Shape

Data privacy policy

1. The data controller within the definition of data protection provisions is:

Facelift brand building technologies GmbH, Gerhofstr. 19, 20354 Hamburg.

If you have any questions concerning the processing of your personal data, you can contact our Data Protection Officer at any time, at dataprivacy@facelift-bbt.com.

2. Collection and storage of personal data, type and purpose of use

a) Visiting the website

When you visit our website, the browser running on your terminal device will automatically send information to our website server. This information will be temporarily stored in a log file, where it will remain saved until it is automatically erased. The information includes the IP address of the requesting computer with the date and time of the access, and the name and URL of the retrieved file, as well as the URL of the website from which the access takes place. In addition, the browser used, your computer’s operating system, as well as the name of the respective access provider, are identified.

The purpose of processing the aforementioned data is to guarantee seamless connection to the website for the optimum use of our online service, as well as analysis of the system security and stability. The data is also used for administrative purposes.

The data processing has its legal basis in Art. 6 (1) sentence 1 f) GDPR. Our legitimate interest is based on the purposes for the data collection as listed above. Under no circumstances will we use the collected data for the purpose of drawing any inferences about you personally. Furthermore, we use website cookies and analysis services in connection with your visit to our website. Details of this can be found in Nos. 4 and 5 of this Data Protection Notice.

b) Using our contact form

We offer you the opportunity to contact us using the form available on our website. At this point it is necessary to provide a valid email address, so that we know who sent the request and so that we can respond accordingly. Further information may be provided voluntarily. Processing data for the purpose of making contact with us takes place in accordance with Art. 6 (1) sentence 1 a) GDPR, on the basis of the consent you give voluntarily.

3. Transfer of data

Your personal data will not be transferred to third parties for any purpose other than those specified below.

We transfer your personal data to third parties only

  • if you have issued your explicit consent in accordance with Art. 6 (1) sentence 1 a) GDPR,

  • if the data transfer according to Art. 6 (1) sentence 1 f) GDPR is necessary for the assertion, exercise or defence of legal claims, and there is no reason to assume that you have an overriding protected interest in your data not being passed on in this manner,

  • if there is a statutory obligation for the data transfer in accordance with Art. 6 (1) sentence 1 c) GDPR,

  • if this is legally permissible and is necessary in accordance with Art. 6 (1) sentence 1 b) GDPR for the performance of contractual arrangements with you.

4. Cookies

We use cookies on our pages in order to optimise the user-friendliness of our site. These are small files automatically created by the browser, which are stored in the respective terminal device when visiting a website. The cookie contains information relating to the specific terminal device used. We use “session cookies” in order to recognise that you have already visited certain pages on our website.

These are automatically erased when leaving our site. We also use temporary cookies which are stored on your terminal device for a certain fixed period of time. When you next visit our website to use our services, the system will automatically detect that you have already visited us, as well as which entries you made and settings you selected, to save you having to re-enter these again. When you next visit our website to use our services, the system will automatically detect that you have already visited us, which entries you made and the settings you selected. This is to save you having to re-enter this information again and may be used for marketing purposes.

We also use cookies for recording and analysing statistics on the use of our website. This data is used to help optimise our site. These cookies enable us to recognise that you have already visited us once when you return to our site. These cookies will be automatically erased after a defined period of time. The data processed through cookies is necessary for the purposes of pursuing our legitimate interests and those of third parties in accordance with Art. 6 (1) sentence 1 f) GDPR. The majority of browsers accept cookies automatically.

However, you can configure your browser so that no cookies are saved to your computer, or that a message is always displayed before a new cookie is accepted. Please note that the complete deactivation of cookies may mean that you will be unable to use all of the functions available on our website.

5. Analytical tools

Tracking tools

The tracking measures described below and used by us are carried out on the basis of Art. 6 (1) sentence 1 f) GDPR as legitimate interests. On the one hand, these tracking measures are used for the purpose of continual optimisation of our online pages. On the other hand, these tracking measures are used for recording and analysing statistics on the use of our website. This data is used to help optimise our online site. The respective data processing purposes and data categories can be found in the corresponding tracking tools.

Google Analytics

We use Google Analytics, a web analysis service provided by Google Inc. (https://www.google.de/intl/eng/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94 https://www.google.de/intl/de/about/043, USA; “Google”), for the purpose of designing our web pages in a manner appropriate to users’ needs and to continually optimise our site. Pseudonymised usage profiles are created and cookies are used in this context (see No. 4).

