In the following, we provide information about the collection of personal data when using
● our website dishbrain.com
● our profiles in social media.
Personal data is any data that can be related to a specific natural person, such as their name or IP address.
The controller within the meaning of Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is Dishbrain GmbH, Enzianstrasse 2, 82319 Starnberg, Germany, email: info@dishbrain.com. We are legally represented by Michael Caudera. Our data protection officer can be reached via heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, E-Mail: datenschutz@heydata.eu.
We detail the scope of data processing, processing purposes and legal bases below. In principle, the following come into consideration as the legal basis for data processing:
● Art. 6 para. 1 s. 1 lit. a GDPR serves as our legal basis for processing operations for which we obtain consent.
● Art. 6 para. 1 s. 1 lit. b GDPR is the legal basis insofar as the processing of personal data is necessary for the performance of a
contract, e.g. if a site visitor purchases a product from us or we perform a service for him. This legal basis also applies to
processing that is necessary for pre-contractual measures, such as in the case of inquiries about our products or services.
● Art. 6 para. 1 s. 1 lit. c GDPR applies if we fulfill a legal obligation by processing personal data, as may be the case, for example, in tax law.
● Art. 6 para. 1 s. 1 lit. f GDPR serves as the legal basis when we can rely on legitimate interests to process personal data, e.g. for cookies that are necessary for the technical operation of our
website.
Insofar as we transfer data to service providers or other third parties
outside the EEA, the security of the data during the transfer is
guaranteed by adequacy decisions of the EU Commission, insofar as
they exist (e.g. for Great Britain, Canada and Israel) (Art. 45 para. 3
GDPR). In the case of data transfer to service providers in the USA, the legal
basis for the data transfer is an adequacy decision of the EU
Commission if the service provider has also certified itself under the EU
US Data Privacy Framework.
In other cases (e.g. if no adequacy decision exists), the legal basis for
the data transfer are usually, i.e. unless we indicate otherwise, standard
contractual clauses. These are a set of rules adopted by the EU
Commission and are part of the contract with the respective third party.
According to Art. 46 para. 2 lit. b GDPR, they ensure the security of the
data transfer. Many of the providers have given contractual guarantees
that go beyond the standard contractual clauses to protect the data.
These include, for example, guarantees regarding the encryption of
data or regarding an obligation on the part of the third party to notify
data subjects if law enforcement agencies wish to access the respective
data.
Unless expressly stated in this privacy policy, the data stored by us will
be deleted as soon as they are no longer required for their intended
purpose and no legal obligations to retain data conflict with the
deletion. If the data are not deleted because they are required for other
and legally permissible purposes, their processing is restricted, i.e. the
data are blocked and not processed for other purposes. This applies,
for example, to data that must be retained for commercial or tax law
reasons.
Data subjects have the following rights against us with regard to their
personal data:
● Right of access,
● Right to correction or deletion,
● Right to limit processing,
● Right to object to the processing,
● Right to data transferability,
● Right to revoke a given consent at any time.
Data subjects also have the right to complain to a data protection
supervisory authority about the processing of their personal data.
Contact details of the data protection supervisory authorities are
available at
https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-
node.html.
Within the scope of the business or other relationship, customers,
prospective customers or third parties need to provide us with personal
data that is necessary for the establishment, execution and termination
of a business or other relationship or that we are legally obliged to
collect. Without this data, we will generally have to refuse to conclude
the contract or to provide a service or will no longer be able to perform
an existing contract or other relationship.
6 /
Mandatory data are marked as such.
As a matter of principle, we do not use a fully automated decision-
making process in accordance with article 22 GDPR to establish and
implement the business or other relationship. Should we use these
procedures in individual cases, we will inform of this separately if this is
required by law.
When contacting us, e.g. by e-mail or telephone, the data provided to
us (e.g. names and e-mail addresses) will be stored by us in order to
answer questions. The legal basis for the processing is our legitimate
interest (Art. 6 para. 1 s. 1 lit. f GDPR) to answer inquiries directed to us.
We delete the data accruing in this context after the storage is no
longer necessary or restrict the processing if there are legal retention
obligations.
Occasionally, we offer competitions via our website or in other ways.
We process the data requested in these competitions in order to
determine and notify the winners. Afterwards, we delete the data. It
may also be that we only offer competitions for existing customers. In
7 /
this case, we only process the name to determine the winners and the
contact data to notify the winners. It is our legitimate interest to offer
competitions to attract customers or to interact with our existing
customers. The legal basis for data processing is Art. 6 para. 1 s. 1 lit. f
GDPR.
From time to time, we conduct customer surveys to get to know our
customers and their wishes better. In doing so, we collect the data
requested in each case. It is our legitimate interest to get to know our
customers and their wishes better, so that the legal basis for the
associated data processing is Art. 6 para. 1 s. 1 lit f GDPR. We delete the
data when the results of the surveys have been evaluated.
