Data protection

1. Data Protection at a Glance

General Information
The following information is intended to give you an easy overview of what will happen to your personal data when you visit our website. Personal data refers to all data which makes you per-sonally identifiable. For detailed information about data protection, please refer to our Privacy Statement below this text.

Data Collection on Our Websites
Who is responsible for collecting data on this website? On these websites, data processing is performed by the website operator. Contact information:

ONLEVEL GmbH
Budberger Straße 5
46446 Emmerich am Rhein (Germany)
+49 2822 97514-0
info@onlevel.com

How do we collect your data?
One way of collecting data is by your disclosing them to us. This can be data, for example, that you enter into a contact or order form. Other data is collected automatically by our IT systems once you visit our website. These are mainly technical data (e.g. internet browser, operating system or time when viewing the site). The data are collected automatically as soon as you enter our website.

What do we use your data for?
Some of the data is collected in order to ensure the trouble-free provision of the website, or for order or delivery purposes, and other data may be used to analyse your user behaviour.

Which rights do you have with respect to your data?
You are entitled to receive information at all times and free of charge about the origin, the recipi-ent and the purpose of your stored personal data. In addition, you are entitled to demand the rectification, erasure or blocking of such data. If you have further questions about this topic or about data protection in general, please contact us at all times at the address indicated above. You also have the right to appeal to the responsible supervisory authority.

Analytical Tools and Third-Party Provider Tools
When visiting our website, your surfing behaviour can be statistically evaluated. This is primarily done with cookies and with so-called analysis programmes. Your surfing behaviour is generally analysed anonymously; it cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You can find further detailed information in the following statements. You can object to this analysis. Learn more about the possibilities of objection here.

2. Detailed Guidance and Mandatory Information

Data Privacy
The providers of these websites takes the protection of your personal data very seriously. We treat your personal data confidentially and comply with the corresponding legal data protection regulations and this Privacy Statement. When you use this website, different personal data will be collected. Personal data refers to data which makes you personally identifiable. This Privacy Statement lays down which data we col-lect and what we use it for. It also outlines how and for which purpose this is done.
We point out that the transmission of data via the internet (such as when communicating by e-mail) may involve security gaps. It is not possible to fully protect the data from being accessed by third parties.

Data Collection and Usage for Contract Execution and for Opening a Customer Account
We collect personal data, especially if you make them available to us voluntarily when placing your order, making contact with us (e.g. via a contact form or by e-mail), or when open-ing a customer account. Mandatory fields are marked as such as in these cases, this data is man-datory for executing a contract, for processing your request or opening a customer account and without which your order cannot be concluded and/or your account cannot be final-ly opened or your request cannot be sent. The input form clearly indicates which data is collected.

We use the data you make available to us pursuant to Art. 6 Para. 1 S. 1 lit. b GDPR for execut-ing contracts and answering your requests. After complete performance of the contract or eras-ure of your customer account, your data will be limited for further processing and erased upon expiry of the statutory retention periods according to tax and commercial law, unless you have expressly consented to the further use of your data or we reserve the right to use the data beyond this scope, which is permitted by law and about which we will notify you in this Privacy Statement. The erasure of your customer account is possible at any time either via a message to the contact details indicated below or via a function provided in the customer account.

Data Transfer
We transfer your data to the shipping company entrusted with the delivery for the purpose of contract execution pursuant to Art. 6 Para. 1 p. 1 lit. b GDPR, if this is required for the delivery of the ordered goods. Depending on which payment provider you choose while ordering, we pass on the payment data collected for this purpose to the authorised banking institution and payment provider commissioned by us, or the selected payment service for the pro-cessing of payments. The selected payment providers may in part collect this data themselves if you open an account with them. In this case, you must log in to the payment provider with your access data while ordering. The privacy statement of the respective payment provider shall apply in this respect. The same applies for the transfer of data to our manufacturers or wholesalers in the cases in which they take over the shipment for us (drop shipment).

Information on the Responsible Authority
The responsible authority for data processing on this website is:

ONLEVEL GmbH
Budberger Straße 5
46446 Emmerich am Rhein (Germany)
+49 2822 97514-0
info@onlevel.com

The responsible authority is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses or the like). You can contact our Data Protection Officer under the following address: thomas@onlevel.com.

Revocation of Your Consent to Data Processing
Many data processing activities are only possible with your express consent. You can withdraw the consent already granted at all times. For this purpose, an informal e-mail notification to us is sufficient. The lawfulness of the data processing having taken place before the revocation shall remain unaffected thereof.

