Privacy Notice

Privacy Policy

This is a translation of our privacy notice written in German:Datenschutz

Data processing by our company

When using the www.marvelmetrix.com website, its functionalities, through your contact and through your enquiry, you provide us with personal data, which we process for the purpose of processing your enquiries. This data is treated by us strictly earmarked within the context of the Data Protection Act.

Data controller in the sense of the data protection laws:

CodeAndWeb GmbH
Saalbaustraße 61
89233 Neu-Ulm
Germany

Represented by: Andreas Löw

General information on data processing

Scope of processing of personal data in general

We collect and utilise our users’ personal data only insofar as this is necessary for provision of an operational site and of our content and services.

The respective legal basis for the processing of personal data results from the General Data Protection Regulation (GDPR), Article 6 para. 1a – f GDPR.

With the consent of the data subject, Art. 6 para. 1a GDPR serves as a legal basis.

Art. 6 para. 1b GDPR is the legal basis for the processing of personal data for the performance of a contract to which the data subject is a party or for processing operations in pre-contractual measures.

If processing is necessary to fulfil a legal obligation of the data controller, Art. 6 Para. 1c GDPR serves as a legal basis.

If the processing is necessary in the vital interests of the data subject or another natural person, Art. 6 para. 1d GDPR serves as a legal basis.

Where processing is necessary for the performance of a task, which is in the public interest or is carried out in the exercise of official authority conferred on the controller, the legal basis is Art. 6 para. 1e GDPR.

If processing is necessary to safeguard a legitimate interest of our company and if the interests, fundamental freedoms or rights of the data subject do not prevail, the legal basis is Art. 6 para. 1f GDPR.

When you contact us, we collect personal data. This data is stored by us partly due to legal regulations, it is partly necessary for the conclusion of a contract. If you wish to conclude a contract with us, you must provide us with your data so that we can provide our services to you. In addition, we are required by law to keep records for tax and commercial law reasons, which we must comply with. Otherwise we may not be able to provide our services to you.

Before providing your personal data, you are welcome to contact your respective contact person in our company to find out whether we need your data for the conclusion of a contract and/or our legal storage obligations and what consequences it will have if you do not make the data available to us.

Data erasure and storage duration

We store your personal data as long as this is necessary for the fulfilment of the purpose or storage is prescribed by law, Art 6 Para. 1c GDPR. If the purpose for the storage of personal data is no longer given, this data will be deleted after 24 months or the processing will be restricted, unless there is a necessity for further storage of the data for the conclusion of a contract or performance of a contract. Further storage only takes place if this has been provided for by the European or national legislator.

SSL or TLS Encryption

For security reasons and to protect your confidential data, we use SSL or TLS encryption throughout the website. This encryption means that confidential data, such as enquiries or orders that you transmit to us, cannot be viewed by third parties. You can recognise an encrypted connection by the browser’s address line changing from “http://” to “https://” and a lock symbol being displayed in the address line.

Automatic data processing when accessing the website www.marvelmetrix.com

IP - address

1. Description and scope of data processing

When this page is called up, requests are sent to the server, which has to answer them. For this purpose, your IP address must be collected and processed in order to be able to answer the corresponding server enquiries.

The legal basis for processing is your consent under Art. 6 para. 1f GDPR.

3. The purpose of data processing

The purpose of processing your IP address is the functionality of the website and the provision of technical retrieval facilities.

4. Legitimate interest

The legitimate interest in the temporary storage of the IP address lies in the fact that the functionality and provision of the technical accessibility of the website is not possible without this.

5. Duration of storage

The data will be deleted as soon as the further storage is no longer necessary due to the purpose being achieved. When collecting the data for the provision of the website, this is the case when the retrieval process is completed.