We reserve the right to inform customers who have already used
services from us or purchased goods from time to time by e-mail or
other means about our offers, if they have not objected to this. The
legal basis for this data processing is Art. 6 para. 1 s. 1 lit. f GDPR. Our
legitimate interest is to conduct direct advertising (recital 47 GDPR).
Customers can object to the use of their e-mail address for advertising
purposes at any time without incurring additional costs, for example via
the link at the end of each e-mail or by sending an e-mail to our above-
mentioned e-mail address.
8 /
Interested parties have the option to subscribe to a free newsletter. We
process the data provided during registration exclusively for sending
the newsletter. Subscription takes place by selecting the corresponding
field on our website, by ticking the corresponding field in a paper
document or by another clear action, whereby interested parties
declare their consent to the processing of their data, so that the legal
basis is Art. 6 para. p. 1 lit. a GDPR. Consent can be revoked at any time,
e.g. by clicking the corresponding link in the newsletter or notifying our
e-mail address given above. The processing of the data until revocation
remains lawful even in the event of revocation.
Based on the consent of the recipients (Art. 6 para. 1 s. 1 lit. a GDPR),
we also measure the opening and click-through rate of our newsletters
to understand what is relevant for our audience.
We send newsletters with the tool Brevo of the provider Sendinblue
GmbH, Köpenicker Str. 126, 10179 Berlin (privacy policy:
https://www.sendinblue.com/legal/privacypolicy/). The provider
processes content, usage, meta/communication data and contact data
in the process in the EU.
Our website stores information in the terminal equipment of website
visitors (e.g. cookies) or accesses information that is already stored in
the terminal equipment (e.g. IP addresses). What information this is in
detail can be found in the following sections.
This storage and access is based on the following provisions:
● Insofar as this storage or access is absolutely necessary for us to
provide the service of our website expressly requested by website
visitors (e.g., to carry out a chatbot used by the website visitor or
to ensure the IT security of our website), it is carried out on the
basis of Section 25 para. 2 no. 2 of the German
Telecommunications Telemedia Data Protection
(Telekommunikation-Telemedien-Datenschutz-Gesetz, "TTDSG").
● Otherwise, this storage or access takes place on the basis of the
website visitor's consent (Section 25 para. 1 TTDSG).
The subsequent data processing is carried out in accordance with the
following sections and on the basis of the provisions of the GDPR.
During the informative use of the website, i.e. when site visitors do not
separately transmit information to us, we collect the personal data that
the browser transmits to our server in order to ensure the stability and
security of our website. This is our legitimate interest, so that the legal
basis is Art. 6 para. 1 s. 1 lit. f GDPR.
These data are:
10 /
● IP address
● Date and time of the request
● Time zone difference to Greenwich Mean Time (GMT)
● Content of the request (specific page)
● Access status/HTTP status code
● Amount of data transferred in each case
● Website from which the request comes
● Browser
● Operating system and its interface
● Language and version of the browser software.
This data is also stored in log files. They are deleted when their storage
is no longer necessary, at the latest after 14 days.
Our website is hosted by United Domains. The provider is united-
domains AG, Gautinger Straße 10, 82319 Starnberg. In doing so, the
provider processes the personal data transmitted via the website, e.g.
content, usage, meta/communication data or contact data, in the EU.
Further information can be found in the provider's privacy policy at
https://www.united-domains.de/unternehmen/datenschutz/.
It is our legitimate interest to provide a website, so the legal basis of the
described data processing is Art. 6 para. 1 s. 1 lit. f GDPR.
When contacting us via the contact form on our website, we store the
data requested there and the content of the message.
The legal basis for the processing is our legitimate interest in answering
inquiries directed to us. The legal basis for the processing is therefore
Art. 6 para. 1 s. 1 lit. f GDPR.
We delete the data accruing in this context after the storage is no
longer necessary or restrict the processing if there are legal retention
obligations.
Site visitors can leave reviews on our website for our goods, services or
generally about our company. For this purpose, we process meta data
or communication data in addition to the data entered. We have a
legitimate interest in receiving feedback from site visitors about our
offerings. Therefore, the legal basis for data processing is Art. 6 para. 1
s. 1 lit. f GDPR. Insofar as we use a third-party tool for the agreement,
the information on this can be found under "Third parties".
Site visitors can open a customer account on our website. We process
the data requested in this context based on the consent of the site
visitor. Legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR.
12 /
The consent may be revoked at any time by contacting us, for example,
using the contact details provided in our privacy policy. The revocation
does not affect the lawfulness of the processing until the revocation. If
the consent is revoked we will delete the data insofar as we are not
obliged or have a right to retain it further.
Beyond the data entered during registration, we process IP Adresse,
Endgerät, Browser, Auflösung .