The information generated by the cookie regarding your use of this website, such as browser type/version, the operating system used, the referrer URL (the previously visited page), host name of the accessing computer (IP address), and time of the server query, are transferred to a Google service located in the USA and stored there. This information is used to evaluate the use of the website, to compile reports on website activities, and for the delivery of other services connected with website and internet usage for the purposes of market research and website design that meets needs of our users. This information may also possibly be transferred to third parties, if this is required by law or in cases where third parties are commissioned to process this data.

Under no circumstances will your IP address be linked with other data owned by Google. IP address are anonymised, so that they cannot be connected to any individual (IP masking). You can prevent the installation of cookies by adjusting your browser software accordingly.

However, please note that this may mean that you will not be able to use the full functionality of this website. Furthermore, by downloading and installing the browser add-on, you can prevent the information generated by the cookie about your use of the website (including your IP address) from being transmitted to and processed by Google (https://tools.google.com/dlpage/gaoptout?hl=en).

As an alternative to the browser add-on – particularly for browsers on mobile devices – you can also prevent Google Analytics from collecting data by clicking on this link. An opt-out cookie is activated, which prevents your data from being collected whenever you visit this website in the future. The opt-out cookie only applies in this browser and only for our website, and is stored on your device. If you delete the cookies in this browser, you will have to reactivate the opt-out cookies again. Further information on data protection in connection with Google Analytics can be found in Google Analytics Help, for example (https://support.google.com/analytics/answer/6004245?hl=en).

Google Adwords (Remarketing / Conversion Tracking)

We use Google Adwords for our website. Google AdWords is an online marketing programme delivered by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). We use its remarketing function.

With the aid of cookies, this enables us to present users with adverts tailored to their interests. For this purpose, an analysis is carried out into the way in which users interact with our website, e.g. which offers were of interest to the user, to be able to display targeted advertising to them after having visited our website. The cookies used enable the clear identification of a web browser on a particular computer, and not the identification of an individual person; personal data is not stored. You can disable the application of cookies by Google. To do so, click on the following link to download and install the plug-in provided there: https://www.google.com/settings/ads/plugin.

Detailed information on Google Remarketing and Google’s Privacy Policy is available at: http://www.google.com/privacy/ads/.

In addition, we also use the conversion tracking function provided by the Google AdWords service. When you click on an advert placed by Google, a conversion tracking cookie will be placed on your terminal device. These cookies become invalid after 90 days, contain no personal data, and therefore cannot be used to personally identify any individual. The information collected by the conversion cookie is used to compile cookie statistics for AdWords customers using the conversion tracking function.

You can block the installation of cookies by adjusting your browser software accordingly; however we point out that by doing so you may be prevented from using the full range of this website’s functions. You can deactivate personalised ads on Google and personalised Google ads across the web (within the Google display network) in your browser by clicking “Off” at http://www.google.de/settings/ads or opting out at http://www.aboutads.info/choices/. For further information on ad settings available to you and Google’s privacy policy, visit https://www.google.de/intl/en/policies/privacy/?fg=1.

Microsoft Advertising (Remarketing)

On our website we use Microsoft Advertising which is an online advertising program from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

By using a Universal Event Tracking (UET) tag on our Website, we are able to track individual end-users and share information with third parties for advertising and marketing purposes. The interaction of the users on our website is analyzed, e.g. which offers the user was interested in, in order to be able to display targeted advertising to the users on other pages even after they have visited our website. The cookies used here serve to identify a web browser on a particular computer and not to identify a person; personal data is not stored.

Of course, you have the right to deactivate Microsoft Advertising, please go to one of the following pages:  Network Advertising Initiative (NAI) consumer deactivation page or Digital Advertising Alliance (DAA) deactivation page

For more information about remarketing and Microsoft Corporation's privacy policy, please visit: https://privacy.microsoft.com/de-de/privacystatement

Analysis by wiredminds

Our website uses a counting pixel technology provided by wiredminds GmbH (www.wiredminds.de) to analyze visitor behavior. If necessary, data is collected, processed and stored, from which user profiles are created under a pseudonym. Wherever possible and reasonable, these usage profiles are completely anonymized. Cookies can be used for this purpose. Cookies are small text files that are stored in the visitor's Internet browser and serve to recognize the Internet browser.

