Data privacy

 

Privacy policy

Thank you for visiting our website and for your interest in data protection. Below you will find an overview of what personal data is and how it is processed. In addition, we will inform you about your rights and other topics relevant to data protection.

RESPONSIBLE PARTY

Cofana GmbH
Managing Director: Daniel Becker

Boxhagener Street 72
10245 Berlin
Germany

Phone: +49 (0)176 434 499 27
Mail: info@lsd-legal.de
Commercial register: Charlottenburg Local Court, HRB 228911 B
Sales tax identification number: DE815903901

PERSONAL DATA

According to Art. 4 No. 1 DSGVO, personal data is any information relating to an identifiable natural person. This includes, for example, the name, address, customer number, telephone number and also the IP address. In summary, any information about natural persons that can directly or indirectly identify the person is to be considered personal data.

Accordingly, you will be informed in this way about the way in which personal data is processed on our website.

DATA COLLECTION AND PROCESSING

The purpose of processing and collecting data on our website is, in addition to ensuring security, to provide information about our services and general information about the company.

During processing, we pay particular attention to the necessity and proportionality in accordance with Art. 5 DSGVO. Furthermore, personal data is only processed in accordance with Art. 6 of the DSGVO.

The transmission of your data takes place on the one hand by yourself when you contact us via our contact forms to inform you about our range of products and services, job opportunities and other company-related matters.

In addition to the voluntary transmission, an automatic transmission of your data also takes place. For example, when you access our site, metadata such as IP address, browser type and version, operating system used, amount of data transferred, time and date of access and referring URL are transmitted to our web servers. The collection of the data is necessary for the provision of our websites and the storage of the data in log files is mandatory for the operation of our websites and is based on the legal basis of Art. 6 para. 1 lit. f DSGVO. The servers on which these websites are operated are located in Germany. We have concluded a corresponding order processing agreement with the provider of the servers.

The IP address is thereby anonymized by shortening it, so that an identification of individual users is not possible at any time. For statistical purposes and to analyze user behavior, your data is used in anonymized form. In this way, we ensure that our offers are always up-to-date and tailored to your needs.

Your personal data will be deleted or blocked as soon as the purpose of the storage is no longer applicable. However, the deletion or blocking of data is prevented if we, as the responsible body, have to comply with corresponding commercial or tax law retention obligations. Such a case exists, for example, if we process accounting-relevant data and must store it for 10 years in accordance with Section 147 (4) of the German Fiscal Code (AO).

When using service providers, we ensure that your data is handled in accordance with the law by concluding a contract processing agreement (CPA) with our service provider based on Art. 28 DSGVO. Our service provider processes data on our behalf in accordance with instructions. Thus, the responsibility for proper data processing remains with us.

Hosting

Akamai Content Delivery Network

We use the Content Delivery Network (CDN) of Akamai Technologies GmbH, Parkring 20, 85748 Garching Germany (Akamai) to increase the security and delivery speed of our website. We thus have a legitimate interest (Art. 6 para. 1 lit. f DSGVO). A CDN is a network of servers distributed worldwide that is able to deliver optimized content to the user of the website. For this purpose, the following personal data may be processed in server log files by Akmai:

Your IP address

 

URLs of the pages visited

Date and time of access

Location based on your IP address and the location of the Akamai server

Telemetry data (e.g., mouse clicks, movement patterns, and related browser data).

Your personal data will be stored by Akamai for as long as necessary for the purposes described.

For more information on how to opt out and unsubscribe from Akamai, please visit:

 

 

USE OF COOKIES

Our website uses cookies. Cookies are small text files that are stored in the Internet browser or in the user’s terminal device. The browser is recognized by unique identification the next time the website is visited. Thus, among other things, cookies allow us to infer visitor preferences with regard to the website, which in turn helps us to make our website more user-friendly.

The stored data may include language settings, log in information, search terms entered, frequency of page views as well as the use of website functions. The legal basis for the processing of personal data using cookies is Art. 6 para. 1 lit. f DSGVO.