Users can log in to our website using one or more single sign-on
methods. In doing so, they use the login data already created for a
provider. The prerequisite is that the user is already registered with the
respective provider. When a user logs in using a single sign-on
procedure, we receive information from the provider that the user is
logged in to the provider and the provider receives information that the
user is using the single sign-on procedure on our website. Depending
on the user's settings in his account on the provider's site, additional
information may be provided to us by the provider. The legal basis for
this processing is Art. 6 para. 1 sentence 1 lit. f GDPR. We have a
legitimate interest in providing users with a simple log-in option. At the
same time, the interests of the users are safeguarded, as use is only
voluntary.
Providers of the offered method(s) are:
We offer services via our website. In doing so, we process the following data as part of the ordering process:
● Name,
● Address,
● Telephone number,
● E-mail address
The processing of the data is carried out for the performance of the contract concluded with the respective site visitor (Art. 6 para. 1 s. 1 lit. b GDPR).
For the processing of payments, we use payment processors who are
themselves data controllers within the meaning of Art. 4 No. 7 GDPR.
Insofar as they receive data and payment data entered by us in the
ordering process, we thereby fulfill the contract concluded with our
customers (Art. 6 para. 1 s. 1 lit. b GDPR).
These payment processors are:
● PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxemburg
Our website sets cookies. Cookies are small text files that are stored in
the web browser on the end device of a site visitor. Cookies help to
make the offer more user-friendly, effective and secure. Insofar as
these cookies are necessary for the operation of our website or its
functions (hereinafter "Technically Necessary Cookies"), the legal basis
for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We
have a legitimate interest in providing customers and other site visitors
with a functional website.
Specifically, we set technically necessary cookies for the following
purpose or purposes:
● Cookies that adopt language settings,
● Cookies that remember search terms,
● Cookies that save log-in data,
● Cookies that payment providers set to process payments and do
not analyze user behavior and
● Flash cookies that are set to play media content
We use LinkedIn Ads for advertisement. The provider is LinkedIn
Ireland Unlimited Company, Wilton Place, Dublin 2, Irland. The provider
15 /
processes usage data (e.g. web pages visited, interest in content, access
times) and meta/communication data (e.g. device information, IP
addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
We delete the data when the purpose for which it was collected no
longer applies. Further information is available in the provider's privacy
policy at https://www.linkedin.com/legal/privacy-policy?.
We use Google Webfonts for fonts on the website. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
However, the processing only takes place on our servers. The provider
processes meta/communication data (e.g. device information, IP
addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR. We
have a legitimate interest in using a font that is easy to use and
inexpensive on our website.
Further information is available in the provider's privacy policy at
https://policies.google.com/privacy?hl=en-US.
We use Surfer SEO for SEO optimization. The provider is Surfer Sp. z
o.o., Plac Solny 14/3, 50-062 Wrocław, Poland. The provider processes
usage data (e.g. web pages visited, interest in content, access times)
and meta/communication data (e.g. device information, IP addresses) in
the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at
https://surferseo.com/privacy-policy/.
We use WP rocket for the website performance. The provider is SAS WP
MEDIA, 4 rue de la République, 69001 LYON, France. The provider
processes meta/communication data (e.g. device information, IP
addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR. We
have a legitimate interest in reducing the loading time on our website.
17 /
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at https://wp-
rocket.me/de/impressum/.
We use CookieYes to manage consents. The provider is CookieYes
Limited, 3 Warren Yard Warren Park, Wolverton Mill, Milton Keynes,
MK12 5NW, United Kingdom. The provider processes
meta/communication data (e.g. device information, IP addresses) in
Great Britain.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. c DSGVO. The
processing is necessary for the fulfillment of a legal obligation to which
we are subject.
The legal basis for the transfer to a country outside the EEA are
adequacy decision. The security of the data transferred to the third
country (i.e. a country outside the EEA) is guaranteed because the EU
Commission has decided as part of an adequacy decision in accordance
with Art. 45 para. 3 GDPR that the third country ensures an adequate
level of protection.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at
https://www.cookieyes.com/privacy-policy/.
We use Google Webfonts for fonts on the website. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The provider processes meta/communication data (e.g. device
information, IP addresses) in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The legal basis for the transfer to a country outside the EEA are
consents.
Further information is available in the provider's privacy policy at
https://policies.google.com/privacy?hl=en-US.
We use Google Analytics for analytics. The provider is Google Ireland
Limited, Gordon House, Barrow Street, Dublin 4, Dublin, Ireland. The
provider processes usage data (e.g. web pages visited, interest in
content, access times) and meta/communication data (e.g. device
information, IP addresses) in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
19 /
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The legal basis for the transfer to a country outside the EEA are
adequacy decision. The security of the data transferred to the third
country (i.e. a country outside the EEA) is guaranteed because the EU
Commission has decided as part of an adequacy decision in accordance
with Art. 45 para. 3 GDPR that the third country ensures an adequate
level of protection.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at
https://policies.google.com/privacy?hl=en-US.
