The following data protection declaration applies to the use of the website www.studio-lacks.com (hereinafter “website”).
We attach great importance to data protection. The collection and processing of your personal data is carried out in compliance with the applicable data protection regulations, in particular the EU General Data Protection Regulation (DSGVO). We collect and process your personal data in order to offer you the above-mentioned portal. This statement describes how and for what purpose your data is collected and used and what choices you have in connection with personal data.
1 Responsible entity
The responsible party for the collection, processing and use of your personal data within the meaning of the DSGVO is
Becker Eschenauer Scholl GbR
If you wish to object to the collection, processing or use of your data by us in accordance with these data protection provisions, either as a whole or for individual measures, you may address your objection to the above-mentioned responsible office.
2 General use of the website
2.1 Access data
We collect information about you when you use this website. We automatically collect information about your usage behavior and your interaction with us and register data about your computer or mobile device. We collect, store and use data about each access to our online offer (so-called server log files). The access data includes
- Name and URL of the file accessed,
- date and time of the retrieval,
amount of data transferred,
- Message about successful retrieval (HTTP response code),
- Browser type and version, operating system,
- Referrer URL (i.e. the previously visited page),
- IP address and the requesting provider.
We reserve the right to subsequently review the log data if there is a justified suspicion of unlawful use based on concrete indications. We store IP addresses in the log files for a limited period of time if this is required for security purposes or necessary for the provision of services or the billing of a service, e.g. if you use one of our offers. After the order process has been cancelled or after payment has been received, we delete the IP address if it is no longer required for security purposes. We also store IP addresses if we have a concrete suspicion of a criminal offense in connection with the use of our website. In addition, as part of your account, we store the date of your last visit (e.g. when registering, logging in, clicking links, etc.).
2.2 Legal basis and storage period
The legal basis for data processing pursuant to the above paragraphs is Art 6 (1) (f) DSGVO. Our interests in data processing are in particular to ensure the operation and security of the website, to study the way visitors use the website, and to simplify the use of the website.
Unless specifically stated, we store personal data only as long as necessary to fulfill the purposes pursued.
3 Your rights as a data subject affected by data processing
According to the applicable laws, you have various rights regarding your personal data. If you wish to exercise these rights, please send your request by e-mail or by post, clearly identifying yourself, to the address mentioned in section 1.
Below you will find an overview of your rights.
3.1 Right to confirmation and information
You have the right to obtain confirmation from us at any time as to whether personal data relating to you is being processed. If this is the case, you have the right to obtain from us, free of charge, information about the personal data stored about you, together with a copy of this data. Furthermore, you have the right to the following information:
- the purposes of processing;
- the categories of personal data processed;
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular in the case of recipients in third countries or international organizations;
- if possible, the planned duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration;
- the existence of a right to obtain the rectification or erasure of personal data concerning you, or to obtain the restriction of processing by the controller, or a right to object to such processing;
- the existence of a right of appeal to a supervisory authority;
- if the personal data is not collected from you, any available information about the origin of the data;
- the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR and, at least in these cases, meaningful information about the logic involved and the scope and intended effects of such processing for you.
If personal data are transferred to a third country or to an international organization, you have the right to be informed about the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.
3.2 Right to rectification
You have the right to demand that we correct any inaccurate personal data concerning you without delay. Taking into account the purposes of the you have the right to request the completion of incomplete personal data – also by means of a supplementary statement.
3.3 Right to erasure (“right to be forgotten”)
You have the right to request that we delete personal data relating to you without undue delay, and we are obliged to delete personal data without undue delay, if one of the following reasons applies:
- The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Article 6(1) DSGVO(a) or Article 9(2)(a) DSGVO and there is no other legal basis for the processing.
- You object to the processing pursuant to Article 21(1) DSGVO and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) DSGVO.
- The personal data have been processed unlawfully.
- The erasure of the personal data is necessary for compliance with a legal obligation under Union or Member State law to which we are subject.
- The personal data has been collected in relation to information society services offered in accordance with Article 8(1) DSGVO.
If we have made the personal data public and we are obliged to erase it in accordance with the available technology and implementation costs, we shall take reasonable measures, including technical measures, to inform data controllers that process the personal data that you have requested erasure of all links to or copies or replications of such personal data.
3.4 Right to restriction of processing
You have the right to request us to restrict processing if one of the following conditions is met:
- the accuracy of the personal data is contested by you for a period of time which enables us to verify the accuracy of the personal data,
- the processing is unlawful and you refused to erase the personal data and instead request the restriction of the use of the personal data;
- we no longer need the personal data for the purposes of processing, but you required the data for the assertion, exercise or defense of legal claims; or
- you have objected to the processing pursuant to Article 21(1) of the GDPR, as long as it has not yet been determined whether the legitimate reasons prevail over ours.
