Data Protection Statement
in accordance with the EU General Data Protection Regulation (GDPR)
(Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC in the Official Journal of the European Union, OJEU L 119/1; effective date: 25 May 2018).
for the website www.tres-paises-rum.com
At Berentzen-Gruppe Aktiengesellschaft, we are very serious about protecting your personal data. We treat your personal data confidentially in conformity with statutory data protection regulations under German and European law (in particular the General Data Protection Regulation/GDPR and the German Telemedia Act/TMG) and with the following Statement.
This Data Protection Statement relates exclusively to our website www.tres-paises-rum.com. If you are forwarded to other websites via links on our website, please seek information from those other websites about how they handle and process your data.
The legal basis for data processing, including on websites, is essentially the following provisions and legal regulations:
- Your consent (Art. 6 para. 1 lit. a GDPR)
- Fulfilment of agreements or other legal relationships (Art. 6 para. 1 lit. b GDPR)
- Protection of legitimate interests / balancing of interests (Art. 6 para. 1 lit. f GDPR)
Based on the principles of data avoidance and data economy, we process personal data only as long as this is necessary within the meaning of the Statement below or prescribed by legislators (statutory storage period). If the purpose or right to process the collected personal data no longer exists or if the permitted storage period expires, we will lock or erase the data; that is, unless their further processing — with a time limit — is required, particularly for the following purposes:
- Fulfilment of retention periods under commercial and tax laws, in particular pursuant to the German Commercial Code (HGB) and the German Tax Code (AO). The periods prescribed therein for retention or documentation run from two to at most ten years.
- Preservation of evidence in the context of statutes of limitations. According to Secs. 195 et seq. of the German Civil Code (BGB), these limitation periods can run as long as 30 years, although the regular limitation period is three years.
- Warranty claims made by you
To allow for a data lock at any time, it is necessary to keep the data in a lock file for control purposes. If there is no statutory duty to archive, you can also demand the erasure of such data. If a statutory duty to archive exists, we will lock these data if you wish. If providing personal data is mandated by law or contract, or is necessary for conclusion of a contract, we refer to the adverse consequences for not providing them.
In particular, the following terms used in this agreement are defined according to Art. 4 GDPR as follows:
- Personal data: any information relating to an identified or identifiable natural person (hereinafter referred to as a “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Data subject: any identified or identifiable natural person whose personal data are processed by the controller responsible for the processing.
- Processing: any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
For further definitions, please refer to Art. 4 GDPR ( https://dejure.org/gesetze/DSGVO ).
1. name and contact data of the controller responsible for the processing and of the internal data protection officer
This Data Protection Statement is valid for data processing by the responsible operator of this website: Berentzen-Gruppe Aktiengesellschaft, Ritterstraße 7, 49740 Haselünne (hereinafter: BGAG), e-mail: firstname.lastname@example.org, phone: +49 (0)5961/502-0, fax: +49 (0)5061/502-268.
BGAG’s internal Data Protection Officer can be reached as follows:
Phone: +49(0) 5961/502-0
Fax: +49(0) 5961/502-268
E-mail address: email@example.com
2. collection and storage of personal data, nature and purpose of use
a. Call-up of the website (server log files)
When this website www.tres-paises-rum.com is called up, information is automatically sent by the browser used on your terminal device to the server of this website. This information is stored temporarily in a log file. The following information is recorded without you doing anything and is stored until it is automatically deleted:
- IP address of the querying computer (hostname)
- access date and time
- name and URL of the file called up
- website from which the access originates (referrer URL)
- browser used and operating system of your computer, if applicable
- name of your access provider.
It is not possible to deduce your identity from this automatically generated information. The aforementioned data are processed for the following purposes:
- Ensuring a smooth establishment of connection with the website
- Ensuring a comfortable use of our website
- Analysis of system security and stability
- Other administrative purposes.
The legal basis for this data processing is provided by Art. 6 para. 1 sentence 1 lit. f of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as: GDPR). Our legitimate interest follows from the data collection purposes listed above. In no case will we use the collected data for the purpose of drawing conclusions as to your identity.
b. Age verification
The website does require an age verification, but no specific personal data are processed by us for this purpose beyond the data mentioned above under subsection 2.a. Age verification takes place fundamentally in order to check whether you are permitted to have access to the content of our website based on your age (e.g. only 18+).
A cookie is placed (age_gate), which stores the existence of the age verification (see under section 4. below); this is so that the age verification does not have to be performed every time our website is called up (for comfort and convenience). Age_gate is a session cookie, which is active only for the duration of the session.
c. Newsletter subscription
If you have explicitly consented under Art. 6 para. 1 sentence 1 lit. a GDPR, we will use your e-mail address as well as your first and last name, if provided, to send you our newsletter on a regular basis. To receive the newsletter, it is enough to give us an e-mail address; entering your first and last name is optional.
When you subscribe to the newsletter, we store the IP address for the PC system you use to subscribe, which is provided by the Internet service provider (ISP), as well as the date and time of subscription. Collection of these data is required in order to trace any possible misuse of your e-mail address.
