PRIVACY NOTICE
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed under this text.
Data collection on this website
Who is responsible for the data collection on this website?
The data processing on this website is carried out by the website operator. His contact details can be found in the section "Note on the responsible body" in this privacy policy.
How do we gather your data?
On the one hand, your data is collected by the fact that you provide it to us. Here it can be e.g. data that you enter in a contact form.
Other data is collected automatically or after your consent when visiting the website by our IT systems. These are mainly technical data (e.g. B. Internet browser, operating system or time of page view). This data is collected automatically as soon as you enter this website.
For what purposes do we use your data?
Part of the data is collected to ensure an error-free provision of the website. Other data can be used to analyze your user behavior.
What rights do you have with regard to your data?
You have the right at any time to receive information free of charge about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. In addition, you have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have a right of appeal to the competent supervisory authority. For this and for further questions about data protection, you can contact us at any time.
2. Hosting
We host the contents of our website with the following provider:
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hoster. These can include IP addresses, contact requests, meta and communication data, contract data, contact data, names, website access and other data generated via a website.
The external hosting is carried out for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f DSGVO). If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent requires the storage of cookies or access to information in the user's terminal device (e.g. B. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time. Our hoster will or will only process your data to the extent that this is necessary to fulfill its Performance obligations are required and follow our instructions with regard to this data.
We use the following hoster(s):
Hostinger, UAB
Švitrigailos Str. 34, 03230
Vilnius, Lithuania
Order processing
We have concluded a contract for order processing (AVV) to use the above-mentioned service. This is a contract prescribed by data protection law, which ensures that it processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
3. General information and mandatory information
data privacy
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration. When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. She also explains how and for what purpose this is done. We would like to point out that the data transmission on the Internet (e.g. B. when communicating by e-mail) may have security gaps. A complete protection of the data against access by third parties is not possible.
Note on the responsible authority
The authority responsible for data processing on this website is:
Prasad Vettukattil
Rathausstraße 13,
66125, Saarbrücken
GERMANY
E-Mail: hello@blaulotus.de
Tel.: +49 6897 9141972
The responsible body is the natural or legal person who alone or jointly with others is responsible for the purposes and means of processing personal data (e.g. B. Names, e-mail addresses o. Ä.) decides.
Storage period
Insofar as no more specific storage period has been mentioned within this data protection declaration, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate deletion request or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. B. tax or commercial retention periods); in the latter case, the deletion takes place after these reasons have not occurred.
General information on the legal basis of data processing on this website
If you have consented to the data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, if special data categories are processed in accordance with Art. 9 para. 1 GDPR. In the case of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you are interested in the storage of cookies or access to information in your terminal device (e.g. B. via device fingerprinting), the data processing is additionally carried out on the basis of § 25 para. 1 TTDSG. The consent is revocable at any time. If your data is necessary for the fulfillment of the contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b DSGVO. Furthermore, we process your data if they are necessary for the fulfillment of a legal obligation on the basis of Art. 6 para. 1 lit. c DSGVO. Data processing can also be carried out on the basis of our legitimate interest in accordance with Art. 6 para. 1 lit. f DSGVO. The following paragraphs of this data protection declaration provide information on the legal bases relevant to each individual case.
Recipients of personal data
As part of our business activities, we work together with various external bodies. In some cases, a transfer of personal data to these external bodies is also necessary. We only pass on personal data to external bodies if this is necessary in the context of the performance of a contract, if we are legally obliged to do so (e.g. B. Transfer of data to tax authorities) if we have a legitimate interest in the transfer in accordance with Art. 6 para. 1 lit. f GDPR or if another legal basis allows the transfer of data. When using processors, we only pass on personal data of our customers on the basis of a valid contract for order processing. In the case of joint processing, a contract for joint processing is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke an already given consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases as well as to direct advertising (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS DATA PROTECTION DECLARATION. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED, UNLESS WE CAN PROVE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING IS INTENDED TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS (OPPOSITION PURSUANT TO ART. 21 PARA. 1 GDPR). IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT ADVERTISING (OPPOSITION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right of complaint with the responsible regulatory authority
In the event of violations of the GDPR, the persons concerned have the right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right of appeal exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to yourself or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another person responsible, this will only be done to the extent that it is technically feasible.
Information, correction and deletion
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipient and the purpose of the data processing and, if necessary, a right to correction or deletion of this data. You can contact us at any time for this as well as for further questions on the subject of personal data.
Right to the limitation of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the exam, you have the right to request restriction of the processing of your personal data.
If the processing of your personal data happened/unlawfully, you can request the restriction of data processing instead of deletion.