3.5 Right to data portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transfer this data to another controller without hindrance from us, provided that
- the processing is based on consent pursuant to Article 6(1)(a) DSGVO or Article 9(2)(a) DSGVO or on a contract pursuant to Article 6(1)(b) DSGVO and
- the processing is carried out with the aid of automated procedures.
When exercising your right to data portability pursuant to paragraph 1, you have the right to obtain that the personal data be transferred directly from us to another controller, where technically feasible.
3.6 Right of objection
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) DSGVO; this also applies to profiling based on these provisions. We will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims.
3.7 Automated decisions including profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
3.8 Right to revoke consent under data protection law
You have the right to revoke consent to the processing of personal data at any time, as long as no higher law allows or requires it.
3.9 Right to complain to a supervisory authority
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement, you believe that the processing of personal data concerning you is unlawful.
4 Data security
We make every effort to ensure the security of your data within the framework of the applicable data protection laws and technical possibilities.
Your personal data is transmitted encrypted with us. This applies to your orders and also to the customer login. We use the SSL (Secure Socket Layer) coding system, but we would like to point out that data transmission on the Internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
To protect your data, we maintain technical and organizational security measures, which we constantly adapt to the state of the art.
We also do not guarantee that our service will be available at certain times; disruptions, interruptions or failures cannot be ruled out. The servers we use are carefully backed up on a regular basis.
5 Data collection on our website
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- Operating system used
- referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
The collection of this data is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be collected.
Our Internet pages use so-called “cookies”. Cookies are small text files and do not cause any damage to your terminal device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your end device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or until they are automatically deleted by your web browser.
In some cases, cookies from third-party companies may also be stored on your terminal device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or display advertising.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions that you have requested (e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 (1) lit. f DSGVO, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
Insofar as cookies are used by third-party companies or for analysis purposes, we will inform you separately about this within the framework of this data protection declaration and, if necessary, request your consent.
You can change or revok your consent at any time.
Please provide your consent ID and date when contacting us regarding your consent.
Your consent ID:
Essential cookies enable basic functions and are necessary for the proper functioning of the website.
|Provider||Eigentümer dieser Website, Imprint|
|Purpose||Speichert die Einstellungen der Besucher, die in der Cookie Box von Borlabs Cookie ausgewählt wurden.|
|Cookie Expiry||1 Jahr|
Marketing cookies are used by third-party vendors or publishers to display personalized advertisements. They do this by tracking visitors across websites.
|Provider||Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland|
|Purpose||Cookie from Google for website analytics. Generates statistical data about how the visitor uses the website.|
|Cookie Expiry||26 Monate|
Google Tag Manager
|Name||Google Tag Manager|
|Provider||Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland|
|Purpose||Cookie from Google to control advanced script and event handling.|
|Cookie Expiry||26 Monate|
Consent with Borlabs Cookie
Our website uses Borlabs Cookie consent technology to obtain your consent to store certain cookies in your browser or to use certain technologies, and to document this consent in a privacy-compliant manner. The provider of this technology is Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg (hereinafter Borlabs).
When you enter our website, a Borlabs cookie is stored in your browser, in which the consents you have given or the revocation of these consents are stored. This data is not shared with the Borlabs cookie provider.
The collected data will be stored until you request us to delete it or until you delete the Borlabs cookie yourself or until the purpose for storing the data no longer applies. Mandatory legal retention periods remain unaffected. Details on the data processing of Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
6 Analysis tools and advertising
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, length of stay, operating systems used and the origin of the user. This data may be summarized by Google in a profile that is assigned to the respective user or their end device.
Furthermore, Google Analytics may record your mouse and scroll movements and clicks, among other things. Furthermore, Google Analytics uses various modeling approaches to supplement the collected data sets and uses machine learning technologies in the data analysis.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.
The use of this analysis tool is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (e.g. consent to store cookies), the processing is based exclusively on Art. 6 para. 1 lit. a DSGVO; the consent can be revoked at any time revocable.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
We have concluded an order processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic characteristics with Google Analytics
This website uses the “demographic characteristics” function of Google Analytics to display suitable advertisements to website visitors within the Google advertising network. This allows reports to be generated that include statements about the age, gender, and interests of site visitors. This data comes from interest-based advertising from Google as well as from visitor data from third-party providers. This data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as shown in the item “Objection to data collection”.
Data stored by Google at user and event level that is linked to cookies, user identifiers (e.g. User ID) or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) is anonymized or deleted after 2 months. For details, please see the following link: https://support.google.com/analytics/answer/7667196?hl=de
7 Automated decision making
Automated decision-making based on the personal data collected does not take place.
8 Disclosure of data to third parties
In principle, we only use your personal data internally. If and to the extent that we involve third parties in the performance of contracts (such as service providers), they will only receive personal data to the extent that the transfer is necessary for the corresponding service. In the event that we outsource certain parts of data processing (“commissioned processing”), we contractually oblige commissioned processors to use personal data only in accordance with the requirements of data protection laws and to ensure the protection of the rights of the data subject.
9 Changes to the data protection provisions