A distinction is made between the following cookie types and functions:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their browser.
  • Permanent cookies: Permanent cookies remain stored even after the browser is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. The interests of users that are used to measure reach or for marketing purposes can also be stored in such a cookie.
  • First-party cookies: First-party cookies are set by us.
  • Third-party cookies (also: third-party cookies): Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.
  • Necessary (also: essential or absolutely necessary) cookies: Cookies may be absolutely necessary for the operation of a website (e.g. to store logins or other user input or for security reasons).
  • Statistical, marketing and personalization cookies: Cookies are also generally used to measure reach and when a user’s interests or behaviour (e.g. viewing certain content, using functions, etc.) on individual websites are stored in a user profile. Such profiles are used, for example, to show users content that matches their potential interests. This process is also referred to as “tracking”, i.e. tracking the potential interests of users. If we use cookies or “tracking” technologies, we will inform you separately in our privacy policy or when obtaining consent.
 

Wistia

Statistics

Usage

Sharing data

This data is not shared with third parties.

Statistics

Name
Expiration
persistent
Function
Store if the user has seen embedded content

Elementor

Statistics (anonymous)

Usage

Sharing data

This data is not shared with third parties.

Statistics (anonymous)

Name
Expiration
persistent
Function
Store performed actions on the website

WooCommerce

Functional

Usage

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
session
Function
Store items in shopping cart
Name
Expiration
session
Function
Store performed actions on the website
Name
Expiration
persistent
Function
Name
Expiration
session
Function
Store items in shopping cart
Name
Expiration
session
Function
Store performed actions on the website
Name
Expiration
1 day
Function
Store items in shopping cart
Name
Expiration
session
Function
Store performed actions on the website

Complianz

Functional

Usage

Sharing data

This data is not shared with third parties. For more information, please read the Complianz Privacy Statement.

Functional

Name
Expiration
365 days
Function
Read to determine which cookie banner to show
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store accepted cookie policy ID
Name
Expiration
365 days
Function
Store if the cookie banner has been dismissed
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences

WordPress

Functional

Usage

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
session
Function
Store browser details

Google Analytics

Statistics

Usage

Sharing data

This data is not shared with third parties.

Statistics

Name
Expiration
2 years
Function
Store and count pageviews
Name
Expiration
1 year
Function
Store and count pageviews

Sourcebuster JS

Statistics

Usage

Sharing data

This data is not shared with third parties.

Statistics

Name
Expiration
6 months
Function
Name
Expiration
6 months
Function
Name
Expiration
6 months
Function
Store browser details
Name
Expiration
6 months
Function
Name
Expiration
Function

WPML

Functional

Usage

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
1 day
Function
Store language settings

Miscellaneous

Statistics

Usage

Sharing data

Sharing of data is pending investigation

Purpose pending investigation

Name
continueReview
Expiration
Function
Name
__kla_viewed
Expiration
Function
Name
Expiration
Function
Name
e_kit-elements-defaults
Expiration
Function
Name
wistia
Expiration
Function
Name
klaviyoOnsite
Expiration
Function
Name
klaviyoPagesVisitCount
Expiration
Function
Name
_swa_u
Expiration
Function
Name
__kla_id
Expiration
Function

Statistics

Name
Expiration
6 months
Function
Name
Expiration
6 months
Function

 

Notes on legal bases: The legal basis on which we process your personal data with the help of cookies depends on whether we ask you for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is the declared consent. Otherwise, the data processed using cookies will be processed on the basis of our legitimate interests (e.g. in the business operation of our online offering and its improvement) or, if the use of cookies is necessary to fulfill our contractual obligations.

Storage duration: If we do not provide you with explicit information on the storage duration of permanent cookies (e.g. as part of a so-called cookie opt-in), please assume that the storage duration can be up to two years.

General information on revocation and objection (opt-out): Depending on whether the processing is based on consent or legal permission, you have the option at any time to revoke any consent you have given or to object to the processing of your data by cookie technologies (collectively referred to as “opt-out”). You can initially declare your objection using your browser settings, e.g. by deactivating the use of cookies (although this may also restrict the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared using a variety of services, especially in the case of tracking, via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. You can also obtain further information on how to object in the context of the information on the service providers and cookies used.