The collected data, which may also contain personal data, will be transmitted to wiredminds or collected directly by wiredminds. wiredminds may use information that is left by visiting the websites to create anonymized usage profiles. The data obtained without explicit consent of the affected person will not be used to personally identify the visitor of this website and will not be merged with personal data of the bearer of the pseudonym. Whenever IP addresses are recorded, their immediate anonymization takes place by deleting the last number block.

Exclude from tracking.

HubSpot

We use the HubSpot tool provided by HubSpot, Inc. in order to capture and analyse the movement profiles of website visitors. When you provide us with personal data by way of the contact form on our website, we use HubSpot to send the customer specially individualised marketing information. HubSpot uses cookies, which are stored on the computer of the particular website visitor, and which enable an analysis to be carried out of their use of the website. You can block the storage of these cookies at any time by using the relevant settings in your internet browser. However, blocking these cookies may limit the availability of certain functions and reduce the user-friendliness of our website.

The tool has a third-country reference, which means that the collected data may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called "standard contractual clauses" with the provider for data protection compliance within the requirements of the GDPR. Nevertheless, it cannot be ruled out that data may be processed by U.S. authorities for control and monitoring purposes when transferred to the U.S., without you possibly having any legal remedies.

Vidyard

In the context of using the Hubspot tool, we use Vidyard to include videos on our pages. The operator of this video player is Buildscale, Inc. in Kitchener, Canada. Canada is considered a safe third country according to the GDPR.

When you visit one of our pages where Vidyard is integrated, a connection to the servers of Vidyard takes place. The Vidyard server is thereby informed which of our pages you have visited.

Legal basis for the use of Vidyard is Art. 6 (1) sentence 1 f) GDPR. An appealing presentation of our online presence represents our legitimate interest.

Further information on the handling of user data can be found in Vidyard's privacy policy at: https://www.vidyard.com/privacy/

Intercom

We use Intercom in order to communicate with visitors to our website. We use this tool to offer our customers our 1st Level Support in the form of a chat function and email. This tool enables us to track usage behaviour, which allows us to optimise the way in which we send information to the customer.

The tool has a third-country reference, which means that the collected data may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called "standard contractual clauses" with the provider for data protection compliance within the requirements of the GDPR. Nevertheless, it cannot be ruled out that data may be processed by U.S. authorities for control and monitoring purposes when transferred to the U.S., without you possibly having any legal remedies.

Intercom uses cookies, which are stored on the computer of the particular website visitor, and which enable analysis to be made of their use of the website. You can block the storage of these cookies at any time by using the relevant settings in your internet browser. However, blocking these cookies may limit the availability of certain functions and reduce the user-friendliness of our website.

Microsoft Teams

For video conferences, we use the Microsoft Teams tool from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399. When registering for a video conference, only the data relevant to participation such as e-mail address, name and company are queried and logged. While participating in video conferences, pictures of the participants are transmitted to the other participants and displayed. Any content of video conferences will not be saved.

Microsoft has submitted its standard contractual clauses to the Article 29 Data Protection Working Party of the European Union for review and approval. The group has determined that the implementation of the provisions in the Microsoft agreements meets their strict requirements. Further information on the data protection at Microsoft can be found at https://www.microsoft.com/de-de/trust-center/privacy?rtc=1

Conversion measurement through the Facebook Pixel / Custom Audience

With the user’s permission, our website utilises the Conversion Tracking Pixel service provided by Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA (“Facebook”). With the aid of pixels, we are able to track certain user actions after they have viewed or clicked on a Facebook ad. This enables us to analyse the effectiveness of Facebook ads for statistical and market research purposes. The data captured through the use of pixels is rendered anonymous to us. We are unable to recognise personal data of individual users. However, this data will be stored and processed by Facebook. Facebook can link this data with your Facebook account and use it for its own advertising purposes in accordance with its own data processing regulations https://www.facebook.com/about/privacy/.

You can allow Facebook and its partners to display adverts on and outside of Facebook. In addition, a cookie will be saved onto your computer for these purposes. This consent is effective only if the user was at least 16-years old at the time of issuing the declaration of consent. If you do not want Custom Audience to capture data, you can deactivate Custom Audiences here.