If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
If you have filed an objection in accordance with Art. 21 para. 1 GDPR, a balance must be made between your and our interests. As long as it is not yet clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a Member State.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator, this site uses an SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If the SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data collection on this website
Our site offers you various functions, during the use of which personal data is collected, processed and stored by us. Below we explain what happens to this data:
Contact form(s)
What personal data is collected and to what extent is it processed?
We will process the data you entered in our contact forms, which you have entered into the input mask of the contact form, to fulfill the purpose mentioned below.
Legal basis for the processing of personal data
Art. 6 para. 1 lit. a GDPR (consent by clear confirmating act or behavior)
Purpose of data processing
We will only use the data recorded via our contact form or via our contact forms to process the specific contact request received through the contact form.
Duration of storage
After processing your request, the collected data will be deleted immediately, unless there are legal retention periods.
Possibility of revocation and deletion
The revocation and deletion options are based on the general regulations on the right of withdrawal and the right of deletion described below in this data protection declaration.
Necessity of providing personal data
The use of the contact forms is on a voluntary basis and is neither contractually nor legally required. You are not obliged to contact us via the contact form, but can also use the other contact options specified on our page. If you would like to use our contact form, you must fill in the fields marked as mandatory. If you do not fill in the necessary information of the contact form with content, you can either not send the request, or unfortunately we cannot process your request.
Cookies
Our Internet pages use so-called "cookies". Cookies are small data packets and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or automatically deleted by your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of Third-party companies within websites (e.g. B. Cookies for the processing of payment services). Cookies have different functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. B. the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies that are used to carry out the electronic communication process, to provide certain functions desired by you (e.g. e.g. for the shopping cart function) or for the optimization of the website (e.g. B. Cookies are required to measure the web audience) (necessary cookies), are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified.
The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG); the consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
You can find out which cookies and services are used on this website in this privacy policy.
Plugins and tools
The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG); the consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
You can find out which cookies and services are used on this website in this privacy policy.
emailsys (by Hostinger email)
On our site, we use the service emailsys (by Hostinger email) of the company Hostinger, UAB, Švitrigailos str. 34, 03230 Vilnius, Lithuania, Website: https://www.hostinger.de . The transmission and processing of personal data takes place exclusively on servers in the European Union.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
Use of social media buttons with “Hostinger”
Our website uses default buttons for social networks provided by “Hostinger web builder” of the company Hostinger, UAB, Švitrigailos str. 34, 03230 Vilnius, Lithuania, Website: https://www.hostinger.de , thereby keeping your online behavior private. "Hostinger" incorporates these social network share buttons into our website as simple icons containing links to the relevant social networks. Clicking an icon takes you to the service of the network in question. A Hostinger integrated social button does not establish direct contact between a social network and our visitors until those visitors actively click these button. Only then will their data be transmitted to the respective social network. However, if a user does not click the Hostinger Social button, no data will be exchanged between that user and the social network. Our website links to the following social networks with "Hostinger":
Instagram
LinkedIn
Xing
By activating the respective social media buttons you agree to the processing of your data by the respective network in accordance with Art. 6 Para. 1 lit. a) GDPR. By deactivating the buttons you stop the transfer of your data.
Integration of external web services and processing of data outside the EU
On our website we use active content from external providers, so-called web services. By visiting our website, these external providers may receive personal information about your visit to our website. It may be possible to process data outside the EU. You can prevent this by installing a corresponding browser plugin or disabling the execution of scripts in your browser. This may lead to functional restrictions on websites that you visit.
We use the following external web services:
On our site, we use the Google service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision of the Commission. Therefore, the usual level of protection for the GDPR during transmission cannot be guaranteed, as it cannot be ruled out that in the third country, for example, authorities can access the collected data.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
We use Google to be able to download other Google services on the website.
In the context of order processing, personal data may also be transmitted to the servers of the company Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States.
You can revoke your consent at any time. Further information on the revocation of your consent can be found either in the consent itself or at the end of this data protection declaration.
Further information on the handling of the transferred data can be found in the data protection declaration of the provider at https://policies.google.com/privacy.
Google APIs
On our site, we use the Google APIs service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, E-Mail: support-deutschland@google.com, Website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision of the Commission. Therefore, the usual level of protection for the GDPR during transmission cannot be guaranteed, as it cannot be ruled out that in the third country, for example, authorities can access the collected data.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
We use Google APIs to be able to reload other Google services on the website. Google Apis is a collection of interfaces for communication between the various Google services used on your website.
For processing itself, the service or we collects the following data: IP address
In the context of order processing, personal data may also be transmitted to the servers of the company Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States.
You can revoke your consent at any time. Further information on the revocation of your consent can be found either in the consent itself or at the end of this data protection declaration.
Further information on the handling of the transferred data can be found in the data protection declaration of the provider at https://policies.google.com/privacy.