Processing of cookie data on the basis of consent: We use a cookie consent management procedure in which the consent of users to the use of cookies or the processing and providers mentioned in the cookie consent management procedure can be obtained, managed and revoked by users. The declaration of consent is stored so that it does not have to be requested again and the consent can be proven in accordance with the legal obligation. The storage can take place on the server side and/or in a cookie (so-called opt-in cookie, or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following information applies: Consent may be stored for up to two years. A pseudonymous user identifier is created and stored with the time of consent, information on the scope of consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used.

  • Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a. GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).

 

Cookie settings:

If you would like to change the cookie settings, please click on this link.

 

E-MAIL and Newsletter

You have the option to contact us via the email address provided. In this case, the personal data of the user transmitted with the email will be stored. The processing of the information and request is in accordance with Art. 6 para. 1 lit. f DSGVO.

If you send us an email, this email will be stored on our servers. The transmitted data will be deleted by us as soon as the purpose of collection ceases to apply. Emails are generally stored on our servers for up to 10 years. If you wish an early deletion, please contact us. For more information about your rights, please refer to the section “Rights of the data subject”.

We would like to point out that unencrypted e-mail communication is not guaranteed to be protected from unauthorized third-party access. On the other hand, you can use our online forms to send us your request in encrypted form.

If you are interested in current information and offers regarding our company and our range of products and services, you can subscribe to our free newsletter with a valid e-mail address.

In order to prevent misuse of our services or the e-mail address used, we collect your IP address as well as the date and time of registration in addition to the e-mail address. You will then receive a confirmation email with a corresponding activation link as part of a double opt-in process, where you give us your consent to receive our newsletter in accordance with Art. 6 Para. 1 lit. a by activating this activation link with a click. In addition, you provide us with proof that you are the owner of the registered email address. Your data will only be used for sending the newsletter and will not be passed on to third parties.

You can cancel the subscription at any time. For this purpose, you will find a corresponding link in the lower section of each newsletter.

Application procedure

In the context of an online application, personal data about you will be requested and collected. The transmission is encrypted according to the state of the art. This data will only be used by the respective personnel managers and exclusively within the scope of the application procedure and for the purpose of processing your application. The legal basis for the processing here is § 26 BDSG, Art. 6 para. 1 lit. b. DSGVO and Art. 6 para. 1 lit. f. DSGVO.

After completion of the application process, your documents will be deleted after a period of 4 months. An exception to this exists if we are subject to a legal obligation pursuant to Art. 6 para. 1 lit. c.

GOOGLE MAPS

To display a map of the site, this website uses Google Maps from Google Inc -1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

This processing is carried out in the sense of Art. 6 1 lit. F DSGVO and represents a legitimate interest of the responsible parties.

For more information, please refer to the Google Maps Terms of Use at https://www.google.com/intl/de_de/help/terms_maps.html

 

Due to Google’s participation in Privacy Shield, an adequate level of data protection can be assumed for the processing of personal data despite a transfer to a third country.

GOOGLE AJAX & JQUERY LIBRARIES

We use the so-called Ajax & jQuery technologies on our site in order to be able to call up corresponding program libraries from Google, so-called CDN (content delivery network). By using Ajax and jQuery, we hope to optimize the loading speed. This can happen, for example, if a user has previously used CDN on another Google page and the browser falls back on the cached copy. If this is not the case, the browser will download Google CDN and transmit data and browser information to Google for this purpose. We would like to inform you that this could result in a transfer to the USA. You can find more information on the provider’s pages or at: https://developers.google.com/speed/libraries/#jquery

 

GOOGLE WEB FONTS

External fonts, the so-called Google Fonts, are used on these web pages. Google Fonts enable us to display the fonts on our web pages in a consistent manner. When you access the website, your browser loads the web fonts into your browser cache. The integration of these web fonts is done by a server call, usually a Google server in the USA. For this purpose, the server is informed which of our web pages or sub-pages you have visited. Google thereby receives the IP address of the browser of the visitor’s end device. This processing is carried out in accordance with Art. 6 1 lit. F DSGVO and represents a legitimate interest of the responsible parties. You can find more information in the privacy policy of Google: https://developers.google.com/fonts/faq – https://policies.google.com/privacy?hl=de

 

GOOGLE RECAPTCHA


To ensure sufficient data security when transmitting your data through forms, we use Google reCAPTCHA from Google Inc. This ensures that the input in our contact forms is made by a natural person and not by an automated program. This in turn prevents misuse of your data (for example SPAM or automated spying). For this purpose, reCAPTCHA analyzes – in the background – the behavior of the website visitor based on various characteristics. Among other things, the IP address, data about mouse movements and previously visited web pages are transmitted to Google. In order to maintain the quality and security of our website, the use of reCAPTCHA is a legitimate interest pursuant to Art. 6 (1) lit f DSGVO.