The personal data collected for subscribing to the newsletter will be used exclusively for the sending of our newsletter. In addition, you can obtain information by e-mail if this is required for the operation of the newsletter service or a registration in relation to this, e.g. in case of a change to the newsletter service. The personal data collected by the newsletter service will not be shared with third parties. A link is provided in the newsletter for the purpose of withdrawing consent.
Unsubscribing is possible at any time, e.g. via the link at the end of the newsletter. Alternatively, you can also send your unsubscription request that you formulated then to firstname.lastname@example.org at any time by e-mail. The consent to the storage of personal data that you gave us for the sending of the newsletter can be withdrawn at any time, likewise under email@example.com.
d. Use of contact form/initiation of contact
We also provide you the option to contact us using a form on this website or directly via firstname.lastname@example.org. You must provide a valid e-mail address for us to know from whom the inquiry is coming and to respond to it. Additional information can be provided voluntarily, especially via the message box.
You can also contact us by post or by telephone (see Contact and Regulatory Information). In that case, we will process accordingly the data that you send us in your contact initiation; besides purely technical data (see 2.a. above), these can also include real names (first/last name), user-names, addresses (street address, city, postal code), phone numbers or e-mail addresses.
We process your data received in the contact initiation to provide a proper reply.
The data processing for the purpose of initiating contact with us is done on the basis of your freely given consent according to Art. 6 para. 1 sentence 1 lit. a GDPR.
3. sharing of data
Any transfer of your data to third parties will take place only for the purposes listed below.
We share your personal data with third parties only
- if you have given your explicit consent to this under Art. 6 para. 1 sentence 1 lit. a GDPR
- if the sharing is required under Art. 6 para. 1 sentence 1 lit. f GDPR for the assertion, exercise or defense of legal rights and there is no reason to assume that you have an overriding interest worthy of protection in your data not being shared
- if a legal obligation to share the data exists under Art. 6 para. 1 sentence 1 lit. c GDPR
- if this is legally permitted and is required under Art. 6 para. 1 sentence 1 lit. b GDPR for the performance of a contractual relationship with you.
- on the basis of a processing agreement entered into by us with a processor according to Art. 28 GDPR
If we should form the intention to use the personal data for a purpose other than those mentioned above, prior to this further processing we will make available to you information about this other purpose and all other relevant information according to Art. 13 para. 2 GDPR.
We use the following cookies:
- age_gate (session cookie for age verification, see 2.b above)
- cookie_notice_accepted (cookie notice)
In a cookie, information is deposited that arises in connection with the specific terminal device used. But that does not mean that we obtain direct knowledge of your identity from this.
You can prevent the use and placement of cookies by blocking the placement of cookies in the browser (you will find information about this in the Help function of the browser). Opt-out cookies prevent the future recording of data when visiting this website. However, we would like to point out that in this case perhaps not all functions of this website can be used in full.
The deployment of cookies helps in particular to make the use of our website offering convenient for you. We use the following cookies specifically:
a. Session cookies, to detect that you have already visited individual pages of our website. They are only stored in the random access memory of the user’s computer. In a session cookie, a randomly generated, unique identification number is deposited, a so-called session ID. In addition, a cookie contains the information about its source and a storage time-limit. These cookies cannot store any other data. Session cookies are deleted when the session of use of the website is ended.
b. Temporary cookies, which are stored on your terminal device for a certain defined period of time. When you visit our site again to use our services, it is automatically recognised that you were on our site before, and what inputs and settings you made, so that you do not have to enter them again.
c. Cookies for statistical recording and for the purpose of optimising our website offering (see section 5). These cookies also make it possible, when your visit our website again, to recognise automatically that you had already visited our website. These cookies are automatically erased after a period of time defined for each.
The data processed by cookies are required for the aforementioned purposes to protect our legitimate interests and that of third parties under Art. 6 para. 1 sentence 1 lit. f GDPR.
Most browsers accept cookies automatically. But you can set up your browser so that no cookies are stored on your computer or so a notice appears every time before a new cookie is placed. However, complete deactivation of cookies can lead to your not being able to use all the functions of our website. Session cookies (see 4.a. above) normally cannot be suppressed.
5. tracking tools
The tracking measures listed below and used by us are carried out on the basis of Art. 6 para. 1 p. 1 lit. f DSGVO.
With the tracking measures used, we want to ensure a needs-based design and continuous optimization of our website. On the other hand, we use the tracking measures to statistically record the use of our website and evaluate it for the purpose of optimizing our website offering for you.
These interests are to be regarded as legitimate within the meaning of the aforementioned provision. The respective data processing purposes and data categories can be found in the corresponding tracking tools.
Description and purpose
This website uses Matomo (formerly Piwik), an open source software for statistical analysis of visitor access. The provider of Matomo is InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand.
We use Matomo to improve the quality of our website and its content. By learning how our website is used, we can continuously optimize our website offering.
The following data is stored when individual pages of our website are called up:
- two bytes of the IP address of the user’s calling system
- the web page called up
- the website from which the user accessed the website (referrer url)
- subpages that are called from the called web page
- dwell time on the web page
- frequency of calling the web page.