We use Simple History to monitor applications and as remote
monitoring management. The provider is Aut O’Mattic A8C Ireland Ltd.,
25 Herbert Pl, Dublin, D02 AY86, Ireland. The provider processes usage
data (e.g. web pages visited, interest in content, access times) and
meta/communication data (e.g. device information, IP addresses) in the
USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR. We
have a legitimate interest in adequately monitoring the functionality of
our applications.
20 /
The legal basis for the transfer to a country outside the EEA are
standard contractual clauses. The security of the data transferred to
the third country (i.e. a country outside the EEA) is guaranteed by
standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by
the EU Commission in accordance with the examination procedure
under Art. 93 para. 2 of the GDPR, which we have agreed to with the
provider.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at
https://automattic.com/de/privacy/.
We use YouTube Videos for videos on the website. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The provider processes usage data (e.g. web pages visited, interest in
content, access times) and meta/communication data (e.g. device
information, IP addresses) in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The legal basis for the transfer to a country outside the EEA are
consents.
21 /
Further information is available in the provider's privacy policy at
https://policies.google.com/privacy.
We use Rank Math for SEO optimization. The provider is Rank Math
Ventures LLP, EC-320, G-8, Area Rajouri Garden, Maya Enclave, Hari
Nagar, New Delhi, IN – 110064, India. The provider processes usage
data (e.g. web pages visited, interest in content, access times) and
meta/communication data (e.g. device information, IP addresses) in the
USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The legal basis for the transfer to a country outside the EEA are
standard contractual clauses. The security of the data transferred to
the third country (i.e. a country outside the EEA) is guaranteed by
standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by
the EU Commission in accordance with the examination procedure
under Art. 93 para. 2 of the GDPR, which we have agreed to with the
provider.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
22 /
information is available in the provider's privacy policy at
https://rankmath.com/de/privacy-policy/.
We use Jetpack for application security. The provider is Aut O’Mattic
A8C Ireland Ltd., 25 Herbert Pl, Dublin, D02 AY86, Ireland. The provider
processes usage data (e.g. web pages visited, interest in content, access
times) and meta/communication data (e.g. device information, IP
addresses) in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR. We
have a legitimate interest in keeping our website secure and protected
from attacks.
The legal basis for the transfer to a country outside the EEA are
standard contractual clauses. The security of the data transferred to
the third country (i.e. a country outside the EEA) is guaranteed by
standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by
the EU Commission in accordance with the examination procedure
under Art. 93 para. 2 of the GDPR, which we have agreed to with the
provider.
The data will be deleted when the purpose for which it was collected no
longer applies and there is no obligation to retain it. Further
information is available in the provider's privacy policy at
https://automattic.com/privacy/.
We use Google reCAPTCHA to manage authentifications. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin,
Ireland. The provider processes usage data (e.g. web pages visited,
interest in content, access times) and meta/communication data (e.g.
device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR. The
processing is based on consent. Data subjects may revoke their consent
at any time by contacting us, for example, using the contact details
provided in our privacy policy. The revocation does not affect the
lawfulness of the processing until the revocation.
The legal basis for the transfer to a country outside the EEA are
adequacy decision. The security of the data transferred to the third
country (i.e. a country outside the EEA) is guaranteed because the EU
Commission has decided as part of an adequacy decision in accordance
with Art. 45 para. 3 GDPR that the third country ensures an adequate
level of protection.
Further information is available in the provider's privacy policy at
https://policies.google.com/privacy?hl=en-US.
We are represented in social media networks in order to present our
organization and our services there. The operators of these networks
24 /
regularly process their users' data for advertising purposes. Among
other things, they create user profiles from their online behavior, which
are used, for example, to show advertising on the pages of the
networks and elsewhere on the Internet that corresponds to the
interests of the users. To this end, the operators of the networks store
information on user behavior in cookies on the users' computers.
Furthermore, it cannot be ruled out that the operators merge this
information with other data. Users can obtain further information and
instructions on how to object to processing by the site operators in the
data protection declarations of the respective operators listed below. It
is also possible that the operators or their servers are located in non-EU
countries, so that they process data there. This may result in risks for
users, e.g. because it is more difficult to enforce their rights or because
government agencies access the data.
If users of the networks contact us via our profiles, we process the data
provided to us in order to respond to the inquiries. This is our
legitimate interest, so that the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.
We maintain a profile on Instagram. The operator is Meta Platforms
Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2,
Ireland. The privacy policy is available here:
https://help.instagram.com/519522125107875.
We reserve the right to change this privacy policy with effect for the
future. A current version is always available here.
If you have any questions or comments regarding this privacy policy,
please feel free to contact us using the contact information provided
above.