The use of Google services constitutes a transfer of personal data to a third country (USA). Under data protection law, when data is processed in a non-EU member state, it must be ensured that it is handled in accordance with data protection law. Since Google is on the Privacy Shield list, we can assume an adequate level of data protection for the processing of personal data.


You can find more information about the privacy policy of Google Inc. at: http://www.google.de/intl/de/privacy oder https://www.google.com/intl/de/policies/privacy/

 

Facebook


We use the Facebook pixel to show our visitors interest-based advertising on social media channels as well.


The visitor’s browser establishes a connection with the Facebook servers. Thus, Facebook knows that the user has visited our website.


The legal basis for the processing is the user’s consent, which is obtained directly after visiting our website.


You can object to this processing at any time by using an opt-out option in the cookie section.


INTEGRATION OF VIDEOS – YOUTUBE & Vimeo.


In the interest of an appealing presentation of our online offers, we embed some videos of the Google-operated site Youtube, pursuant to Art 6 para 1 lit. f, in our websites and social media pages. When you play or visit these pages, your data is stored on the servers of YouTube, which is based in the USA (YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA).


Among other things, information about visited pages, IP address and other data about your browser type are passed on to YouTube. If you are logged into your Youtube account, your surfing behavior can be assigned to your personal profile. If you do not want this, you should log out of your account beforehand.


You can find more information about the processing of user data in Youtube’s privacy policy. https://www.google.de/intl/de/policies/privacy/

 

SECURITY


We have taken extensive technical and administrative precautions to protect your personal data against loss, destruction, manipulation and unauthorized access. To protect your data, we have committed our employees and service providers to the applicable data protection laws.


The security of your data is very important to us. Therefore, the data transmission on our site takes place without exception with appropriate encryption methods, recognizable by the address line of the browser “https:. This ensures that your data cannot be misused by third parties.

RIGHTS OF THE DATA SUBJECT


When personal data of a user is processed, the user is a “data subject” within the meaning of the GDPR. He is entitled to the following rights against us as the data controller:

  1. Right to information
  2. Right to rectification
  3. Right to restriction of processing
  4. Right to deletion
  5. Right to information
  6. Right to data portability
  7. Right to object
  8. Right to revoke the declaration of consent under data protection law
  9. Right to lodge a complaint with a data protection authority


Note on revocation of consent


Although a data subject has the right to revoke his or her declaration of consent under data protection law with us at any time, this does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.


Notice of complaint to a supervisory authority


Without prejudice to any other administrative or judicial remedy, a data subject has the right to lodge a complaint with a supervisory authority – in particular in the Member State of the user’s residence, the user’s place of work or the place of the alleged infringement – if the user believes that the processing of his personal data by us violates the GDPR.


You can submit your complaint, for example, to the Bavarian State Office for Data Protection Supervision: https://www.lda.bayern.de/de/beschwerde.html

 

Right to object to the collection of data


If the data processing is based on Art. 6 (1) lit. e or f DSGVO, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation. You can find the respective legal basis on which the processing is based in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims (objection under Article 21(1) DSGVO).


If you believe that the processing of personal data concerning you violates the GDPR, you have the right to lodge a complaint with a supervisory authority pursuant to Article 77 of the GDPR. You can submit your complaint, for example, to the Bavarian State Office for Data Protection Supervision: https://www.lda.bayern.de/de/beschwerde.html

 

CHANGES TO OUR PRIVACY POLICY


We reserve the right to adapt and supplement this privacy policy if this should be necessary due to new technologies, current and changing legal requirements or other reasons.

My cart
Your cart is empty.

Looks like you haven't made a choice yet.