6. Recipient of personal data

The IP address is handled by the following hosting providers on behalf of the client on the basis of an order processing agreement in accordance with Art. 28 para. 2, para.4 GDPR:

Hosting

1. Description and scope of data processing

We use the services of our hosting service provider for the technical production of the website and its accessibility as well as its technical maintenance. This includes the provision of storage and database services as well as their maintenance and support.

The legal basis for processing is your consent under Art. 6 para. 1f GDPR.

3. The purpose of data processing

The purpose of the processing is the production of the online offer as well as the recognition of malfunctions and attempts to break in.

4. Legitimate interest

The legitimate interest in commissioning the hosting service provider is the external technical competence and the provision of a functional and uncompromised technical website environment.

5. Recipients of personal data and data categories

The following hosting provisos are provided in the order on the basis of an order processing agreement in accordance with Art. 28 para. 2, para.4 GDPR:

webgo GmbH
Wandsbeker Zollstr. 95
22041 Hamburg
Germany

and

DomainFactory GmbH
Oskar-Messter-Str. 33
85737 Ismaning
Germany

Affected data categories

  • User data
  • Communications data
  • Contact data
  • Contract data

Server log files

1. Description and scope of data processing

The IP addresses collected when this page is called up are also stored in server log files in order to detect technical faults and/or attempts to manipulate or break into the server structure and to make them correctable.

In addition, the hosting provider of this website automatically collects, stores and processes information in so-called server log files, which are automatically transmitted by your browser.

This information is:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request

However, this information is not merged with other data sources.

The legal basis for processing is your consent under Art. 6 para. 1f GDPR.

3. The purpose of data processing

The purpose of processing your IP address and the above information is to detect malfunctions and attempted intrusions.

4. Legitimate interest

The legitimate interest in the processing of the IP address and the above information is the provision of a functional and uncompromised technical website environment.

5. Duration of storage

The data will be deleted within 7 days.

6. Recipient of personal data

The IP address and the above information will be processed by the following hosting provider on behalf of an order processing agreement according to Art. 28 para. 2, para.4 GDPR:

webgo GmbH
Wandsbeker Zollstr. 95
22041 Hamburg
Germany

DomainFactory GmbH
Oskar-Messter-Str. 33
85737 Ismaning
Germany

MarvelMetrix

1. Description and scope of data processing

We use a web analytics tool called MarvelMetrix, developed by us.

The service runs on our servers (see “Hosting”). The visitor’s IP address is not stored in the analytics data. We also honor do-not-track settings of your browser.

MarvelMetrix is used to analyse the behaviour of the website visitors to identify potential pitfalls; not found pages, search engine indexing issues, which contents are the most appreciated… Once the data is processed (number of visitors reaching a not found pages, viewing only one page…), MarvelMetrix is generating reports for website owners to take action, for example changing the layout of the pages, publishing some fresh content… etc.

MarvelMetrix is processing the following personal data:

  • Cookies
  • IP address
  • User ID
  • Location of the user (country, region, city)
  • Date, time and time zone
  • Title of the page being viewed
  • URL of the page being viewed
  • URL of the page that was viewed prior to the current page (Referrer)
  • Screen resolution
  • Events: e.g. Clicking on a link, scroll depth, newsletter sign-up
  • Main Language of the browser
  • User Agent of the browser, Operating system

The processing of personal data with MarvelMetrix is based on legitimate interests.

2. The legitimate interests

The legal basis for processing is your consent under Art. 6 para. 1f GDPR.

3. Recipient of the personal data

The personal data received through MarvelMetrix are sent to:

  • Our company.
  • Our web hosting provider: see above

4. Retention period

We are keeping the personal data captured within MarvelMetrix for a period of 24 months. See section “Cookies” for the storage duration of the cookies.