LinkedIn

Our website uses functions provided by the LinkedIn network. The provider is the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time one of our online pages containing LinkIn functions is accessed, a connection is established to servers operated by LinkedIn. LinkedIn is informed that you have visited our website with your IP address. If you click the LinkedIn “Recommend” button and are logged into your LinkedIn account, it is possible for LinkedIn to establish a correlation between your visit to our website and your user account. We wish to point out that, as the provider of this website, we receive no information on the content of the transmitted data or its use by LinkedIn.

For more information, please see LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy

Hotjar

We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback.

Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

For further details, please see the Hotjar's privacy policy: https://www.hotjar.com/legal/policies/privacy/

Cloudflare

On our website, we use the services of the provider Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107). Cloudflare operates a content delivery network (CDN) and provides protection features for the website (web application firewall). The data transfer between your browser and our servers flows through Cloudflare's infrastructure. Cloudflare uses cookies for this purpose to enable you to access our website and helps us to ensure/increase the functionality of the website and provide you with content more quickly. The use of Cloudflare is in the interest of a safe and trouble-free use of our Internet presence and the defense against harmful attacks from the outside. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. You can find Cloudflare's privacy policy here.

The tool has a third-country reference, which means that the collected data may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called "standard contractual clauses" with the provider for data protection compliance within the requirements of the GDPR. Nevertheless, it cannot be ruled out that data may be processed by U.S. authorities for control and monitoring purposes when transferred to the U.S., without you possibly having any legal remedies.

Usercentrics

For the provision of a cookie consent banner on our website and the connected functions, we use the Usercentrics consent management platform (Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany). The Usercentrics Consent Management Platform collects log file data and consent data via a Javascript. This enables us to inform the user about certain tags, plugins, cookies and web technologies on our website and to obtain, manage and document their consent. The legal basis for the use of the Consent Management Platform and the associated processing of your personal data is Art. 6 (1) sentence 1 f) GDPR. Our legitimate interest lies in the legally secure documentation and verifiability of consents, the control of marketing measures on the basis of the consent granted. You can find more information about Usercentrics' privacy policy here.

Zoom

We use the Zoom tool provided by Zoom Video Technologies, Inc. for conducting webinars. Zoom processes and stores the data relevant for attending a webinar (such as email address, name and company). Usage behaviour is tracked during webinar attendance for the purpose of optimising the webinar service.

The tool has a third-country reference, which means that the collected data may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called "standard contractual clauses" with the provider for data protection compliance within the requirements of the GDPR. Nevertheless, it cannot be ruled out that data may be processed by U.S. authorities for control and monitoring purposes when transferred to the U.S., without you possibly having any legal remedies.

6. Social media plug-ins

We use Facebook social plug-ins for advertising purposes, on the basis of Art. 6 (1) sentence 1 f) GDPR. This is regarded as a legitimate interest within the definition of the GDPR. Responsibility for operation in compliance with data protection rules must be guaranteed with the relevant provider. We integrate these plug-ins using the “two-click method” in order to provide the best possible protection to visitors to our website.

Our website employs Facebook social media plug-ins to personalise use of the site. For this purpose, we use “LIKE” and “SHARE” buttons. This is a service provided by Facebook. If you access one of our online pages containing such a plug-in, your browser will establish a direct connection with Facebook servers. The contents of the plug-in are sent by Facebook directly to your browser and are incorporated by Facebook into the website. By incorporating the plug-ins, Facebook receives the information that your browser has requested the relevant page of our website, even if you do not have a Facebook account or are not logged into Facebook at the time.

This information (including your IP address) will be relayed to a Facebook server in the USA and stored there. If you are logged into Facebook, Facebook will be able to directly correlate the visit to our website with your Facebook account. If you interact with the plug-ins, for example by clicking on the “LIKE” or the “SHARE” button, the relevant information is also sent directly to a Facebook server and stored there.

The information will also be published on Facebook and displayed to your Facebook friends. Facebook can use this information for the purposes of advertising, market research and for designing Facebook pages in line with users’ requirements. To this end, Facebook creates usage, interests and relationship profiles, for example to analyse your use of our website in connection with the adverts Facebook shows you, to inform other Facebook users of your activities on our website, and to deliver other services connected with using Facebook.

If you do not wish for Facebook to correlate the data collected via our website with your Facebook account, you should log out of Facebook before visiting our site. Please read Facebook’s Privacy Policy for information on the purpose and scope of the data capture and how data is subsequently processed and used by Facebook, as well as your rights in this context and the settings available to you for the protection of your privacy (https://www.facebook.com/about/privacy/).

