have.tadduus

Privacy Policy

Preamble

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

Authoritative version: this English text is a translation provided for convenience. The German version of this privacy policy is the authoritative one. In the event of any discrepancy or differing interpretation between the two versions, the German wording prevails. Our processing of personal data is governed by German law and by the General Data Protection Regulation. You can find the German version at have-tadduus.com/de/datenschutz.

Some of the functions described below — such as the newsletter, vouchers, prize draws, the display of Instagram posts or the online deposit payment — are available only temporarily or only in the future. The processing described in those sections takes place solely if the respective function is actually offered on the website and used by you. If a function is not visible, no data is processed for it.

Version dated: 5 August 2026

Table of contents

Controller

York von Have
Smidtstraße 13
20535 Hamburg
Germany

Email address: info@have-tadduus.com

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Master data.
  • Contact data.
  • Special categories of personal data (health data, Art. 9 GDPR).
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Log data.

Categories of data subjects

  • Service recipients and clients.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Participants in prize draws and competitions.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Office and organisational procedures.
  • Organisational and administrative procedures.
  • Conducting prize draws and competitions.
  • Feedback.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.
  • Public relations.
  • Business processes and economic procedures.

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in an individual case, we will inform you of these in the privacy policy.

  • Consent (Art. 6(1)(a) GDPR) — the data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

Application of national data protection law: In the country in which the controller is established, national data protection provisions apply in addition to the General Data Protection Regulation (GDPR).

Security measures

In accordance with the legal requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability and separation relating to it. Furthermore, we have established procedures that ensure the exercise of data subject rights, the erasure of data and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.

Securing online connections using TLS/SSL encryption technology (HTTPS): to protect the data of users transmitted via our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), which protects the data against unauthorised access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS appearing in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and in particular conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.

International data transfers

Data processing in third countries: insofar as we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies (which is recognisable from the postal address of the respective provider or where the privacy policy expressly refers to the transfer of data to third countries), this always takes place in accordance with the legal requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.

This twofold safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes arise within the framework of the DPF, the standard contractual clauses take effect as a reliable fallback. In this way we ensure that your data remains appropriately protected at all times, even in the event of political or legal changes.

For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.

For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

General information on data storage and erasure

We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal bases for the processing exist. This concerns cases in which the original purpose of processing ceases to apply or the data is no longer required. Exceptions to this rule exist where statutory obligations or particular interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where several statements exist regarding the retention period or erasure deadlines for a given item of data, the longest period is always decisive. Data that is no longer retained for the originally intended purpose but on account of statutory requirements or other reasons is processed by us exclusively for the reasons that justify its retention.

Retention and erasure of data: the following general periods apply to retention and archiving under German law:

  • 10 years — retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the working instructions and other organisational documents required to understand them (Section 147(1) no. 1 in conjunction with (3) of the German Fiscal Code (AO), Section 14b(1) of the German VAT Act (UStG), Section 257(1) no. 1 in conjunction with (4) of the German Commercial Code (HGB)).
  • 8 years — accounting vouchers, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with (3) sentence 1 AO and Section 257(1) no. 4 in conjunction with (4) HGB).
  • 6 years — other business documents: received commercial or business letters, reproductions of dispatched commercial or business letters, other documents insofar as they are relevant for taxation, e.g. hourly wage slips, operating accounting sheets, costing documents, price labels, but also payroll accounting documents insofar as they are not already accounting vouchers, and cash register receipts (Section 147(1) nos. 2, 3, 5 in conjunction with (3) AO, Section 257(1) nos. 2 and 3 in conjunction with (4) HGB).
  • 3 years — data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related enquiries, based on previous business experience and customary industry practice, is stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).

Periods commencing at the end of the year: if a period does not expressly begin on a specific date and lasts at least one year, it starts automatically at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the triggering event is the point in time at which the termination or other ending of the legal relationship takes effect.

Automatic erasure and supervisory authority

In addition to the general periods set out above, we erase certain data automatically after fixed periods. We erase rejected appointment enquiries after 180 days and unanswered enquiries after 365 days, in each case including any reference images uploaded. Newsletter recipients who have unsubscribed are removed 365 days after unsubscribing, newsletter registrations that were never confirmed after 30 days, and entries in prize draws that have ended after 180 days. Customer records to which no enquiries, vouchers or prize draw entries remain attached and for which no newsletter consent exists are erased 365 days after they were last modified. Confirmed appointments and transactions involving payment are excluded from automatic erasure insofar as statutory retention obligations exist.

Competent supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information), Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany, https://datenschutz-hamburg.de

Rights of data subjects

Rights of data subjects under the GDPR: as a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: you have the right to withdraw consent given at any time.
  • Right of access: you have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data as well as further information and a copy of the data in accordance with the statutory requirements.
  • Right to rectification: in accordance with the statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: in accordance with the statutory requirements, you have the right to demand that data concerning you be erased without delay, or alternatively, in accordance with the statutory requirements, to request a restriction of the processing of the data.
  • Right to data portability: you have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the statutory requirements, or to request its transmission to another controller.
  • Right to lodge a complaint with a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Commercial services

We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively “contractual partners”), for the purposes of initiating, performing and settling contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request, as well as communication in connection with the respective contractual relationship.

The processing serves in particular to fulfil our primary and ancillary contractual obligations. These include the provision of the agreed services, any update and information obligations, the handling of warranty claims and other performance issues, the processing of withdrawals, terminations of continuing obligations, reversals, refunds and the handling of other contract-related declarations and enquiries. Both one-off contracts and ongoing contractual relationships are covered.

In particular, we process master data such as name, address and, where applicable, company; contact data such as email address and telephone number; contract and service data such as the subject matter of the contract, contract term, order or transaction number; usage and service data; and communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.

In addition, we process the data to safeguard our rights and to comply with legal obligations. This includes in particular commercial and tax law retention obligations, documentation obligations and, where applicable, obligations to provide evidence and render account. Processing also takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse and against threats to data, trade secrets and other legally protected interests. This may also include engaging external service providers such as IT and telecommunications providers, tax and legal advisers or other vicarious agents, insofar as this is necessary for the performance of the contract or to comply with legal obligations.

Personal data is disclosed to third parties only insofar as this is necessary for the performance of the contract, for taking pre-contractual measures, to safeguard legitimate interests or to comply with legal obligations. We provide separate information within this privacy policy about any processing beyond this, in particular for marketing purposes.

We inform contractual partners which data is required in an individual case at the time of collection, for example by marking it accordingly in online forms or in personal contact.

The data is erased as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations conflict with erasure. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order is erased by us after completion of the order and expiry of any retention periods, provided that no further statutory or contractual storage obligations exist.

The legal basis for the processing is Art. 6(1)(b) GDPR for taking pre-contractual measures and performing the respective contractual relationship, as well as Art. 6(1)(c) GDPR for compliance with legal obligations. Insofar as the processing is based on legitimate interests, it takes place on the basis of Art. 6(1)(f) GDPR, namely to safeguard our legitimate interests in proper and efficient business organisation, the internal administration and documentation of business transactions, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations.

  • Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: service recipients and clients; prospective customers. Business and contractual partners.
  • Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures. Business processes and economic procedures.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Tattooing services: we process our customers' data in order to agree on the motif, scope, body area and appointment, to carry out and invoice the tattoo, and to answer queries about aftercare. We tattoo adults only. You confirm to us yourself before the treatment that you are of full age; we do not ask to see an identity document and do not make a copy of one.
    The information required is marked as such in the context of the order, booking or comparable conclusion of contract and comprises the details needed for delivery and invoicing as well as contact information so that any queries can be raised.

Provision of the online offering and web hosting

We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved). Log data (e.g. log files concerning logins or the retrieval of data or access times).
  • Data subjects: users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices such as computers and servers). Security measures.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Provision of the online offering on rented storage space: to provide our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a “web host”).
  • Collection of access data and log files: access to our online offering is logged in the form of so-called “server log files”. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files can be used, on the one hand, for security purposes, e.g. to avoid server overload (in particular in the event of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure server utilisation and stability. Erasure of data: the logs are erased automatically by the hosting provider after a short period; under the current terms of our plan, at the latest one hour after they are created. No storage or evaluation beyond this takes place.

Service providers and infrastructure used

We use the following processors to operate this website and to handle enquiries. Data processing agreements are in place with all of the providers listed.

  • Vercel (hosting): provision of information technology infrastructure (storage space and computing capacity) on which this website is operated; service provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://vercel.com; privacy policy: https://vercel.com/legal/privacy-policy; data processing agreement: https://vercel.com/legal/dpa; basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses.
  • Neon (database): operation of the database in which the data collected in the context of appointment enquiries, customer records and the newsletter is stored. The server location is within the European Union (Frankfurt am Main). Neon processes the data exclusively on our instructions; the legal basis follows from the respective processing operation in the context of which the data is stored there; service provider: Neon Inc., 209 Orange St, Wilmington, DE 19801, USA; website: https://neon.tech; privacy policy: https://neon.tech/privacy-policy; data processing agreement: https://neon.tech/dpa; basis for third-country transfers: standard contractual clauses.
  • Cloudinary (image storage): storage and delivery of the images uploaded as references in the context of an appointment enquiry, as well as of the images shown on the website; service provider: Cloudinary Ltd., 111 W Evelyn Ave, Suite 206, Sunnyvale, CA 94086, USA; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR); website: https://cloudinary.com; privacy policy: https://cloudinary.com/privacy; data processing agreement: https://cloudinary.com/gdpr/dpa; basis for third-country transfers: standard contractual clauses.
  • Resend (email delivery): sending notifications about incoming appointment enquiries as well as newsletters and voucher emails; service provider: Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR), and consent in the case of newsletters (Art. 6(1)(a) GDPR); website: https://resend.com; privacy policy: https://resend.com/legal/privacy-policy; data processing agreement: https://resend.com/legal/dpa; basis for third-country transfers: standard contractual clauses.

Contact and enquiry management

When contacting us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the details of the enquiring persons are processed insofar as this is necessary to respond to the contact enquiries and any measures requested.

  • Types of data processed: contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
  • Data subjects: communication partners.
  • Purposes of processing and legitimate interests: communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online offering and user-friendliness.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).

Further information on processing operations, procedures and services:

  • Contact form: when you contact us via our contact form, by email or by other means of communication, we process the personal data transmitted to us in order to answer and handle the respective request. This generally includes details such as name, contact information and, where applicable, further information provided to us that is necessary for appropriate handling. We use this data exclusively for the stated purpose of contact and communication.

Appointment enquiry and customer records

  • Appointment enquiry with reference images: via the enquiry form we process your name, email address, optionally your telephone number, the preferred appointment time stated in your own words and the description of your tattoo idea. In addition, up to five reference images can be uploaded. We use this information exclusively to answer the enquiry and to arrange an appointment; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
  • Customer records: for each appointment enquiry we automatically create a customer record on the basis of the email address, or update an existing one. It serves to associate recurring enquiries and to trace the appointment history. In addition to name, email address and telephone number, we may store in the customer record the postal address (street, postcode, town, country), the date of birth, an internal note and keywords for classification. We enter these supplementary details ourselves in the administration area only; they are not collected via the enquiry form. The date of birth is optional. Where it is stored, we additionally use it to send a birthday voucher — this is sent exclusively to persons who have either consented to the newsletter or who have already had a confirmed appointment with us. You may object to this at any time without any particular form; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Information relating to health

A tattoo is an intervention in the skin. In this context, information may come up that constitutes health data and is specially protected under Art. 9 GDPR — for example skin conditions, allergies, scars, a pregnancy, the use of blood-thinning medication, or the wish for a cover-up over a surgical scar.

In the enquiry form: we do not ask for such information there. However, it may arise from your free-text description of your idea or from uploaded reference images if you provide it of your own accord. In that case we process it exclusively in order to answer your enquiry, on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give by submitting the form in the knowledge of this notice. You are not obliged to provide such information. If you would rather not submit it in writing, we will discuss it with you in person before the appointment instead.

Before the treatment: before tattooing, you complete a paper consent form at our premises. In it we ask about health circumstances that are relevant to tolerability and healing — in particular allergies and intolerances, skin conditions in the area of the planned tattoo, the use of blood-thinning medication, an existing pregnancy or breastfeeding, and relevant pre-existing conditions. We need this information in order to assess whether and how we can tattoo; without it we cannot responsibly carry out the treatment.

You give your consent to the processing of this information separately on the form itself — separated from the other declarations and revocable at any time. The legal basis is Art. 9(2)(a) GDPR. We keep the completed forms at our premises inaccessible to unauthorised persons and destroy them securely once the retention period has expired. We retain them for as long as claims arising from the treatment can be asserted — as a rule ten years from the end of the year of treatment.

You may withdraw your consent at any time with effect for the future. We will then erase the information concerned without delay, unless a statutory retention obligation prevents this. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.

We do not pass on health-related information to third parties. It is stored together with the appointment enquiry and erased along with it — see the section “Automatic erasure and supervisory authority”.

  • Types of data processed: special categories of personal data (Art. 9(1) GDPR), insofar as provided by you; content data (e.g. textual or pictorial messages and contributions).
  • Data subjects: service recipients and clients; prospective customers.
  • Purposes of processing: answering the enquiry; provision of contractual services; safety and tolerability of the treatment.
  • Retention and erasure: together with the associated appointment enquiry; see the section “Automatic erasure and supervisory authority”.
  • Legal bases: explicit consent (Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR).

Photographs of tattoos

On this website and in our social media profiles we show photographs of completed work. These photographs are taken at the studio after the treatment. They depict the tattooed area of the body and therefore allow conclusions to be drawn about the person shown, even without a face being visible; they are consequently personal data.

We publish such photographs exclusively with your prior consent, which you give separately and voluntarily on the consent form before the treatment. That consent is not a precondition for the tattoo — if you decline, nothing about the treatment changes. The legal basis is Art. 6(1)(a) GDPR and, where persons are identifiable, additionally Sections 22, 23 of the German Act on the Protection of Copyright in Works of Art (KUG).

You may withdraw your consent at any time without giving reasons, informally, for example by email to the address given above. We will then remove the photograph from our website and from our own social media profiles without delay. We have no influence over copies that third parties have previously made or shared — we point this out expressly, because an image once published on the internet cannot be fully retrieved.

The photographs are stored with and delivered by our image storage provider (see the section “Service providers and infrastructure used”) for as long as consent remains in place. We do not publish names or contact details alongside them.

  • Types of data processed: content data (photographs of the tattooed area of the body); where applicable, special categories of personal data insofar as health-related features are visible in the image (e.g. scars).
  • Data subjects: service recipients and clients.
  • Purposes of processing: presentation of our work; public relations.
  • Retention and erasure: until consent is withdrawn, after which removal without delay.
  • Legal bases: consent (Art. 6(1)(a) GDPR); Sections 22, 23 KUG; where health-related features are visible, additionally explicit consent (Art. 9(2)(a) GDPR).

Cookies

We do not set any cookies on the publicly accessible pages of this online offering. No reach measurement, web analytics or online marketing takes place; accordingly, there is no consent banner either.

The non-public administration area is an exception: when logging in, a technically necessary session cookie is set which maintains the login for a period of eight hours. This cookie is strictly necessary for the service expressly requested by the user and therefore does not require consent (Section 25(2) no. 2 of the German Digital Services Data Protection Act, TDDDG). It is set exclusively for persons who log in to the administration area, not for visitors to the website.

  • Types of data processed: meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
  • Data subjects: users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: security measures; provision of our online offering and user-friendliness.
  • Retention and erasure: the session cookie expires at the latest eight hours after login.
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Newsletter and electronic notifications

We send newsletters, emails and other electronic notifications (hereinafter “newsletters”) exclusively with the consent of the recipients or on the basis of a statutory permission. Where the contents of the newsletter are described in the context of registration, those contents are decisive for the users' consent. As a rule, providing your email address is sufficient to subscribe to our newsletter. However, in order to be able to offer you a personalised service, we may ask you to provide your name so that we can address you personally in the newsletter, or for further information if this is necessary for the purpose of the newsletter.

Double opt-in procedure: registration for our newsletter takes place using a so-called double opt-in procedure. This means that after registering you will receive an email asking you to confirm your registration. Only after this confirmation will we add you to the distribution list. This confirmation is necessary so that no one can register using someone else's email address. If you do not confirm, you will not receive any messages from us; we erase the unconfirmed registration automatically after 30 days.

Erasure and restriction of processing: we store the email addresses that have been removed for 365 days from the date of unsubscribing on the basis of our legitimate interests before erasing them, in order to be able to demonstrate consent previously given. The processing of this data is restricted to the purpose of a potential defence against claims. An individual request for erasure is possible at any time, provided that the previous existence of consent is confirmed at the same time. In the case of obligations to observe objections permanently, we reserve the right to store the email address solely for this purpose in a blocklist.

The registration procedure is logged on the basis of our legitimate interests for the purpose of demonstrating that it was carried out properly. Insofar as we commission a service provider to send emails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system.

Contents: information about us, our services, promotions and offers.

  • Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
  • Data subjects: communication partners.
  • Purposes of processing and legitimate interests: direct marketing (e.g. by email or post).
  • Legal bases: consent (Art. 6(1)(a) GDPR).
  • Opt-out: you can cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can use one of the contact options given above, preferably email.

Vouchers

We send discount vouchers by email. This takes place partly manually on specific occasions and partly automatically: if a date of birth is stored in the customer record, the system automatically creates and sends a voucher on the birthday. A corresponding mailing takes place at Christmas. Both are sent exclusively to persons who have consented to the newsletter or who have already had a confirmed appointment with us — not to persons who merely made an enquiry once. Vouchers may also arise as a prize from a prize draw.

For each voucher we store the voucher code, the discount value, the occasion, the recipient's address or the link to the customer record, and the times of creation, dispatch and redemption. We need this information in order to check validity, to exclude multiple redemption and to be able to answer queries.

You can object to receiving further voucher emails at any time without any particular form, for example by email to the address given above. We will then remove the stored date of birth or exclude you from further mailings.

  • Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: service recipients and clients; prospective customers. Business and contractual partners.
  • Purposes of processing and legitimate interests: direct marketing (e.g. by email or post); provision of contractual services and fulfilment of contractual obligations. Organisational and administrative procedures.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
  • Opt-out: you can object to receiving voucher emails at any time, without any particular form, using one of the contact options given above.

Prize draws and competitions

We process personal data of participants in prize draws and competitions only in compliance with the relevant data protection provisions, insofar as the processing is contractually necessary for the provision, conduct and settlement of the prize draw, the participants have consented to the processing, or the processing serves our legitimate interests (e.g. in the security of the prize draw or in protecting our interests against misuse through the possible recording of IP addresses when prize draw entries are submitted).

If participants' entries are published in the context of prize draws (e.g. as part of a vote or presentation of the entries or winners, or in reporting on the prize draw), we point out that participants' names may also be published in this connection. Participants may object to this at any time.

If the prize draw takes place within an online platform or a social network (e.g. Facebook or Instagram, hereinafter “online platform”), the terms of use and privacy provisions of the respective platforms additionally apply. In these cases we point out that we are responsible for the information provided by participants in the context of the prize draw and that enquiries regarding the prize draw are to be addressed to us.

Participants' data is erased as soon as the prize draw or competition has ended and the data is no longer required in order to inform the winners, or because queries regarding the prize draw are no longer to be expected. As a rule, participants' data is erased at the latest six months after the end of the prize draw. Winners' data may be retained for longer, e.g. in order to answer queries about the prizes or to fulfil the prize obligations; in this case the retention period depends on the type of prize and amounts, for example in the case of goods or services, to up to three years, e.g. in order to be able to handle warranty cases. Furthermore, participants' data may be stored for longer, e.g. in the form of reporting on the prize draw in online and offline media.

Insofar as data was also collected for other purposes in the context of the prize draw, its processing and the retention period are governed by the privacy notices relating to that use (e.g. in the case of a newsletter registration in the context of a prize draw).

  • Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation).
  • Data subjects: participants in prize draws and competitions.
  • Purposes of processing and legitimate interests: conducting prize draws and competitions.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Presences in social networks (social media)

We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.

We point out that user data may be processed outside the European Union in this context. This may give rise to risks for users, because it could, for example, make it more difficult to enforce users' rights.

Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of users' usage behaviour and the resulting interests. These profiles may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to users' interests. For this purpose, cookies are generally stored on users' computers in which usage behaviour and users' interests are stored. In addition, data may be stored in the usage profiles irrespective of the devices used by the users (in particular if they are members of the respective platforms and are logged in there).

For a detailed description of the respective forms of processing and the opt-out options, we refer to the privacy policies and information of the operators of the respective networks.

In the case of requests for access and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the latter have access to users' data in each case and can take appropriate measures and provide information directly. Should you nevertheless need assistance, you can contact us.

We do not embed any plugins, buttons or other interactive elements of social networks on this website. Clicking a link to our Instagram profile takes you to Instagram only after your own decision.

We do not currently display posts from our Instagram profile on this website. Accordingly, no data is transmitted to Meta when you visit this website. Should we offer such a display in future, we will obtain your consent beforehand and update this section accordingly.

  • Types of data processed: contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: communication; feedback (e.g. collecting feedback via an online form). Public relations.
  • Retention and erasure: erasure in accordance with the information in the section “General information on data storage and erasure”.
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram: social network, enables the sharing of photos and videos, commenting on and favouriting posts, sending messages, subscribing to profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/.

Amendment and updating

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and we ask you to verify the details before making contact.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, their statutory definitions apply. The following explanations are, by contrast, intended primarily to aid understanding.

  • Contact data: contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
  • Content data: content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates.
  • Contract data: contract data is specific information relating to the formalisation of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This data category is essential for managing and fulfilling contractual obligations and comprises both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the type of services or products agreed, price agreements, payment terms, termination rights, renewal options and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is decisive for clarifying rights and obligations, enforcing claims and resolving disputes.
  • Controller: the “controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Log data: log data is information about events or activities that have been logged in a system or network. This data typically contains information such as time stamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, for security monitoring or to produce performance reports.
  • Master data: master data comprises essential information necessary for the identification and administration of contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between persons and services, institutions or systems by enabling unambiguous assignment and communication.
  • Meta, communication and procedural data: meta, communication and procedural data are categories containing information about the manner in which data is processed, transmitted and managed. Metadata, also known as data about data, comprises information describing the context, origin and structure of other data. It may include details of file size, creation date, the author of a document and change histories. Communication data records the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, time stamps and transmission paths. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, records of transactions and activities, and audit logs used to track and review operations.
  • Personal data: “personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Processing: “processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collecting, evaluating, storing, transmitting or erasing.
  • Usage data: usage data refers to information that records how users interact with digital products, services or platforms. This data covers a broad range of information showing how users use applications, which functions they prefer, how long they spend on particular pages and which paths they take through an application. Usage data may also include the frequency of use, time stamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. In addition, usage data plays a decisive role in identifying trends, preferences and possible problem areas within digital offerings.

Created with the free privacy policy generator Datenschutz-Generator.de by Dr. Thomas Schwenke