Right of Appeal to the Responsible Supervisory Authority
In case of data protection violations, the person affected shall be entitled to appeal to the responsible supervisory authority. The competent supervisory authority in data protection mat-ters is the State Data Protection Officer of the German federal state in which our company has its headquarters. Please refer to the following link for a list of Data Protection Officers together with their contact details: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Right to Data Portability
You have the right to have data, processed by us or by automated means based on your consent or for contract execution purposes, handed over to you or a third party in a standard, machine-readable format. If you request the direct transfer of the data to another responsible person, this is only complied with if technically possible.

SSL and TLS Encryption
For safety reasons and in order to protect the transfer of confidential contents, such as orders or requests you send to us as website operator, the website uses SSL and TLS encryption. You can tell that a connection is encrypted if the ‘http://’ in your browser’s address bar changes to ‘https://’ along with a lock symbol next to it. With an enabled SSL and TLS encryption, data you send to us cannot be read by third parties.

Information, Blocking, Erasure
Within the scope of the applicable legal provisions, you are at any time entitled to free access to your retained personal data, its origin and recipients and the purpose of the data processing, and to rectification, blocking or erasure of this data, if applicable. Regarding this and other questions concerning personal data, you can contact us at any time at the address given in the legal notice.

Objection to Advertising E-Mails
We hereby object to the use of our contact details, as published under the obligation to provide a legal notice, for sending us marketing and information materials not expressly solicited by us. The operators of the web pages expressly reserve the right to take all legal steps in the case of the unsolicited sending of advertisement information, for example spam e-mails.

Right of Revocation
Insofar as we process personal data as indicated above for the protection of our legitimate prevailing interests within the scope of an overall balance of interests, you are entitled to object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you are entitled to exercise this right at all times, as described above. If the processing is carried out for other purposes, you are only entitled to a right of revocation for reasons relating to your particular situation.Upon exercising your right of revocation, we will no longer process your personal data for the respective purposes, unless we are able to provide legitimate and compelling grounds for pro-cessing which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. This does not apply if data is processed for direct marketing purposes. In this case, we will stop processing your personal data for this purpose.

3. Data Collection on Our Website

Cookies
The internet pages in part use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies are intended to make our offer safer, more effective and more user-friendly. Cookies are small text files that are placed on your computer and stored by your browser. Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies are stored on your terminal device until deleted by you. These cookies enable us to recognise your browser upon your next visit.You can configure your browser so as to be informed about the placement of cookies, to decide to accept these on a case-by-case basis or to exclude all incoming cookies in certain cases or in general and enable the automatic deletion of cookies when closing the browser. If cookies are disabled, the functionality of this website may be restricted.

Cookies, which are necessary for the execution of the electronic communication process or for the provision of certain functions desired by you (e.g. shopping cart function), are stored on the basis of Art. 6 Para. 1 lit. f GDPR. The website provider has a legitimate interest in storing the cookies to ensure the technically flawless and optimised provision of its services. Insofar as other cookies are stored (e.g. cookies used to analyse your surfing behaviour), these are addressed separately in this Privacy Statement.

Server Log Files
The provider of the pages collects and automatically stores information in so-called server log files, which your browser automatically sends to us. The following information is stored here:

•    Browser type and browser version
•    Operating system used
•    Referrer URL
•    Host name of the accessing computer
•    Time of the server request
•    IP address

This data is not merged with any other data sources.
The basis for data processing is Art. 6 Para. 1 lit. b GDPR, which permits the processing of data for execution purposes of a contract or precontractual measures.

Contact Form
If you use our contact form for sending us requests, the information indicated in the form, including your contact data, is saved by us for the purpose of handling your request and for an-swering any follow-up questions. We will not pass on these data without your consent.

The processing of the data indicated in the contact form is therefore exclusively based on your consent (Art. 6 Para. 1 lit. a GDPR). You can withdraw this consent at all times. For this pur-pose, an informal e-mail notification to us is sufficient. The lawfulness of the data processing having taken place before the revocation shall remain unaffected thereof.

The data indicated by you in the contact form is stored by us until you request their erasure, revoke your consent to storage or the data storage purpose ceases to exist (e.g. after having an-swered your request). Mandatory statutory provisions – especially retention periods – shall re-main unaffected thereof.