7. Rights of the data subject

If you are affected by the processing of data in connection with our online site, you have the right:

  • in accordance with Art. 15 GDPR, to request information from us detailing the personal data belonging to you and currently being processed by us. In particular, you may request information about the purposes of the processing, the category of the personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to object to a supervisory authority, the origin of your data insofar as it was not collected by us, and the existence of an automated decision-making process (including profiling) and any significant information regarding the specific details involved in this process;

  • in accordance with Art. 16 GDPR, to request that any incorrect or incomplete personal data belonging to you and stored by us be rectified without delay;

  • in accordance with Art. 17 GDPR, to request that personal data belonging to you and stored by us be erased insofar as the processing of said data is not required for exercising the right to free expression of opinion and information, for fulfilling a legal requirement, for reasons of public interest, or for the purposes of asserting, exercising or defending legal claims;

  • in accordance with Art. 18 GDPR, to request that the processing of your personal data be limited insofar as you dispute the correctness of the data or the processing of said data is unlawful, but you do not wish for the data to be erased; in this case, the data are no longer required by us but would be required by you for the purposes of asserting, exercising or defending legal claims, or for objecting to the processing of said data in accordance with Art. 21 GDPR;

  • in accordance with Art. 20 GDPR, to request that your personal data provided to us be made available to you or another authorised party in a structured, standardised and machine-readable format;

  • in accordance with Art. 7 (3) GDPR, to revoke the consent that you previously provided to us, at any time. This means that we will not be permitted to continue processing the data based on this consent in future, and

  • in accordance with Art. 77 GDPR to lodge a complaint with a supervisory authority. Generally speaking, for this purpose you can contact the supervisory authority at your usual place of residence or work, or that of our company’s main office.

8. Right of objection

Insofar as your personal data is processed based on legitimate interests as defined under Art. 6 (1) sentence 1 f) GDPR, you have the right – in accordance with Art. 21 GDPR – to object to your personal data being processed, provided that there are grounds pertaining to your particular circumstances or that the objection is directed towards direct advertising. In the latter case, you have a general right of objection, which we will implement without the indication of any special circumstances.

If you wish to exercise your right of revocation or objection, please send us an email to dataprivacy@facelift-bbt.com.

9. Data security

We operate an information security management system in accordance with ISO 27001, and we are certified accordingly. We upgrade these security measures continually in line with advancements in technology. We employ suitable technical and organisational measures in order to protect your data from accidental or intentional manipulation, partial or complete loss, destruction or access by unauthorised third parties.

During your website visit, we will apply the commonly used SSL (Secure Socket Layer) procedure in conjunction with the highest encryption level supported by your browser. This is generally 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. You can see whether an individual page of our website is transmitted in encrypted form by looking for the closed key or lock symbol on the lower status bar of your browser.

Finally, we would like to point out that when transferring data via the internet, it cannot be guaranteed that this data will be fully protected against access by third parties. We do not accept any liability for damage or loss sustained caused by such security vulnerabilities, or for claims for injunctive relief.

10. Facelift Cloud Third Party Services

In order to work with Facelift Cloud, users are able to connect social networks via "Client APIs" to Facelift Cloud in self-service. By using Facelift Cloud customers and users agree on the below linked Terms of Service and Privacy Policies of these services.

Facebook
Terms of Service: https://www.facebook.com/terms.php
Privacy Policy: https://www.facebook.com/policy.php

Google My Business
Terms of Service: https://policies.google.com/terms
Privacy Policy: https://policies.google.com/privacy

Instragram
Terms of Service: https://help.instagram.com/581066165581870
Privacy Policy: https://help.instagram.com/519522125107875

LinkedIn
Terms of Service: https://legal.linkedin.com/service-specific-terms
Privacy Policy: https://www.linkedin.com/legal/privacy-policy

Pinterest
Terms of Service: https://policy.pinterest.com/en/terms-of-service
Privacy Policy: https://policy.pinterest.com/en/privacy-policy

Twitter
Terms of Service: https://twitter.com/tos
Privacy Policy: https://twitter.com/privacy

Whatsapp
Terms of Service: https://www.whatsapp.com/legal/
Privacy Policy: https://www.whatsapp.com/privacy

XING
Terms of Service: https://www.xing.com/terms
Privacy Policy: https://privacy.xing.com/en

Youtube
Terms of Service: https://www.youtube.com/t/terms
Privacy Policy: https://policies.google.com/privacy