Processing of personal data
“Personal data”: any information regarding a physical person that identifies it or is deemed to identify it directly or indirectly. Personal data is therefore information that can be used to draw conclusions about an identified or identifiable natural person. In principle, all information about which a personal reference can be established also falls under the concept of personal data. For example, a person’s name, address, e-mail address, telephone number, personnel number, vehicle registration number plate, appearance or walk are all personal data. Furthermore, usage data also has a personal connection. Usage data means data that is required to use our website. This includes, for example, information about the start, end and scope of your use;
“Interested party”: the natural person to whom the personal data relate;
“Data Protection Officer” (DPO): is the entity that has the duty of valuing and organizing the protection of the Personal Data.
Who we are
prestatech (also representing the Data Protection Officer) is the trading name of Cara Services GmbH, company number 174193. prestatech’s registered office is located at Kurfürstendamm 11, 10719 Berlin, Deutschland.
Access to your data
The data provided by you is secured and it is handled by the DPO or a responsible person within the DPO department.
Collecting personal data
We collect data with respect to your identity, address, and other personal details related to you or to your business. We must be able to contact you in order to verify your identity or your business and collect additional information. Other details might include the source from which you were referred to the Website and other information used for marketing purposes.
prestatech will use the following data, but not only, on your identity:
- Data on your business (such as fiscal code, financial data, data related to the company or UBOs);
- Data related to your visits on prestatech.com (our “Website”) (such as IP address and browser).
prestatech gathers the following information with the aim of:
- Verifying your existence and the existence of your business;
- Offering you a better service and the assistance you might need;
- Develop and improve our internal processes;
- Making statistical and processing analysis;
- Marketing activities, with your consensus;
- Sharing data with third parties, with your consensus;
- Fulfil any obligation required by the law;
- Processes in sharing your personal data;
Changes of personal data
If you become aware that any of your personal data that you have shared with us including your profile information is incorrect, inaccurate or has changed, you are responsible to make respective changes or corrections on the Website and,if this is not possible, to communicate changes or corrections promptly to us in order for us to update your information.
All cookies can be blocked by setting the respective preferences in your browser.
By default, your browser will accept cookies, unless you change the respective settings.
For more details we suggest to follow the guide for your browser in order to be able to delete or change the settings in relation to cookies.
Cookies can be used for:
- Analysis and research.
We undertake best efforts to take all reasonable steps and organizational measures to protect your personal data aside in cases of “force majeur” whereby we can demonstrate that the DPO or the DPO team cannot be deemed responsible. Your data will be stored within the Microsoft Azure database for a period of 5 years as stated by the legal authorities. The Microsoft Azure database is based in the EU in compliance with the European Regulation on treatement of personal data.
Communication between you and prestatech
For educational, security and future troubleshooting purposes, we may record or monitor your communications with prestatech by phone, email or mail. You acknowledge that e-mail communications are not encrypted. In emails to prestatech, you do not have to include your security information (e.g. your login password).
Integration of third-party services and content: LinkedIn Slideshare and YouTube
We use, based on our legitimate interest in the analysis, optimization and operation of our website within the meaning of Art. 6 para. 1 lit GDPR, content and applications from third parties as Linkedin and Youtube on our website. The use of the offer presupposes that the named providers recognise the IP address of the users. Without the IP address, you cannot send the content to the browser of the respective user. Prestatech has no influence on whether the third-party providers store the IP addresses. For more information about this, please check the relevant third-party website:
Use of Google Analytics with anonymisation function
Our website uses features of the Google Analytics web analytics service. Provider is Google Ireland Limited (hereinafter referred to as “Google”), Gordon House, Barrow St, Dublin 4, D04 E5W5, Ireland. Google Analytics uses the cookies mentioned above. Information generated via cookies is usually transmitted to and stored on a Google USA server. By using this website, you agree to the processing of data about you by Google in the manner described above and for the mentioned purpose.
We use the “Activate IP anonymization” function on this website, to ensure anonymized collection of IP addresses (so called IP masking). Thus your IP address will be truncated by Google within the member states of the European Union or in other Contracting States to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google USA server and truncated there. Google will use this information on our behalf, for the purpose of evaluating your use of the website, for compiling reports on website activity, and for providing us other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics is not bought together with other Google data. Google may also pass this information on to third parties in so far as this is required by law or if third parties process the data on Google’s behalf.
Google Tag Manager
Google Tag Manager is a solution that allows marketers to manage web page tags through a single interface. The “Tag Manager” tool itself, which implements the tags, is a cookie-less domain and does not collect any personal data. The tool triggers other tags, which in turn may collect data under certain circumstances. The “Google Tag Manager” does not access this data. If deactivation occurs at domain or cookie level, it remains in use for all tracking tags, insofar as they are implemented with “Google Tag Manager”. For more information, see: https://policies.google.com/privacy.
