Go Back Up

Data protection notice

I inform you below in accordance with the legal requirements of data protection law (in particular according to BDSG n.F. and the European General Data Protection Regulation 'DS-GVO') about the type, scope and purpose of the processing of personal data by my company. This privacy policy also applies to my websites and social media profiles. With regard to the definition of terms such as "personal data" or "processing", I refer to Art. 4 GDPR.name and contact details of the controller(s).

The controller within the meaning of Art. 4(7) GDPR is
Alexander Mrohs
Brückenstr. 26b
49170 Hagen
E-mail address: mail@alexander-mrohs.de

Types of data, purposes of processing and categories of data subjects

In the following, I will inform you about the type, scope and purpose of the collection, processing and use of personal data.
1. types of data that I process
Contact details (e-mail)

2. purposes of processing according to Art. 13 para. 1 c) GDPR
Customer service and customer care, handling contact requests

3. categories of data subjects according to Art. 13 para. 1 e) GDPR
Customers, interested parties

The data subjects are collectively referred to as "users".

Legal basis for the processing of personal data

Below I inform you about the legal basis for the processing of personal data:

If I have obtained your consent for the processing of personal data, Art. 6 para. 1 sentence 1 lit. a) GDPR is the legal basis.
If the processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract, the legal basis is Art. 6(1)(b) GDPR.
If the processing is necessary for compliance with a legal obligation to which I am subject (e.g. statutory retention obligations), the legal basis is Art. 6 para. 1 sentence 1 lit. c) GDPR.
If the processing is necessary in order to protect the vital interests of the data subject or another natural person, Art. 6 para. 1 sentence 1 lit. d) GDPR is the legal basis.
If the processing is necessary to protect my legitimate interests or the legitimate interests of a third party and your interests or fundamental rights and freedoms do not outweigh this, Art. 6 para. 1 sentence 1 lit. f) GDPR is the legal basis.

Disclosure of personal data to third parties and processors

I do not pass on any data to third parties without your consent. Should this nevertheless be the case, the data will be passed on on the basis of the aforementioned legal bases or on the basis of a court order or due to a legal obligation to disclose the data for the purpose of criminal prosecution, to avert danger or to enforce intellectual property rights.
I also use processors (external service providers, e.g. for web hosting of our websites and databases) to process your data. If data is passed on to the processors as part of an agreement on order processing, this is always done in accordance with Art. 28 GDPR. I select my processors carefully and check them regularly. In addition, the processors must have taken appropriate technical and organizational measures and comply with the data protection regulations according to BDSG n.F. and DS-GVO.

Unless expressly stated in this privacy policy, your personal data will be deleted or blocked as soon as the purpose for storing it no longer applies, unless its further storage is necessary for evidence purposes or is contrary to statutory retention obligations. This includes, for example, commercial law retention obligations for business letters in accordance with Section 257 (1) HGB (6 years) and tax law retention obligations for documents in accordance with Section 147 (1) AO (10 years). If the prescribed retention period expires, your data will be blocked or deleted, unless the storage is still required for the conclusion or fulfillment of a contract.

Provision of my website and creation of log files

If you only use my website for information purposes (i.e. no registration and no other transmission of information), I only collect the personal data that your browser transmits to my server. If you wish to view my website, I collect the following data
IP address
Internet service provider of the user
Date and time of access
browser type
Language and browser version
Content of the request
Time zone
Access status/HTTP status code
Amount of data
Websites from which the request originates
Operating system.

This data is not stored together with your other personal data. This data serves the purpose of user-friendly, functional and secure delivery of my website to you with functions and content as well as their optimization and statistical evaluation.
The legal basis for this is my legitimate interest in data processing in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR, which also lies in the above purposes.

Contact forms, newsletter

The HubSpot software is used for contact forms and the newsletter. Your data will be transmitted to HubSpot, Inc, 25 First Street, 2nd Floor, Cambridge, MA 02141 USA. HubSpot stores your data in the regional hosting center in Frankfurt am Main.

The legal basis for sending the newsletter and storing the email is your consent in accordance with Art. 6 para. 1 sentence 1 lit. a) GDPR in conjunction with Section 7 para. 2 no. 3 UWG and for logging the consent Art. 6 para. 1 sentence 1 lit. f) GDPR, as this serves my legitimate interest in legal provability.
You can revoke your consent to receive the newsletter at any time. You can revoke your consent by clicking on the unsubscribe link at the end of the newsletter, sending an email or sending a message to my contact details above.

Contact via contact form / e-mail / post

When you contact me by contact form, post or email, your data will be processed for the purpose of handling the contact request.
The legal basis for the processing of the data is Art. 6 para. 1 sentence 1 lit. a) GDPR if you have given your consent. The legal basis for the processing of data transmitted in the course of a contact request or e-mail, letter or fax is Art. 6 para. 1 sentence 1 lit. f) GDPR. The controller has a legitimate interest in the processing and storage of the data in order to be able to answer user inquiries, to preserve evidence for liability reasons and, if necessary, to comply with its statutory retention obligations for business letters. If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 sentence 1 lit. b) GDPR.
I may store your details and contact request in our customer relationship management system ("CRM system") or a comparable system.
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input screen of the contact form and those sent by email, this is the case when the respective conversation with you has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. I store inquiries from users who have an account or contract with me for a period of two years after termination of the contract. In the case of statutory archiving obligations, the deletion takes place after their expiry: end of commercial law (6 years) and tax law (10 years) retention obligation.
You have the option to revoke your consent to the processing of personal data at any time in accordance with Art. 6 para. 1 sentence 1 lit. a) GDPR. If you contact me by email, you can object to the storage of your personal data at any time.