Google Fonts
On our site, we use the Google Fonts service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision of the Commission. Therefore, the usual level of protection for the GDPR during transmission cannot be guaranteed, as it cannot be ruled out that in the third country, for example, authorities can access the collected data.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
The Google Fonts service reloads fonts on our site in order to be able to show you the page in a visually better version.
In the context of order processing, personal data may also be transmitted to the servers of the company Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States.
You can revoke your consent at any time. Further information on the revocation of your consent can be found either in the consent itself or at the end of this data protection declaration.
Further information on the handling of the transferred data can be found in the data protection declaration of the provider at https://policies.google.com/privacy.
Google reCaptcha
On our site, we use the Google reCaptcha service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision of the Commission. Therefore, the usual level of protection for the GDPR during transmission cannot be guaranteed, as it cannot be ruled out that in the third country, for example, authorities can access the collected data.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
On the basis of specific characteristics and an analysis of the page behavior, the service recognizes whether the input made is an automated input by means of a program (so-called bot) or a human. The service has three different levels. Either the service automatically detects that the input is not automatically by a bot or it lets the user select a captcha checkbox. A third possibility is the display of small image or language tasks / text tasks that must be solved by the page visitor. Google reCaptcha is a captcha service used on our website for security reasons to prevent bots (robot programs) from interacting on our website. Google reCaptcha verifies on our behalf that only people and not bots can use our website. In particular, we can protect the special functions of our website (e.g. contact forms or other input options such as the login area) from abusive page access.
For processing itself, the service or we collect the following data: user behavior (e.g. mouse gestures or input behavior), IP address, browser data, computer information.
If you want to use the input options of our website protected by Google reCaptcha, you must allow the use of Google reCaptcha and, if necessary, solve corresponding captchas. If you do not fill out the captcha or do not allow the use of Google reCaptcha, you cannot use the form protected by the captcha. Alternatively, you can use our other contact options (e.g. post or e-mail) at any time.
You can revoke your consent at any time. Further information on the revocation of your consent can be found either in the consent itself or at the end of this data protection declaration.
Further information on the handling of the transferred data can be found in the data protection declaration of the provider at https://policies.google.com/privacy.
Gstatic
We use the Gstatic service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision of the Commission. Therefore, the usual level of protection for the GDPR during transmission cannot be guaranteed, as it cannot be ruled out that in the third country, for example, authorities can access the collected data.
The legal basis for the transmission of personal data is your consent in accordance with. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website.
Gstatic is a service used by Google to retrieve static content to reduce bandwidth usage and to preload required catalog files.
In the context of order processing, personal data may also be transmitted to the servers of the company Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States.
You can revoke your consent at any time. Further information on the revocation of your consent can be found either in the consent itself or at the end of this data protection declaration.
Further information on the handling of the transferred data can be found in the data protection declaration of the provider at https://policies.google.com/privacy.
Google Maps
What personal data is collected and to what extent is it processed?
On our site we use the map service of the company Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: Google Maps). Google Maps is integrated on the website via the Google API to visualize location information and display it in the form of a map. In order to display the map, the processing of the IP address by Google Maps is technically necessary. With regard to the other web services integrated via Google Apis, the regulations in the respective section of this privacy policy on Google Apis apply.
Legal basis for the processing of personal data
Art. 6 lit. f DSGVO (legitimate interest). Our legitimate interest is to be able to visualize the usual presentation of location information on the Internet.
Purpose of data processing
On our behalf, Google will use the information obtained using Google Maps to show you the map. Using Google Maps, you can find us faster and more accurately than with a mere non-interativel approach map.
Duration of storage
Google will store the data relevant to the function of Google Maps for as long as it is necessary to fulfill the booked web service. The data collection and storage is anonymous. If there is a personal reference, the data will be deleted immediately, as long as they are not subject to legal storage obligations. In any case, the deletion takes place after the expiry of the storage obligation.
Possibility of objection and deletion
You can prevent the collection and forwarding of personal data to Google (in partly your IP address) as well as the processing of this data by Google by deactivating the execution of script code in your browser, installing a script blocker in your browser or activating the "Do Not Track" setting of your browser. Google's security and data protection principles can be found at https://policies.google.com/privacy.
Joint processing
We have concluded a contract for joint processing with Google with regard to Google Maps. The content can be found at https://privacy.google.com/intl/de/businesses/mapscontrollerterms/.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://privacy.google.com/businesses/gdprcontrollerterms/and
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
More information on the handling of user data can be found in Google's privacy policy:
https://policies.google.com/privacy? hl=de.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that ensures compliance with
European data protection standards for data processing in the USA. Every company certified according to the DPF undertakes to comply with these data protection standards.
Further information can be obtained from the provider at the following link:
Source: