features
Google Analytics 4 uses the “demographic features” function to generate statistics that can provide insights into the age, gender, and interests of website visitors. This is done through the analysis of advertising and information from third parties. Target groups for marketing activities can thus be identified. However, the collected data cannot be assigned to any specific individual and will be deleted after two months.
Google Signals
As an extension to Google Analytics 4, this website may use Google Signals to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google, subject to your consent to the use of Google Analytics in accordance with Art. 6(1)(a) GDPR, can analyze your usage behavior across devices and create database models, including cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can disable “Personalized Advertising” in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de. More information about Google Signals can be found at: https://support.google.com/analytics/answer/7532985?hl=de.
User IDs
As an extension to Google Analytics 4, this website may use the “User IDs” feature. If you have consented to the use of Google Analytics 4 under Art. 6(1)(a) GDPR, created an account on this website, and logged in on various devices, your activities, including conversions, can be analyzed across devices.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
7.2 Google Tag Manager
This website uses “Google Tag Manager,” a service provided by: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Google Tag Manager provides a technical foundation for bundling and managing various web applications, including tracking and analytics services, through a unified user interface. Google Tag Manager itself does not store or read any information on user devices and does not perform its own data analyses. However, your IP address may be transmitted to Google and stored when Google Tag Manager is used. Transfers to Google LLC in the USA may also occur.
This processing only takes place if you have given us your express consent in accordance with Art. 6(1)(a) GDPR. Without this consent, Google Tag Manager will not be used during your visit. You can withdraw your consent at any time with future effect by deactivating this service in the “Cookie Consent Tool” provided on the website.
We have signed a data processing agreement with Google to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
Further legal information regarding Google Tag Manager can be found at: https://business.safety.google/intl/de/privacy/ and https://policies.google.com/privacy?hl=de&gl=de.
7.3 Wix Analytics
This website uses the web analytics service provided by: Wix HQ, 6350671, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel.
Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms to read device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used such as the IP address and browser details, in order to evaluate usage patterns on our website for statistical analysis and to create pseudonymized usage profiles. Among other things, this allows the evaluation of movement patterns (so-called heatmaps), which display the duration of page visits and interactions with page content (e.g., text inputs, scrolling, clicks, and mouse-overs). Pseudonymization generally prevents direct personal identification. Data collected in this way is not merged with other clear data about your person.
All the above-mentioned processing, especially reading or storing information on the device used, will only take place if you have given us your express consent under Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect by deactivating this service in the “Cookie Consent Tool” provided on the website.
We have signed a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.
For data transfers to the provider’s location, an adequate level of data protection is guaranteed by a decision of the European Commission.
8) Retargeting/Remarketing and Conversion Tracking
Google Ads Conversion Tracking
This website uses the online advertising program "Google Ads" and, as part of Google Ads, the conversion tracking service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use the Google Ads service to draw attention to our attractive offers on external websites through advertising materials (known as Google AdWords). Based on the data from the advertising campaigns, we can determine the success of individual advertising measures. Our aim is to show you ads that interest you, make our website more attractive to you, and enable a fair calculation of advertising costs.
A conversion tracking cookie is set when a user clicks on an ad placed by Google Ads. Cookies are small text files that are stored on your device. These cookies generally expire after 30 days and are not intended for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie, meaning cookies cannot be tracked across the websites of Google Ads customers. The information collected using the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. Customers are informed of the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that personally identifies users. As part of the use of Google Ads, personal data may also be transmitted to Google LLC's servers in the USA.
Details about the data processing triggered by Google Ads Conversion Tracking and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites.
All the aforementioned processing, especially the setting of cookies for reading information on the device used, only takes place if you have given us your express consent in accordance with Art. 6(1)(a) GDPR. You can revoke your consent at any time with future effect by deactivating this service in the "Cookie Consent Tool" provided on the website.
Additionally, you can permanently object to the setting of cookies by Google Ads Conversion Tracking by downloading and installing the browser plug-in available at the following link: https://www.google.com/settings/ads/plugin?hl=de.
Please note that certain functions of this website may not be available or may be limited if you disable the use of cookies.
Google's privacy policy is available here: https://business.safety.google/intl/de/privacy/and https://www.google.de/policies/privacy/.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on a decision of the European Commission.
9) Tools and Miscellaneous
9.1 - DATEV
For handling accounting, we use the service of the cloud-based accounting software provided by the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany.
The provider processes incoming and outgoing invoices as well as, where applicable, our company’s bank transactions to automatically record invoices, match them to transactions, and generate the financial accounting in a partially automated process.
If personal data is processed in this context, the processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in efficient organization and documentation of our business transactions.
9.2 Cookie Consent Tool
This website uses a "Cookie Consent Tool" to obtain effective user consent for cookies and cookie-based applications requiring consent. The "Cookie Consent Tool" is presented to users in the form of an interactive user interface upon page access, where they can consent to certain cookies and/or cookie-based applications by ticking checkboxes. Through the tool, all cookies/services that require consent will only be loaded when the respective user gives their consent by ticking the checkboxes. This ensures that such cookies are only set on the respective user's device if consent has been granted.
The tool sets technically necessary cookies to store your cookie preferences. Personal user data is not processed in this context.
In cases where personal data (such as the IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in legally compliant, user-specific, and user-friendly cookie consent management, as well as in a legally compliant design of our website.
Additionally, the legal basis for the processing is Art. 6(1)(c) GDPR. As the responsible party, we are legally obliged to make the use of non-essential cookies dependent on the respective user's consent.
Where necessary, we have signed a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.
Further information about the operator and the settings options of the Cookie Consent Tool can be found directly in the corresponding user interface on our website.
10) Rights of the Data Subject
10.1 The applicable data protection law grants you the following rights (information and intervention rights) with respect to the processing of your personal data by the responsible party, with reference to the respective legal basis for the conditions of exercising these rights:
-
Right to access in accordance with Art. 15 GDPR;
-
Right to rectification in accordance with Art. 16 GDPR;
-
Right to erasure in accordance with Art. 17 GDPR;
-
Right to restriction of processing in accordance with Art. 18 GDPR;
-
Right to notification in accordance with Art. 19 GDPR;
-
Right to data portability in accordance with Art. 20 GDPR;
-
Right to withdraw consent granted in accordance with Art. 7(3) GDPR;
-
Right to lodge a complaint in accordance with Art. 77 GDPR.
10.2 Right to Object
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTERESTS AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE, OR DEFEND LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES. YOU MAY EXERCISE THE RIGHT TO OBJECT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.
11) Duration of Storage of Personal Data
The duration of the storage of personal data depends on the respective legal basis, the processing purpose, and—if applicable—also on the relevant statutory retention periods (e.g., commercial and tax retention periods).
When personal data is processed on the basis of explicit consent in accordance with Art. 6(1)(a) GDPR, the data concerned will be stored as long as you do not withdraw your consent.
If statutory retention periods apply to data processed as part of contractual or quasi-contractual obligations based on Art. 6(1)(b) GDPR, this data will be routinely deleted after the retention periods expire, provided it is no longer required for the fulfillment of the contract or the initiation of a contract, and/or there is no legitimate interest on our part in continuing to store the data.
When personal data is processed on the basis of Art. 6(1)(f) GDPR, this data will be stored until you exercise your right to object under Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
When personal data is processed for direct marketing purposes on the basis of Art. 6(1)(f) GDPR, this data will be stored until you exercise your right to object under Art. 21(2) GDPR.
Unless otherwise stated in this privacy policy, personal data that has been stored will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.