5. The existence of each of the data subject’s rights

As MarvelMetrix is processing personal data on legitimate interests, you can exercise the following rights:

  • Right of access: you can ask us at any time to access your personal data.
  • Right to erasure: you can ask us at any time to delete all the personal data we are processing about you.
  • Right to object: you can object to the tracking of your personal data by using the following opt-out feature:

Use of cookies

1. Description and scope of data processing

The website www.marvelmetrix.com uses “cookies”. Cookies are text files which are stored in the memory and/or on a data carrier of the device you use to visit the site and which are processed by your Internet browser according to the settings stored there. We use a cookie to determine when you log in to your customer account.

The content of these cookies is:

CookieDurationPurpose
_mm_id,
_mm_ses
up to 24 MonthsMarvelMetrix Web Analysis

The legal basis for processing is your consent under Art. 6 para. 1b and Art. 6 para. 1f GDPR.

3. The purpose of data processing

These cookies contain technical information for the provision of website functionalities within the framework of the order and customer account process. This enables the technical implementation of the purchasing and customer account process.

4. Entitled interest pursuant to Art. 6 para. 1f GDPR

Our legitimate interest lies in providing a technical environment that maps an online purchasing process for our customers and users. The cookies used only contain technical data and product information which technically represent the conclusion of an online purchase by our customers at the initiative of our customers.

Duration of storage, revocation and elimination options

Most cookies used on this site are so-called “session cookies”. These are automatically deleted from the browser cache / memory at the end of your visit to the website and/or when you close your browser, provided you have activated this function in your browser.

The permanent cookies that we use are automatically deleted after their storage period has expired.

Please check the settings of your internet browser (e.g. Firefox, Internet Explorer, Edge, Chrome, Opera, Safari). Your Internet browser also gives you the option of regulating the handling of cookies or deactivating them completely. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all of the website’s features in full.

Processing of personal data via contact form and support form

1. Description and scope of data processing

There is a contact form on our website which is only for electronic contact. We only process your personal data to the extent that you provide it to us when you contact us.

For enquiries via the contact form (help button) the following data will be processed:

  • Name *
  • Email address*
  • Enquiry*

For enquiries via the support form (support pages) the following data will be processed:

  • E-mail address*
  • Product *
  • Operating system*
  • Framework*
  • Importance*
  • Title*
  • Enquiry*

The fields marked with an ”*” symbol are mandatory fields, without which no request can be sent to us via this contact form.

The name is used for personal contact during the processing of your enquiry.

When simply entering the data in the forms, no data is yet transmitted to us; this is only done after the “send message” button has been pressed.

The following data is also stored at the time the message is sent:

  • Date and time of enquiry

The legal basis for the processing of personal data for processing and answering your enquiries is Art. 6 para. 1f GDPR. The legal basis for the processing of personal data used for the preparation and/or implementation of a contractual relationship is Art. 6 para. 1b) GDPR.

3. The purpose of data processing

The processing of personal data via the contact form serves the sole purpose of establishing contact and enabling the company to address the customer informatively at the customer’s initiative. Depending on the intention and content of your inquiry, the purpose can also be the initiation and/or execution of a contractual relationship; in this case, the purpose is also the maintenance of the customer relationship.

4. Legitimate interest

The legitimate interest in data processing lies in the possibility to process your request and to be able to answer you according to your request. The data collected will be processed on the basis of a request made by you. This processing is also in your interest in order to be able to respond to your request according to your expectations.

5. Duration of storage

The data is deleted within 6 months after it is no longer necessary to achieve the purpose of its collection or after no further legal storage obligations (e.g. 10 years according to AO (Fiscal Code), 6 years according to HGB (German Commercial Code)) apply. This is the case when the conversation with the user is finished, for your data entered in the contact form. The conversation is terminated when the circumstances indicate that the matter in question has been finally resolved.