4. Social Media

Data Processing by Social Networks
We maintain publicly accessible profiles in social networks. Details of the specific social networks used by us are set out below. Social networks, such as Facebook, Google+ etc. are generally able to comprehensively analyse your user behaviour when you visit their websites or a website with integrated social media content (e.g. “Like” buttons or banner ads). Visiting our social media pages triggers numerous processing operations that are covered by data protection laws. In detail: If you visit our social media page when you are logged in to your social media account, the operator of the social media portal can assign this visit to your user ac-count. Under certain circumstances, your personal data may also be recorded even if you are not logged in or do not have an account with the social media portal in question. In this case, these data are collected, through cookies stored on your terminal device for example, or by recording your IP address. Using the data collected in this way, the operators of the social media portals are able to create user profiles containing your preferences and interests. In this way, you can be shown interest-based advertising both within and outside of the particular social media site. If you have an account with the social network, interest-based advertising can be displayed on any device you are logged in to or have previously logged in to. Please also note that we cannot track all processing operations on the social media portals.

Depending on the provider, other processing operations may therefore be performed by the so-cial media portal operators. Details can be found in the terms of use and privacy statements of the relevant social media portals.

Legal Basis
Our social media activity is designed to achieve the widest possible online presence. This is a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. The analysis processes trig-gered by the social networks may be based on alternative legal bases, which must be specified by the social network operators (e.g. consent within the meaning of Art. 6 Para. 1 lit. a GDPR).

Person Responsible and Exercising Your Rights
If you visit one of our social media pages (e.g. Facebook), we and the operator of the social media platform, are jointly responsible for the data processing operations triggered by your visit. In principle, you can exercise your rights (disclosure, rectification, erasure, restriction of processing, data portability, and the right to object) against us and against the operator of the rele-vant social media site (e.g. Facebook). Please note that despite our joint responsibility with the social media site operators, we cannot fully control the data processing activities of the social media sites. Our options are largely based on the company policy of the provider in question.

Duration of Storage
The data we collect directly through our social media presence will be erased from our systems once the purpose of their storage no longer exists, if you ask us to erase these data, if you withdraw your consent to the storage of the data, or the purpose for the data storage no longer exists. Stored cookies remain on your terminal device until deleted by you. Mandatory statutory provisions – especially retention periods – shall remain unaffected thereof. We have no control over the duration of storage of data retained by social network operators for their own purposes. For details, please refer to the social network operators directly (e.g. consult their pri-vacy statement, see below).

Specific Social Networks

  • Facebook
    We have a Facebook profile. The provider is Facebook Inc., 1 Hacker Way, Menlo Park, Cali-fornia 94025, USA. Facebook is certified under the EU-US Privacy Shield. We have concluded a joint processing agreement with Facebook (Controller Addendum). This agreement specifies which data processing operations we or Facebook are responsible for when you visit our Facebook fan page. You can view this agreement under the following link: https://www.facebook.com/legal/terms/page_controller_addendum.

    You can adjust your advertising settings independently in your user account. For this purpose, click on the following link and log in: https://www.facebook.com/settings?tab=ads. Details can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy/.
  • Twitter
    We use the Twitter short message service. The provider is the Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Twitter is certified under the EU-US Privacy Shield. You can adjust your Twitter privacy settings independently in your user account. For this purpose, click on the following link and log in: https://twitter.com/personalization. Details can be found in Twitter’s privacy policy: https://twitter.com/de/privacy.
  • Google+
    We have a Google+ profile. The provider is Google Inc., 1600 Amphitheatre Parkway Moun-tain View, CA 94043, USA. Google is certified under the EU-US Privacy Shield. You can adjust your advertising settings independently in your user account. For this purpose, click on the following link and log in: https://adssettings.google.com/authenticated. Details can be found in Google’s privacy policy: https://policies.google.com/privacy.
  • XING
    We have a XING profile. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. For details on how your personal data is handled, please refer to XING’s privacy policy: https://privacy.xing.com/de/datenschutzerklaerung
  • LinkedIn
    We have a LinkedIn profile. The provider is LinkedIn Ireland Unlimited Company, Wilton Pla-za, Wilton Place, Dublin 2, Ireland. LinkedIn is certified under the EU-US Privacy Shield. LinkedIn uses advertising cookies. If you would like to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

For details on how your personal data is handled, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.

5. Analytical Tools and Advertisements

Google Analytics
This website uses the functions of the Google Analytics web analysis service provider. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Google Analytics uses so-called “cookies”. They are text files which are saved on your computer and enable analysing your usage of the website. Information about your usage of the website created by this cookie are usually transmitted to and stored on a server operated by Google in the USA. Google Analytics cookies are stored on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in analysing the user behaviour for optimising both its web offers and its advertisements.