Objecting to the collection of data
You can prevent data collection by Google Analytics by clicking on the following link. This sets an opt-out cookie that prevents the future collection of your data when visiting this website: Opt-out (disable Google Analytics). We also use Google Analytics to evaluate data from AdWords and the double-click cookie for statistical purposes. If you do not want this to be carried out, you can disable the function via the Ads Preferences Manager (http://www.google.com/settings/ads/onweb/?hl=de).
Our websites use so-called retargeting technologies from Google and LinkedIn. This technology makes it possible to address Internet users who have already been interested in our website with advertising on the websites of our partners. The insertion of these advertising materials on the pages of our partners is based on cookie technology and is completely anonymous. No personal data is stored, and no user profiles are combined with your personal data.
We use the online advertising program Google AdWords, which was developed by Google Inc. “(“Google”) is operated in the USA and in the context of “Conversion-Tracking” (statistical evaluation). Cookies can be used to do this. The cookie for conversion tracking is set when a user clicks on an ad placed by Google. These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages of our website when the cookie has not yet expired, we and Google can detect that the user clicked on the ad and proceeded to this website. Each Google AdWords advertiser has a different cookie. This means that cookies cannot be tracked via the website of an Adwords customer. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Prestatech learns the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, advertisers do not obtain any information that can be used to personally identify users. Users who do not wish to participate in tracking can easily disable the cookie of Google conversion tracking on their Internet browser and user settings. These users will not be included in the conversion tracking statistics. For more information, see http://www.google.com/intl/de/policies/privacy. The following Google AdWords features are used on this website:
Remarketing Interest Categories Similar target groups Other types of interest-based advertising We use these Google Adwords features to redirect visitors to this site to third-party websites or to appeal to Internet users with specific interest profiles based on their internet usage. We do not collect any personal information with our cookies, remarketing lists or other anonymous IDs.
We use the LinkedIn Insight Conversion Tool from LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA, which allows us to obtain information about the use of our website and to present advertising content tailored to your interests on other websites. A cookie with a validity of 120 days is set in your browser, which enables LinkedIn to recognize you when you visit a website. LinkedIn uses this information to create anonymous reports for us about ad activity and information about how you interact with our website. You can deactivate the LinkedIn Insight Conversion Tool and interest-based advertising by opting out at the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. If you are a LinkedIn member, click on “Reject on LinkedIn”. Other visitors click on “Reject”. Further information on data protection at LinkedIn can be found here: https://www.linkedin.com/legal/privacy-policy#choices-oblig.
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights with respect to prestatech:
The right to be informed
As a data subject, you have the right granted by the European Directive and Regulator to receive free information from prestatech about your stored personal data and a copy of this information at any time. Furthermore, the European Directive and Regulator has granted you, as the person concerned, access to the following information:
- the purposes of processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- the existence of a right to rectification or erasure of the personal data concerning you or of a restriction of the processing by the person responsible or of a right to object to such processing;
- the existence of the right to lodge a complaint with a supervisory authority;
- where the personal data is not collected from the data subject, any available information as to their source;
- the existence of automated decision-making, including profiling, in accordance with Article 22 Para.1 and 4, GDPR and – at least in these cases – meaningful information on the logic involved and the scope and intended effects of such processing for the data subject.
Furthermore, you have a right of access to information as to whether personal data has been transferred to a third country or to an international organisation. If this is the case, you have, in addition, the right to obtain information about the appropriate guarantees in connection with the transfer.
If you would like to make use of this right to information, you can contact us at the following address: firstname.lastname@example.org.
The right of rectification
You also have the right, granted by the European legislator, to request the immediate rectification of inaccurate personal data concerning you. You also have the right, taking into account the purposes of the processing, to request the completion of incomplete personal data, including by means of a supplementary declaration.
If you would like to make use of this right to rectification, you can contact us at the following address: email@example.com.
The right to limitation of processing
You have the right granted by the European legislator of directives and regulations to require prestatech to restrict processing if one of the following conditions is met:
- The accuracy of your personal information is contested by you for a period of time that allows us to verify the accuracy of your personal information.
- The processing is unlawful, you refuse to delete the personal data and instead demand a restriction on the use of the personal data.
- We no longer need the personal data for the purposes of processing, but you do need it to assert, exercise or defend legal claims.
- You have objected to the processing pursuant to Art. 21 Para. 1 GDPR and it is not yet clear whether prestatech’s legitimate reasons outweigh yours.
