Privacy policy
1 Information about the collection of personal data
(1) In the following, we inform you about the collection of personal data when using our website. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior.
(2) The responsible party pursuant to Article 4 (7) of the EU General Data Protection Regulation (DS-GVO) is Hermann Schmalzried, Kirchstr. 61/3, 71404 Korb, Germany, info@weingutschmalzried.de (see our imprint). You can reach our data protection officer at info@weingutschmalzried.de or our postal address with the addition “c/o to the data protection officer”.
(3) When you contact us by e-mail or via a contact form, the data you provide (your e-mail address, name and telephone number, if applicable) will be stored by us in order to answer your questions. We delete the data accruing in this context after the storage is no longer necessary or restrict the processing if there are legal retention obligations.
(4) If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. In doing so, we will also state the defined criteria for the storage period.
2 Your rights
(1) You have the following rights vis-à-vis us regarding the personal data concerning you:
– Right to information,
– Right to rectification or deletion,
– Right to restriction of processing,
– Right to object to processing,
– right to data portability.
(2) You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us.
3 Collection of personal data when visiting our website
(1) In the case of mere informational use of the website, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 para. 1 p. 1 lit. f DS-GVO):
– IP address
– Date and time of the request
– Time zone difference to Greenwich Mean Time (GMT)
– Content of the request (specific page)
– Access status/HTTP status code
– Amount of data transferred in each case
– Website from which the request comes
– browser
– Operating system and its interface
– Language and version of the browser software.
(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive associated with the browser you are using and through which the entity that sets the cookie (in this case by us) receives certain information. Cookies cannot execute programs or transfer viruses to your computer. They serve to make the Internet offer as a whole more user-friendly and effective.
(3) Use of cookies:
- a) This website uses the following types of cookies, the scope and functionality of which are explained below:
– Transient cookies (for this purpose b)
– Persistent cookies (c).
b) Transient cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called session ID, with which various requests of your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
c) Persistent cookies are deleted automatically after a specified period of time, which may differ depending on the cookie. You can delete the cookies in the security settings of your browser at any time.
d) You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all functions of this website.
e) [We use cookies to identify you for subsequent visits if you have an account with us. Otherwise, you would have to log in again for each visit].
f) [The Flash cookies used are not collected by your browser, but by your Flash plug-in. Furthermore, we use HTML5 storage objects that are stored on your terminal device. These objects store the required data independently of the browser you are using and have no automatic expiration date. If you do not want Flash cookies to be processed, you must install an appropriate add-on, such as “Better Privacy” for Mozilla Firefox (https://addons.mozilla.org/de/firefox/addon/betterprivacy/) or the Adobe Flash Killer Cookie for Google Chrome. You can prevent the use of HTML5 storage objects by using private mode in your browser. In addition, we recommend that you manually delete your cookies and browser history on a regular basis].[/vc_column_text][vc_empty_space height=”40px”][vc_column_text]
Special forms of website use
1 Use of our webshop
(1) If you wish to place an order in our webshop, it is necessary for the conclusion of the contract that you provide your personal data, which we require for the processing of your order. Mandatory data necessary for the processing of contracts are marked separately, other data are voluntary. We process the data you provide to process your order. For this purpose, we may pass on your payment data to our house bank. The legal basis for this is Art. 6 para. 1 p. 1 lit. b DS-GVO.
[Optional: You can voluntarily create a customer account, through which we can store your data for future purchases. When creating an account under “My Account”, the data you provide will be stored revocably. You can always delete all further data, including your user account, in the customer area].
We may also process the data you provide to inform you about other interesting products from our portfolio or to send you e-mails with technical information.
(2) We are obliged by commercial and tax law to store your address, payment and order data for a period of ten years. However, we will restrict processing after [two years], i.e. your data will only be used to comply with legal obligations.
(3) To prevent unauthorized access by third parties to your personal data, in particular financial data, the ordering process is encrypted using TLS technology.
2 Use of our portal
(1) If you wish to use our portal, you must register by entering your e-mail address, a password of your choice and your user name. There is no obligation to use a clear name; pseudonymous use is possible. We use the so-called double-opt-in procedure for registration, i.e. your registration is only completed when you have first confirmed your registration via a confirmation e-mail sent to you for this purpose by clicking on the link contained therein. If your confirmation is not received within [24 hours], your registration will be automatically deleted from our database. The provision of the aforementioned data is mandatory, all other information you can provide voluntarily by using our portal.
(2) If you use our portal, we store your data required for the fulfillment of the contract, including information on the method of payment, until you finally delete your access. Furthermore, we store the voluntary data you provide for the duration of your use of the portal, unless you delete it beforehand. You can manage and change all details in the protected customer area. The legal basis is Art. 6 para. 1 p. 1 lit. f DS-GVO.
(3) If you use the portal, your data may become accessible to other participants of the portal in accordance with the contractual performance. Non-registered members will not receive any information about you. For all registered members, your [username and photo] are visible, regardless of whether you have released them. In contrast, your entire profile with the data you have shared is visible to all members who have confirmed you as a personal contact. If you make content available to your personal contacts that you do not send by means of a private message, this content is visible to third parties, provided that your personal contact has given the release. If you post contributions in public groups, these are visible to all registered members of the portal.
(4) To prevent unauthorized access by third parties to your personal data, especially financial data, the connection is encrypted using TLS technology.
3 Data securityt
Within the website visit, we use the widespread SSL procedure (Secure Socket Layer) in connection with the highest encryption level supported by your browser. As a rule, this is a 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is encrypted by the closed key or lock symbol in the lower status bar of your browser. We also use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.[/vc_column_text][vc_empty_space height=”40px”][vc_column_text]4 Integration of YouTube videos
(1) We have integrated YouTube videos into our online offer, which are stored on http://www.YouTube.com and can be played directly from our website. [These are all integrated in “extended data protection mode”, i.e. no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in paragraph 2 be transmitted. We have no influence on this data transmission].
(2) By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned under § 3 of this declaration are transmitted. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not want the assignment with your profile at YouTube, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right.
(3) For more information on the purpose and scope of data collection and its processing by YouTube, please refer to the privacy policy. There you will also find further information on your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
5 Integration of Google Maps
(1) On this website we use the offer of Google Maps. This allows us to show you interactive maps directly on the website and enables you to use the map function comfortably.
(2) By visiting the website, Google receives the information that you have called up the corresponding sub-page of our website. In addition, the data mentioned under § 3 of this declaration are transmitted. This occurs regardless of whether Google provides a user account through which you are logged in or whether there is no user account. If you are logged in to Google, your data will be directly assigned to your account. If you do not want the assignment with your profile at Google, you must log out before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.
(3) For more information on the purpose and scope of data collection and its processing by the plug-in provider, please refer to the provider’s privacy policy. There you will also find further information on your rights in this regard and setting options for protecting your privacy: http://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.