YouTube videos

I have integrated YouTube videos from youtube.com on my website using the embedded function so that they can be accessed directly on my website. YouTube belongs to Google Ireland Limited, registration no.: 368047, Gordon House, Barrow Street, Dublin 4, Ireland. I have integrated the videos in the so-called "extended data protection mode" without using cookies to record user behaviour in order to personalize video playback. Instead, the video recommendations are based on the video currently being played. Videos that are played in extended data protection mode in an embedded player do not affect which videos are recommended to you on YouTube, and when you start a video (click on the video), YouTube receives the information that you have accessed the corresponding subpage of my website. The data obtained is transferred to the USA and stored there. This also takes place without a Google user account. If you are logged into your Google account, Google can assign the above data to your account. If you do not wish this to happen, you must log out of your Google account. Google creates user profiles from such data and uses this data for the purposes of advertising, market research or optimization of its websites. The legal basis for this is my legitimate interest in data processing in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR, which also lies in the above purposes.
You have the right to object to the creation of user profiles by Google. Therefore, please contact Google directly via the privacy policy below. You can opt out of advertising cookies here in your Google account: https://adssettings.google.com/authenticated.
You can find more information on the use of Google cookies and their advertising technologies, storage duration, anonymization, location data, how they work and your rights in YouTube's terms of use at https://www.youtube.com/t/terms and in Google's privacy policy for advertising at https://policies.google.com/technologies/ads. Google's general privacy policy: https://policies.google.com/privacy.

Presence in social media

I maintain profiles in social media to communicate with the users connected and registered there and to provide information about my products, offers and services. When you use and access my profile in the respective network, the respective data protection notices and terms of use of the respective network apply.
I process your data that you send me via these networks in order to communicate with you and to reply to your messages there.
The legal basis for the processing of personal data is my legitimate interest in communicating with users and my public image for the purpose of advertising in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR. Insofar as you have given the controller of the social network your consent to the processing of your personal data, the legal basis is Art. 6 para. 1 sentence 1 lit. a) and Art. 7 GDPR.

Rights of the data subject

Objection or revocation against the processing of your data

Insofar as the processing is based on your consent in accordance with Art. 6 para. 1 sentence 1 lit. a), Art. 7 GDPR, you have the right to withdraw your consent at any time. This does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.

Insofar as I base the processing of your personal data on the balancing of interests pursuant to Art. 6 para. 1 sentence 1 lit. f) GDPR, you can object to the processing. This is the case if, in particular, the processing is not necessary for the performance of a contract with you, which is described by me in the following description of the functions. When exercising such an objection, I ask you to explain the reasons why I should not process your personal data as I have done. In the event of your justified objection, I will examine the situation and either stop or adapt the data processing or show you my compelling reasons worthy of protection on the basis of which I will continue the processing.
You can object to the processing of your personal data for advertising and data analysis purposes at any time. You can exercise your right to object free of charge. You can inform me of your objection to advertising using the following contact details:
Alexander Mrohs
Natruper Str. 49a
49170 Hagen
E-mail address: mail@alexander-mrohs.de

Right to information

You have the right to request confirmation from me as to whether personal data concerning you is being processed. If this is the case, you have a right to information about your personal data stored by me in accordance with Art. 15 GDPR. This includes, in particular, information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the origin of your data if it was not collected directly from you.
Right to rectification

You have a right to rectification of inaccurate data or completion of correct data in accordance with Art. 16 GDPR.
Right to erasure

You have the right to erasure of your data stored by me in accordance with Art. 17 GDPR, unless legal or contractual retention periods or other legal obligations or rights to further storage conflict with this.

Right to restriction

You have the right to request a restriction on the processing of your personal data if one of the conditions in Art. 18 para. 1 lit. a) to d) GDPR is met:
If you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead
the controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims, or
if you have objected to the processing pursuant to Art. 21 para. 1 GDPR and it is not yet certain whether the legitimate reasons of the controller outweigh your reasons.

Right to data portability

You have a right to data portability in accordance with Art. 20 GDPR, which means that you can receive the personal data I have stored about you in a structured, commonly used and machine-readable format or request that it be transferred to another controller.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement.

Data security

I have taken appropriate technical and organizational security measures to protect all personal data that is transmitted to me and to ensure that I and our external service providers comply with data protection regulations. Therefore, among other things, all data between your browser and my server is transmitted in encrypted form via a secure SSL connection.

Status: 02.01.2022

Source: Privacy policy template from JuraForum.de