6. Recipient of personal data

The IP address and the above information will be processed by the following hosting provider on behalf of an order processing agreement according to Art. 28 para. 2, para.4 GDPR:

webgo GmbH
Wandsbeker Zollstr. 95
22041 Hamburg
Germany

DomainFactory GmbH
Oskar-Messter-Str. 33
85737 Ismaning
Germany

Zendesk, Inc
1019 Market Street
San Francisco, CA 94103
United States of America
Zendesk is a member of Privacy Shield Agreement

Processing of personal data via e-mail

1. Description and scope of data processing

Depending on the content of your email, personal data will be processed for enquiries by email:

This is, in any case, your email address, date and time as well as the content of the message. In addition, depending on the content of your email, the following personal data can, for example, be processed:

  • First name, surname
  • Phone Number
  • Customer number
  • Payment data
  • Contract data

The data will be used exclusively for the processing of the conversation and/or the execution and/or initiation of a contractual relationship.

On the basis of the user’s express request via email, the legal basis for the processing of the data is Art. 6 para. 1f GDPR. If the establishment of contact by email also aims at the conclusion and/or the execution of a contract, then additional legal basis for the processing is Art. 6 para. 1b) GDPR.

3. The purpose of data processing

The processing of personal data via the email contact form serves the sole purpose of establishing contact and enabling the company to address the customer informatively at the customer’s initiative. Depending on the intention and content of your enquiry, the purpose may also be the initiation and/or execution of a contractual relationship.

4. Legitimate interest

The legitimate interest in data processing lies in the possibility to process your request and to be able to answer you according to your request. The data collected will be processed on the basis of a request made by you. This processing is also in your interest in order to be able to respond to your request according to your expectations.

5. Duration of storage

The data is deleted within 2 months after it is no longer necessary to achieve the purpose of its collection or after no further legal storage obligations (e.g. 10 years according to AO (German Fiscal Code), 6 years according HGB (German Commercial Code)) apply. For your email, this is the case when the conversation with the user is finished.

The conversation is terminated when the circumstances indicate that the matter in question has been finally resolved.

Processing of personal data via telephone

1. Description and scope of data processing

Depending on the content of the call, personal data will be processed for telephone enquiries:

Depending on the information you provide during the telephone call, this may also contain the following personal data:

  • First name, surname
  • Phone Number
  • Customer number
  • Payment data
  • Contract data

The data will be used exclusively for the processing of the conversation and/or the execution and/or initiation of a contractual relationship.

On the basis of the user’s express request via e-mail, the legal basis for the processing of the data is Art. 6 Para. 1f GDPR. If the establishment of contact by e-mail also aims at the conclusion and/or the execution of a contract, then additional legal basis for the processing is Art. 6 Abs. 1b) GDPR.

3. The purpose of data processing

The processing of personal data via the contact form serves the sole purpose of establishing contact and enabling the company to address the customer informatively at the customer’s initiative.

Depending on the intention and content of your enquiry, the purpose may also be the initiation and/or execution of a contractual relationship.

4. Legitimate interest

The legitimate interest in data processing lies in the possibility to process your request and to be able to answer you according to your request. The data collected will be processed on the basis of a request made by you. This processing is also in your interest in order to be able to respond to your request according to your expectations.

5. Duration of storage

The data is deleted within 6 months after it is no longer necessary to achieve the purpose of its collection or after no further legal storage obligations (e.g. 10 years according to AO (German Fiscal Code), 6 years according HGB (German Commercial Code)) apply. For your email, this is the case when the conversation with the user is finished.

The conversation is terminated when the circumstances indicate that the matter in question has been finally resolved.

Newsletter

1. Description and scope of data processing

If you would like to receive our newsletter, we require a valid email address as well as information which allows us to verify that you are the owner of the email address provided and that you agree to receive this newsletter. No additional data is collected or will only be collected on a voluntary basis. We only use this data to send the requested information and do not pass it on to third parties.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 para. 1a GDPR. You can revoke consent to the storage of your data and email address as well as their use for sending the newsletter at any time, e.g. through the “unsubscribe” link in the newsletter. The data processed before we receive your request may still be legally processed.