IP Anonymisation
We have enabled the IP anonymisation function on this website. Your IP address will therefore be truncated by Google within the member states of the European Union or in other states party to the Agreement on the European Economic Area before sending it to the USA. Only in excep-tional cases will the complete IP address be sent to a Google server in the USA and truncated there. Google will use this information on behalf of the website operator to evaluate your usage of the website, to compile reports about the website activities and to provide further services in connection with website and internet usage for the website operator. The IP address sent by your browser within the scope of Google Analytics is not associated with other data in Google.

Browser Plugin
You can prevent the storage of cookies by changing the corresponding settings of your browser software accordingly; however, we point out that if you do so, you might not be able to make full use of all the functions on this website. In addition, you can prevent the collection of the data generated by the cookie and related to your usage of the website (including your IP ad-dress) for Google and the processing of these data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

Objection to Data Collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this site: Disable Google Analytics. For more information on how to handle user data on Google Analytics, please refer to the Google privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Contract Data Processing
We have an agreement with Google on contract data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Demographics in Google Analytics
This website uses the “Demographics Feature” of Google Analytics. As a result, reports can be produced that contain statements on the age, gender and interests of the site visitors. This data comes from interest-based advertising from Google and third-party visitor data. This data cannot be assigned to a specific person. You can disable this feature at any time through the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as outlined in the section “Objection to Data Collection”.

Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter referred to as “reCAPTCHA”) on our websites. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA (“Google”).
reCAPTCHA is intended to verify whether the data on our websites (e.g. in a contact form) are entered by a human or by an automated programme. For this purpose, reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. The analysis au-tomatically starts as soon as the website visitor accesses the website. reCAPTCHA analyses and evaluates various information such as the IP address, how long the visitor remains on the web-site, and mouse movements made by the user. The data collected during the analysis is passed on to Google.

The reCAPTCHA analyses run in the background. Website visitors are not informed that an analysis is being conducted. The data processing is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legiti-mate interest in protecting its web offers from abusive automated spying and SPAM. For more information about Google reCAPTCHA and the Google privacy policy, please visit the following links: https://www.google.com/intl/de/policies/privacy/ and https://www.google.com/recaptcha/intro/android.html.

6. Plugins und Tools

YouTube
Our website uses the plugins of the YouTube site operated by Google. The provider of the site is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our sites equipped with a YouTube plugin, a connection to our YouTube servers will be established. The YouTube server will be informed about which of our sites you have visited. If you are logged in to your YouTube account, you enable YouTube to assign your surfing behaviour directly to your individual profile. You can prevent this by logging out of your YouTube account. The use of YouTube is in the interest of an attractive presentation of our online offers. This con-stitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.

For more information about how user data are handled, please refer to the YouTube privacy policy at: https://www.google.de/intl/de/policies/privacy.

Vimeo
Our website uses plugins of the Vimeo video portal. This service is provided by Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA. If you visit one of our sites equipped with a Vimeo plugin, a connection to the Vimeo servers will be established. The Vimeo server will be informed about which of our sites you have visited. In addition, Vimeo obtains your IP address. This also applies even if you are not logged into Vimeo when visiting our website or if you do not have a Vimeo account. The information collected by Vimeo is transmitted to a Vimeo server in the USA. If you are logged in to your Vimeo account, you enable Vimeo to assign your surfing behaviour directly to your individual profile. You can prevent this by logging out of your Vimeo account.

For more information about how user data are handled, please refer to the Vimeo privacy policy at: https://vimeo.com/privacy.

Google Web Fonts
For uniform representation of fonts, this page uses so-called Web Fonts provided by Google. When you open a page, your browser loads the required Web Fonts into your browser cache to display texts and fonts correctly. For this purpose, it is required that the browser you use makes a connection with the Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web Fonts is done in the interest of a uniform and attractive presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
If your browser does not support Web Fonts, a standard font is used by your computer.

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at: https://www.google.com/policies/privacy/.

Google Maps
This site uses the Google Maps map service through an API. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Your IP address must be stored for using the functions of Google Maps. This information is generally transferred to a Google server in the USA and stored there. The provider of this site does not have any control whatsoever of the transfer of this data. The use of Google Maps is done in the interest of an attractive presentation of our online offers and the easy retrieval of the places mentioned on our website. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.

For more information on the handling of user data, please refer to the Google privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.