The software runs exclusively on the servers of our website or our website support, a storage of the personal data of the users takes place exclusively there. The user’s IP address is not stored in full, but is shortened by masking only 2 bytes of the IP address. An assignment of the IP address shortened in this way to the end device of the user is then not possible.
The processing of the user’s personal data enables the analysis of usage behavior on our website.
The legal basis of this processing of your personal data is Art. 6 para. 1 lit. f) DSGVO.
Data recipient, data transfer and data transmission to third countries
The recipient of your anonymized data is the website operator and website support. A data transfer to a third country does not take place. There is also no other transfer of data to third parties.
Duration and scope of data storage
The data will be deleted as soon as the data is no longer required to achieve the purpose for which it was collected and processed. Likewise, the data will be deleted if you assert your right to data deletion pursuant to Art. 17 (1) DSGVO.
There is no contractual or legal obligation for the provision of the data.
Further information on the processing of your personal data by Matomo can be found here: https://matomo.org/privacy-policy/
6. social media plug-ins
Plug-ins, by which you might be directly linked to our website, or conversely this website might be directly linked to a social media account of yours, and by which a certain usage behaviour of yours might become detectable, are not used on this website.
7. rights of data subjects
You have the right, free of charge,
- under Art. 15 GDPR, to demand information about your personal data that we process. In particular, you can demand information about the purposes of processing, the category of personal data, the categories of recipients to whom your personal data were or are disclosed, the planned duration of storage, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to complain, the source of your data if not collected by us, and about the existence of automated decision-making including profiling and meaningful information about its details, if any;
- under Art. 16 GDPR, to demand the rectification of inaccurate data or the completion of your personal data stored with us without undue delay;
- under Art. 17 GDPR, to demand the erasure of your personal data stored with us, unless the processing is necessary to exercise the right to a free expression of opinion and to information, to fulfil a legal obligation, for reasons of the public interest, or to assert, exercise or defend against legal claims; the same applies in the event of a restriction of processing;
- under Art. 18 GDPR, to demand restriction of the processing of your personal data, if the correctness of the data is disputed by you, processing is unlawful but you refuse to have them erased, and we no longer need the data, but you need them to assert, exercise or defend against legal claims, or you have lodged a protest against processing under Art. 21 GDPR;
- under Art. 20 GDPR, to demand to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format, or to have those data transmitted to another controller;
- under Art. 7 para. 3 GDPR, to withdraw your previously given consent from us at any time. This will have the consequence that we will no longer be permitted in future to continue the data processing that was based on this consent;
- not to be subjected to a decision based solely on automated processing — including profiling — that has legal effect in relation to you or significantly harms you in a similar manner, insofar as the decision (1) is not required for the conclusion or performance of a contract between the data subject and the controller, or (2) is not permissible based on legal regulations of the European Union or of the Member States to which the controller is subject and these legal regulations contain appropriate measures to protect the rights and freedoms and the legitimate interests of the data subject or (3) is not made with the express consent of the data subject. If the decision (1) is required for the conclusion or performance of a contract between the data subject and the controller or (2) if it occurs with the express consent of the data subject, the Berentzen-Gruppe Aktiengesellschaft will take reasonable measures to protect the rights and freedoms and legitimate interests of the data subject, which shall include at a minimum the right to force a person to act on behalf of the controller, the right to explain one’s own standpoint, and the right to challenge the decision. If the data subject would like to assert rights with respect to automated decisions, he/she can at any time contact an employee of the controller responsible for the processing and
- object to a supervisory authority in accordance with Art. 77 GDPR. For this purpose, you can usually turn to the supervisory authority of your customary place of residence or employment or of the registered office of our firm.
To assert the rights of a data subject, please send an e-mail to email@example.com.
8. right of objection/withdrawal
Insofar as your personal data are processed on the basis of legitimate interests under Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right under Art. 21 GDPR to lodge an objection to the processing of your personal data or to withdraw any consent to the processing, to the extent that there are reasons for it resulting from your particular situation or that the objection/withdrawal is directed against direct advertising. In the latter case, you have a general right of objection/withdrawal that will be put into effect by us without your indicating any particular situation.
If you would like to make use of your right of objection/withdrawal, an e-mail sent to firstname.lastname@example.org will suffice.
9. data protection
Within the website visit, we use the prevalent SSL method (Secure Sockets Layer) in combination with the highest encryption level that your browser supports. Generally, this is 256-bit encryption. You can tell whether a specific page on our website is transmitted in encrypted form by the locked image of the key or lock symbol in the lower status bar of your browser.
In addition, we use suitable technical and organisational security measures to protect your data against random or deliberate manipulation, partial or total loss, destruction or unauthorised access by third parties. Our security measures are continually enhanced in step with technological developments.
10. up-to-dateness and amendment of this data protection statement
This Data Protection Statement is currently valid and is updated as of 25 May 2018 (effective date of the GDPR).
On account of the further development of our website and offerings made via the website, or due to changes to legal or regulatory requirements, it may become necessary to amend this Data Protection Statement.