The data provided when registering for the newsletter will be used to distribute the newsletter until such time as you cancel your subscription, when said data will be deleted. Data we have stored for other purposes (e.g. email addresses for the members area) remains unaffected.

This website uses MailJet to send newsletters. The provider is Mailjet (SAS Mailjet, 30 Rue Blondel, 75002 Paris, FRANCE)

MailJet is a service with which the dispatch of newsletters can be organised and analysed. The data you provide in order to subscribe to our newsletter will be stored on MailJet servers.

If you do not want your use of the newsletter to be analysed by MailJet, you will have to unsubscribe from the newsletter. We provide a link to do this in every newsletter we send. Furthermore, you can also directly unsubscribe from the newsletter on the website.

The click analysis is deactivated with us.

Detailed information about the functions of MailJet can be found in the following link: https://www.mailjet.de/funktion/.

Data processing is based on your consent (Art. 6 para. 1a GDPR). You may revoke your consent at any time. The data processed before we receive your request may still be legally processed.

3. Storage duration

The data provided when registering for the newsletter will be used to distribute the newsletter until such time as you cancel your subscription, when said data will be deleted from our servers and those of MailJet. Data stored by us for other purposes (e.g. email addresses for registration remain unaffected by this).

4. Recipient of personal data

The data is processed by the following dispatch service providers on behalf of the customer on the basis of an order processing agreement in accordance with Art. 28 para. 2, para.4 GDPR:

  • Name
  • Email address

The data is processed by the following dispatch service providers on behalf of the customer on the basis of an order processing agreement in accordance with Art. 28 para. 2, para.4 GDPR:

SAS Mailjet
30 Rue Blondel
75002, Paris
France

webgo GmbH
Wandsbeker Zollstr. 95
22041 Hamburg
Germany

DomainFactory GmbH
Oskar-Messter-Str. 33
85737 Ismaning
Germany

Categories of data:

  • Order data
  • Product specification
  • Address data

Rights of the data subject

If your personal data is processed, you are the data subject within the meaning of the General Data Protection Regulation. Therefore, you have the following rights regarding the data controller.

To exercise your rights towards us as the data subject, please contact us at the following email address: privacy@marvelmetrix.com

1. Right to information - Art. 15 GDPR

You have the right to request confirmation from us as to whether we are processing personal data relating to you.

If such processing exists, you have a right of access to this personal data and to the following information:

  • the purposes for processing the personal data
  • the categories of personal data being processed
  • the recipients or categories of recipients to whom your personal data has been or will be disclosed
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
  • the existence of a right of rectification or deletion of your personal data or of a restriction on processing by the data controller or of a right to oppose such processing
  • the existence of a right of appeal to a supervisory authority
  • any available information on the origin of the data if the personal data has not been collected from the person concerned
  • the existence of automated decision-making, including profiling, in accordance with Art. 22 Para. 1 and 4 of the GDPR and – at least in these cases – meaningful information on the logic involved and the scope and intended effects of such processing for the data subject

You have the right to request information regarding whether your personal information will be transmitted to a third-party country or an international organisation. In this respect, you can request the appropriate guarantees in accordance with Art. 46 of the GDPR in connection with the transmission.

2. The right to rectification - Art. 16 GDPR

You have the right to request that the data controller correct and/or complete the data concerning you immediately if the personal data processed is incorrect or incomplete.

3. The right to deletion - Art. 17 GDPR

Deletion obligation:

You have the right to request the immediate deletion of your personal data at any time, provided that one of the following reasons is given:

  • the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  • you have revoked your consent to the processing of your personal data in accordance with Art. 6 para. 1a or Art. 9 para. 2a GDPR and there is no other legal basis for processing;
  • you have objected pursuant to Art. 21 para. 1, GDPR, and there are no overriding legitimate grounds for processing, or you submit an objection according to Art. 21 para. 2 GDPR against processing;
  • the personal data concerning you has been unlawfully processed;
  • the personal data concerning you must be deleted for compliance with a legal obligation under Union or Member State law to which the data controller is subject;
  • the personal data concerning you has been collected in relation to services offered by information society services pursuant to Art. 8 para. 1 GDPR.

Exceptions: The right to erasure does not exist insofar as processing is necessary

  • to exercise your rights to freedom of expression and information;
  • for the performance of a legal obligation required for processing under the law of the Union or of the Member States to which the data controller is subject or for the performance of a task in the public interest or in the exercise of official authority conferred to the data controller;
  • on grounds of public interest in the field of public health in accordance with Article 9 para. 2h and 2i and Article 9 para. 3;
  • for archiving purposes in the interest of public, scientific or historical research purposes or for statistical purposes in accordance with Art. 89 para. 1 GDPR, to the extent that the law referred to in a) is likely to render impossible or seriously prejudicial the attainment of the objectives of such processing; or
  • to assert, exercise or defend legal claims.

4. The right to restriction of processing - Art. 18 GDPR

You have the right to request the restriction of your personal data under the following conditions:

  • you contest the accuracy of your personal data for a period that enables the data controller to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
  • the data controller no longer needs the personal data for processing purposes, but it is required by you for the establishment, exercise or defence of legal claims or
  • you have objected to processing pursuant to Art. 21 para. 1 GDPR and it is not yet clear whether the legitimate reasons of the data controller outweigh your reasons.

Where processing of the personal data that concerns you has been restricted, such data – apart from being stored – may be processed only with your consent or for the purpose of asserting, exercising or defending rights or protecting the rights of another natural or legal person or on the grounds of an important public interest of the Union or of a Member State.

If the processing restriction has been made in accordance with the above conditions, you will be informed by the data controller before the restriction is lifted.

5. Right to information - Art. 19 GDPR

If you have exercised your right to have the data controller correct, delete or limit the processing, we are obliged to inform all recipients to whom the personal data that concerns you has been disclosed of this correction or deletion of the data or restriction on processing, unless this proves impossible or involves a disproportionate effort.

You also have the right to be informed of these recipients.

6. The right to data portability - Art. 20 GDPR

You have the right to obtain your personal data that you have provided to the data controller in a structured, commonly used and machine-readable format. In addition, you have the right to transmit this data to another data controller without hindrance from the data controller to which the personal data has been provided, insofar as

  1. the processing on a consent according to. Art. 6 para. 1a GDPR or Art. 9 para. 2a GDPR or on a contract pursuant to Art. 6 para. 1b GDPR and
  2. processing is carried out using automated methods.

In exercising this right to data transferability, you also have the right to obtain that your personal data relating to you are transmitted directly from one data controller to another, where technically feasible.

7. Right of objection - Art. 21 GDPR

Pursuant to the law, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, which may be processed on the basis of Art. 6 para. 1e or f GDPR; the same applies to profiling based on these provisions.

The data controller will no longer process the personal data that concerns you, unless they can prove compelling legitimate reasons for the processing, which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. If the personal data that concerns you is being processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data that concerns you for the purpose of such marketing; this also applies to profiling, insofar as it is associated with such direct marketing.

If you object to processing your data for direct marketing purposes, your personal data twill no longer be processed for these purposes.

In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.

You have the right at any time to revoke your data protection declaration of consent. The revocation of consent shall not affect the legality of any processing undertaken on the basis of this consent before its withdrawal.

9. Right of appeal to a supervisory authority - Art. 77 GDPR

Without prejudice to any other administrative or judicial remedy, you have the right of appeal to a supervisory authority, in particular in the Member State where you reside, work or where the infringement is suspected, if you believe that the processing of personal data that concerns you is in contravention of GDPR.

As the complainant, the supervisory authority to which you lodge your complaint must inform you of the status and the results of the complaint, including the possibility of a legal remedy under Art. 78 GDPR.

This data protection information is updated at regular intervals.

Valid from: 2019/01/16