Privacy policy
November 2024
Protecting your data matters to us. That is why we follow the statutory data protection rules (GDPR) and go further still to keep your data safe. The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states of the European Union (EU), as well as other data protection provisions, is:
fjnland GmbH
Frankfurter Straße 87
Gebäude 13 (Picherei)
D-97082 Würzburg
dse@fjnland.de
1.1. Processing of personal data
Data protection applies to the processing of personal data. Personal means any data by which you can be identified. That is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are sitting in front of. Such data is processed whenever "something happens to it". Here, for example, the IP is transmitted from the browser to our provider and stored there automatically. That is then processing (within the meaning of Art. 4 no. 2 GDPR) of personal data (under Art. 4 no. 1 GDPR). These and further statutory definitions can be found in Art. 4 GDPR.
1.2. Applicable rules and laws
The scope of data protection is set by law. In this case that is the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as national law. The TTDSG also supplements the GDPR rules where the use of cookies is concerned.
1.3. The controller
The controller for data processing on this website is the controller within the meaning of the GDPR. That is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data. You can reach the controller using the contact details given above.
1.4. Processing in general
As we have already noted, there is data (e.g. IP address) that is collected automatically. This data is needed mainly to make the website technically available. Where we use personal data beyond that, or collect other data, we will inform you or ask for consent. Other personal data you share with us deliberately. You will find detailed information on this further down.
1.5. Your rights
The GDPR gives you extensive rights. These include, for example, free information about the origin, recipients, and purpose of your stored personal data. You can also request the rectification, restriction, or erasure of this data, or lodge a complaint with the competent data protection supervisory authority. You can withdraw consent you have given at any time. How these rights look in detail and how to exercise them is set out in the last section of this privacy notice.
1.6. How we see data protection
Data protection is more than a tiresome duty for us. Personal data has real value, and careful handling of it should be a given in our digital world. As a website visitor, you should also be able to decide for yourself what happens to your data, when, and by whom. That is why we commit to complying with all statutory provisions, collect only the data we need, and of course treat it confidentially.
1.7. Disclosure and erasure
Disclosure and erasure of data are also important and sensitive topics. That is why we want to briefly explain our general approach up front. Data is disclosed only on a legal basis and only where it is unavoidable. That can be the case in particular where a so-called processor is involved and a processing agreement under Art. 28 GDPR has been concluded. We erase your data when the purpose and the legal basis for processing cease to apply and no other statutory obligations stand in the way of erasure. Art. 17 GDPR also gives a useful overview. Please take all further information from this privacy notice and, for specific questions, contact the controller.
1.8. Legal bases
The processing of personal data always needs a legal basis. In the following sections we will name the specific legal basis for each processing. Art. 6(1) sentence 1 GDPR provides for the following possibilities:
the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
processing is necessary for compliance with a legal obligation to which the controller is subject;
processing is necessary in order to protect the vital interests of the data subject or of another natural person;
processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
What happens on our website
By visiting our website we process personal data of yours. To protect this data as well as possible against unauthorised interference by third parties, we use SSL or TLS encryption. You can recognise this encrypted connection by an https:// or a padlock symbol in the address bar of your browser. Below you will learn which data is collected when you visit our website, for what purpose, and on which legal basis.
2.1. Hosting
This website is hosted externally. The personal data collected on this website is stored on the hoster's servers. This includes the automatically collected and stored log files (more on this below), as well as any other data that website visitors provide.
External hosting is for the purpose of making our website available securely, quickly, and reliably, and in this context serves the performance of contracts with our potential and existing clients. The legal basis for the processing is Art. 6(1)(a), (b) and (f) GDPR, as well as section 25(1) TTDSG, insofar as consent covers the storage of cookies or access to information on the end device of the website visitor or user within the meaning of the TTDSG.
Our hoster processes only such data as is required to fulfil its service obligations and acts as our processor, meaning it is bound by our instructions. We have concluded a corresponding processing agreement with our hoster.
Provider: Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands
2.2. Data collection when the website is accessed
When the website is accessed, information is automatically stored in so-called server log files. This includes the following information:
browser type and browser version
operating system used
Referrer URL
host name of the accessing computer
time of the server request
IP address
This data is needed temporarily so that we can display our website to you continuously and without problems. In particular, the data serves the following purposes:
system security of the website
system stability of the website
troubleshooting on the website
establishing the connection to the website
display of the website
The data is processed pursuant to Art. 6(1)(f) GDPR and is based on our legitimate interest in processing this data, in particular our interest in the functionality of the website and its security. This data is stored in pseudonymised form where possible and erased once the respective purpose has been achieved. Where the server log files make it possible to identify the data subject, the data is stored for a maximum of 14 days. An exception applies if a security-relevant event occurs. In that case the server log files are stored until the security-relevant event has been resolved and fully investigated.
Otherwise the data is not combined with other data.
2.3. Cookies
This website uses so-called cookies. A cookie is a data record, information stored in the browser of your end device and related to our website. Setting cookies can in particular make it easier for visitors to navigate the website.
Rejecting cookies: Cookies can be prevented by adjusting your browser settings. Here you will find the relevant links for frequently used browsers:
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?redirectslug=Cookies+l%C3%B6schen&redirectlocale=de
Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de
Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Safari: https://support.apple.com/de-de/guide/mdm/mdmf7d5714d4/web und https://support.apple.com/de-de/guide/safari/sfri11471/mac If you use a different browser, we recommend entering the name of your browser and 'delete and manage cookies' in a search engine and following the official link to your browser.
Alternatively you can also manage your cookie settings at www.aboutads.info/choices/ www.youronlinechoices.com. We must point out, however, that comprehensively blocking or deleting cookies can impair the use of the website.
Technically necessary cookies: We use technically necessary cookies on this website so that our website works without errors and in accordance with applicable law. They help make the website user-friendly. Some functions of our website cannot be displayed without the use of cookies.
Cookies that are not technically necessary: We also use cookies on our website that are not technically necessary. These cookies serve, among other things, to analyse the browsing behaviour of the website visitor or to offer functions of the website that are not strictly necessary from a technical point of view. The legal basis for this is your consent pursuant to Art. 6(1)(a) GDPR. Cookies that are not technically necessary are set only with your consent, which you can withdraw at any time in the cookie consent tool.
2.4. Data processing through user input
If you contact us by email, we process your email address and, where applicable, further data contained in the email. This is stored on the mail server and in part on the respective end devices. Depending on the matter, the legal basis is regularly Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR. The data is erased as soon as the respective purpose ceases to apply and erasure is possible under statutory requirements.
If you contact us by telephone, the call data may be stored in pseudonymised form on the respective end device and with the telecommunications provider used. Personal data collected during the call is processed solely to handle your enquiry. Depending on the matter, the legal basis is regularly Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR. The data is erased as soon as the respective purpose ceases to apply and erasure is possible under statutory requirements.
To let you book an appointment with us, we embed the functions of cal.com. This service is offered by cal.com Inc., 5220 Cabrito Dr, Lay Vegas, Nevada, 89103, USA. For the purpose of booking an appointment, personal data is requested and entered in the form provided, in particular name, company name, postal address, telephone number and email address, and where applicable financial qualification and billing data such as invoice name and address and credit card number, as well as the preferred appointment. The data entered is used for planning, conducting, and where applicable following up on the appointment. The legal basis for the use of cal.com is Art. 6(1)(f) GDPR, as we have a legitimate interest in entering into direct exchange with clients, potential clients and other interested parties, and in handling enquiries immediately and as quickly as possible. The data is stored until the data subject requests erasure, withdraws consent to storage, or the purpose for storage has ceased to apply. Mandatory statutory retention periods remain unaffected. For data transfers to the USA, the standard contractual clauses (SCCs) of the EU Commission apply. Further information: https://cal.com/de/privacy.
Cookies that are not essential are set only with consent. This consent can be withdrawn at any time. The legal basis for this is Art. 6(1)(a) GDPR and section 25(1) TTDSG, insofar as this consent covers access to information on the user's end device or the storage of cookies within the meaning of the TTDSG. In addition, the legal basis for the use of Tally is Art. 6(1)(f) GDPR. We have a legitimate interest in creating online forms and embedding them in working order on our website. Insofar as processing via the form serves the offering of our contractual services, the legal basis is Art. 6(1)(b) GDPR. Data entered into the form by the website visitor is stored on Tally's servers until the website visitor requests erasure, a given consent to storage is withdrawn, or the purpose for storing the data ceases to apply. Mandatory statutory retention periods remain unaffected. Further information: https://tally.so/help/privacy-policy.
We use Loops to provide our newsletter. This service is offered by Astrodon Inc., 9450 SW Gemini Dr, PMB 22902, Beaverton, Oregon 97008-7105, USA. This service can be used to organise and analyse the sending of newsletters. The data entered in order to receive the newsletter is stored on Loops servers. With the help of Loops, interactions with the newsletter can be analysed. Conversion rates can also be determined and newsletter users categorised in order to adapt the newsletter to different target groups. The legal basis for the processing is Art. 6(1)(a) GDPR and section 25(1) TTDSG. Consent can be withdrawn at any time by unsubscribing from the newsletter. The lawfulness of processing already carried out remains unaffected by any withdrawal.
We also use further email services from Loops to perform our contractual services and for client administration. The legal basis for this is Art. 6(1)(b) GDPR. The data is erased at the end of the contract between us and Loops , unless the website visitor withdraws consent before then. If that is the case, the data is deleted from the mailing list. For data transfers to the USA, the standard contractual clauses (SCCs) of the EU Commission apply. Further details: https://loops.so/privacy.
2.5. Analytics and tracking tools
We embed the functions of plausible.io on our website. This is a service of Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonia. Plausible is an open source analytics tool. All measurements on the website are carried out in a fully anonymous way. No cookies are used and no personal data is collected. There are no persistent identifiers. Nor is there any cross-site or cross-device tracking. Website data is not used for other purposes. All visitor data is processed exclusively with servers that are owned and operated by European companies, and it never leaves the EU.
The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in analysis to ensure the technical stability and maximum performance of our online presence. Further information: https://plausible.io/data-policy.
2.6. Embedding of third-party content
Spotify: We use the Spotify plugin on this website. Spotify is a music streaming service. This service is offered by SoundCloud Limited, Berners House, 47-48 Berners Street, London W1T 3NF, United Kingdom. After the plugin is activated, a visit to the website establishes a direct connection between the website visitor's browser and the Spotify server. Spotify thereby receives the information that the website was visited with this IP address. If the website visitor is logged in with a Spotify user account, Spotify can associate the visit to this website with the user account. When Spotify is used, cookies from Google Analytics are set. Usage data may also be passed on to Google. Spotify alone is responsible for embedding these cookies. The legal basis for the processing is Art. 6(1)(a) GDPR and section 25(1) TTDSG. Consent can be withdrawn at any time. Further details: https://www.spotify.com/de/legal/privacy-policy/.
2.7. Audio and video conferences
Zoom: We use Zoom for communication with clients. Zoom is an online conferencing tool. This service is offered by Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.
When communicating with this tool via video or audio conferences, personal data is processed by us and by the provider of the tool. The data collected includes all information you provide when using the tool. Metadata relating to the conference is also processed. In addition, technical information needed for the online communication to function is processed. Furthermore, all files shared within the tool are stored on the tool provider's servers. Zoom may also set cookies. These cookies are set only with consent. Consent can be withdrawn at any time. The legal basis for this is Art. 6(1)(a) GDPR. Otherwise, the legal basis for Zoom's processing of the data is Art. 6(1)(b) GDPR. The communication is related to the performance of a contract or is necessary to take pre-contractual steps. The tool is also used to simplify communication with our company. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
This data is stored until the data subject requests erasure, consent to storage has been withdrawn, or the purpose for storage has ceased to apply. Cookies remain on the end device until the user deletes them. Mandatory statutory retention periods remain unaffected. For data transfers to the USA, the standard contractual clauses (SCCs) of the EU Commission apply. Further information: https://zoom.us/de-de/privacy.html.
Google Meet: We use Google Meet for communication with clients. Google Meet is an online conferencing tool. This service is offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When communicating with this tool via video or audio conferences, personal data is processed by us and by the provider of the tool. The data collected includes all information you provide when using the tool. Metadata relating to the conference is also processed. In addition, technical information needed for the online communication to function is processed. Furthermore, all files shared within the tool are stored on the tool provider's servers. Google Meet may also set cookies. These cookies are set only with consent. This consent can be withdrawn at any time. The legal basis for this is Art. 6(1)(a) GDPR. Otherwise, the legal basis for Google Meet's processing of the data is Art. 6(1)(b) GDPR. The communication is related to the performance of a contract or is necessary to take pre-contractual steps. The tool is also used to simplify communication with our company. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
This data is stored until the data subject requests erasure, consent to storage has been withdrawn, or the purpose for storage has ceased to apply. Cookies remain on the end device until the user deletes them. Mandatory statutory retention periods remain unaffected. Further details: https://policies.google.com/privacy?hl=de.
What else matters
To close, we want to inform you in detail about your rights and tell you how you will be informed about changes to data protection requirements.
3.1. Right of access under Art. 15 GDPR
You can request information as to whether personal data of yours is being processed. If that is the case, you can request further information about the nature and manner of the processing. A detailed list can be found in Art. 15(1)(a) to (h) GDPR.
3.2. Right to rectification under Art. 16 GDPR
This right covers the rectification of inaccurate data and the completion of incomplete personal data.
3.3. Right to erasure under Art. 17 GDPR
This so-called 'right to be forgotten' gives you the right, under certain conditions, to request that the controller erase the personal data. This is generally the case when the purpose of the processing has ceased to apply, when consent has been withdrawn, or when the original processing took place without a legal basis. A detailed list of grounds can be found in Art. 17(1)(a) to (f) GDPR. This "right to be forgotten" also corresponds to the controller's duty under Art. 17(2) GDPR to take appropriate measures to bring about general erasure of the data.
3.4. Right to restriction of processing under Art. 18 GDPR
This right is tied to the conditions in Art. 18(1)(a) to (d).
3.5. Right to data portability under Art. 20 GDPR
This governs the basic right to receive one's own data in a commonly used format and to have it transmitted to another controller. This applies, however, only to data from processing based on consent or contract under Art. 20(1)(a) and (b) and only insofar as this is technically feasible.
3.6. Right to object under Art. 21 GDPR
You can in principle object to the processing of your personal data. This applies in particular where your interest in objecting outweighs the controller's legitimate interest in the processing, and where the processing relates to direct marketing and/or profiling.
3.7. Right to an "individual decision" under Art. 22 GDPR
You have in principle the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. This right is, however, also subject to restrictions and additions in Art. 22(2) and (4) GDPR.
3.8. Right to lodge a complaint under Art. 77 GDPR
You also have the right to lodge a complaint with a data protection supervisory authority if you consider that processing of personal data relating to you infringes this regulation.
3.9. Further rights
The GDPR includes extensive rights to have third parties informed about whether or how you have exercised rights under Art. 16, 17, 18 GDPR. This only insofar as it is possible or can be carried out with reasonable effort. We would like to point you once more to your right to withdraw consent given, under Art. 7(3) GDPR. The lawfulness of processing carried out up to that point is not affected by this.
We would also like to point you to your rights under sections 32 et seq. BDSG, which are for the most part substantively congruent with the rights just described.
The current version of this privacy notice is December 2023. From time to time it is necessary to adapt the content of the privacy notice in order to respond to factual and legal changes. We therefore reserve the right to change this privacy notice at any time. We will publish the amended version in the same place and recommend that you read the privacy notice regularly.
Not enough? Ask your AI about us