If one of the above conditions is fulfilled and you wish to request the restriction of personal data stored by prestatech, you can contact us at the following address: firstname.lastname@example.org. Our employee will arrange for processing to be restricted.
Right to erasure
You have the right granted by the European Directive and Regulator to require prestatech to delete your personal data immediately, provided that one of the following reasons applies and insofar as the processing is not necessary:
- The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
- You revoke your consent on which the processing pursuant to Art. 6 Para. 1 letter a GDPR or Art. 9 para. 2 letter a GDPR and there is no other legal basis for processing.
- You submit an objection to the processing according to Art. 21 Para. 1, GDPR, and there are no overriding legitimate grounds for processing, or you submit an objection according to Art. 21 Para. 2 GDPR objecting to the processing.
- The personal data has been unlawfully processed.
- The personal data must be erased for compliance with a legal obligation under Union or Member State law to which the responsible person is subject.
- The personal data concerning you has been collected in relation to services offered by the information society according to Art. 8 Para. 1 GDPR.
If one of the above-mentioned reasons applies and you wish to have your personal data stored at prestatech deleted, you can contact us at the following address: email@example.com. The employee will arrange for the deletion request to be complied with without delay.
If the personal data has been made public by us and our company is responsible pursuant to Art. 17 Para. 1 GDPR to delete personal data, we will take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other data processors who process the published personal data, that you have requested the deletion of all links to such personal data or of copies or replications of such personal data from those other data processors, where processing is not necessary. Our employees will do what is necessary in individual cases.
Right to data portability
You have the right granted by the European regulator to receive the personal data concerning you that you have provided to prestatech in a structured, common and machine-readable format. You also have the right to transfer this data to another data controller without obstruction by prestatech, provided that the processing is based on the consent provided for in Art. 6 para. 1 letter a GDPR or Art. 9 para. 2 letter a GDPR or on a contract in accordance with Art. 6 para. 1 letter b GDPR and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority conferred on the controller.
Furthermore, when exercising your right to data transferability pursuant to Art. 20 para. 1 GDPR, the right to require that the personal data is transmitted directly from prestatech to another responsible person, as far as technically feasible and provided that this does not affect the rights and freedoms of others.
To assert the right to data transferability, you can contact us at the following address: firstname.lastname@example.org.
Right of appeal
You have the right granted by the European legislator for reasons arising from your particular situation, to object at any time to the processing of personal data relating to you, which may be processed on the basis of Art. 6 para. 1 letters e or f GDPR. This also applies to profiling based on these provisions.
prestatech no longer processes personal data in the event of an objection, unless we can prove compelling reasons worthy of protection for the processing, which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If prestatech processes personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data for the purpose of such advertising. This also applies to any profiling connected with such direct advertising. If you object to prestatech processing for direct advertising purposes, prestatech will no longer process your personal data for these purposes.
Furthermore, for reasons arising from your particular situation, you have the right to object to the processing of personal data concerning you which prestatech uses for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 para. 1 GDPR, unless such processing is necessary to fulfil a task in the public interest.
To exercise your right of objection, you can contact us at the following address: email@example.com. In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.
Automated individual decision-making including profiling
You have the right granted by the European directive and regulatory body not to be subject to a decision based exclusively on automated processing – including profiling – which has legal effect against you or which significantly affects you in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between you and prestatech, or (2) is admissible under Union or Member State legislation to which prestatech is subject and contains appropriate measures to safeguard your rights and freedoms and your legitimate interests, or (3) takes place with your express consent.
If the decision (1) is necessary for the conclusion or performance of a contract between you and us or (2) is made with your express consent, prestatech will take reasonable measures to protect your rights and freedoms as well as your legitimate interests, including at least the right to obtain the intervention of a person by prestatech, to state their own position and to challenge the decision.
If you wish to assert rights relating to automated decisions, you can contact us at the following address: firstname.lastname@example.org.
Right to withdraw data protection consent
You have the right to revoke your consent to the processing of personal data at any time as granted by the European Directive and Regulator.
If you would like to exercise your right to revoke your consent, you can contact us at the following address: email@example.com.
The right of appeal to a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right of appeal to a supervisory authority, in particular in the Member State where you reside, work or where the infringement is suspected, if you believe that the processing of personal data that concerns you is in contravention of GDPR.
The supervisory authority responsible for prestatech is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstr. 219, 10969 Berlin Telephone: +49 30 13889-0 E-Mail: firstname.lastname@example.org
The supervisory authority with which the appeal has been lodged shall inform the appellant of the status and results of the appeal, including the possibility of a judicial remedy under Art. 78 GDPR.