1. The name and contact details of the data controller
Raumbild GmbH, Feringastraße 4, 85774 Unterföhring (hereinafter also referred to as "Subs", "we" or "us")
+49 157 8510 3567
2. Collection and storage of personal data as well as type and purpose of their use
a) When visiting the website and using the application
When you access our website and use the application, the browser and subs app used on your device automatically send information to our servers. This information is temporarily stored in a so-called log file. The following information is recorded without your intervention and stored until it is automatically deleted:
- name of the retrieved file
- date and time of retrieval
- transferred data volume
- message as to whether the call was successful
- description of the type of web browser used
- used operating system
- the previously visited page
- your IP address
- your activity in Subs (Likes, Views, Comments, Posts, News, Reports)
- your voluntary location, invitations and other metadata
The data mentioned will be processed by us for the following purposes:
- guarantee of the usability of our services
- ensure a smooth connection of the website,
- ensure comfortable use of our website and app,
- evaluation of system safety and stability as well as
- for other administrative purposes.
The legal basis for data processing is Art. 6 Para. 1 lit.f DSGVO. Our legitimate interest follows from the purposes listed above for the collection of data. Under no circumstances do we use the collected data for the purpose of drawing conclusions about your person.
b) When registering on the website or in the app
We collect the telephone number for the purpose of registration. In addition, further data may be provided voluntarily.
Your data provided to us for the purpose of registration will be processed by us exclusively for the provision of our services and may be used to contact you in connection with the contract.
The legal basis for this data processing is Art. 6 Para. 1 Letter b) DSGVO.
3. Transfer of data
Your personal data will not be transferred to third parties for purposes other than those listed below.
We will only pass on your personal data to third parties if:
you have given your express consent in accordance with Art. 6 Para. 1 lit.a DSGVO,
the disclosure according to Art. 6 para. 1 lit.f DSGVO is necessary and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data,
in the event that there is a legal obligation to pass on data pursuant to Art. 6 para. 1 lit.c DSGVO, and
this is legally permissible and necessary for the execution of contractual relationships with you pursuant to Art. 6 Para. 1 lit. b DSGVO.
5. use of third party software
a) Google Analytics
We use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google is certified under the Privacy Shield Agreement, which guarantees compliance with European privacy laws (see https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active ).
We base the use of the aforementioned analysis tool on Art. 6 para. 1 lit.f DSGVO: the processing is carried out for the analysis of user behaviour and is therefore necessary to safeguard our legitimate interests.
We use the analysis service Mixpanel, a service of Mixpanel Inc, a company incorporated under the laws of the State of Delaware of the United States of America. The Mixpanel service logs page views and page activity. To enable this, log data is transmitted to Mixpanel (and Mixpanel Inc.). More information about the use of your data can be found on the privacy page of the Mixpanel service (http://mixpanel.com/privacy) in the appropriate paragraphs. If you do not want Mixpanel (and Mixpanel Inc.) to receive log information about your activities on this Web site, you can stop recording logs of your activities using the "opt out cookie", which you can enable at http://mixpanel.com/optout/. Please note, however, that this cookie and thus the recording prohibition will be deleted as soon as you delete your cookies in the settings of your browser (Internet access program). Please note that as the operator of the website you are on, we have no influence on the use of your data.
What information does Wix.com collect?
Wix.com collects two types of information: personal information (which can be used to uniquely identify an individual) and non-personal information (which is not used to identify an individual). Wix.com collects such information about our users and visitors, as well as users of users and other individuals who provide it to us. Wix.com may also collect similar information - solely for and in the interest of our users - in connection with visitors and users of our users' websites or services ("users of users").
Why does Wix.com collect such data?
Wix.com collects and uses information to provide our services and make them better and safer, to contact our visitors, users and job applicants, and to comply with the legal requirements for Wix.com.
Where is the information stored?
Wix.com may store and process personal information in the United States, Europe, Israel or other jurisdictions - either itself or through our affiliates and service providers. The data storage providers Wix.com works with are contractually committed to protecting your privacy. Wix.com complies with the data protection principles of the EU-US and the Swiss-US Privacy Shield Agreement, among other things, in order to better protect the data of our users. Some jurisdictions require that we manage and store your citizens' information locally. Wix.com may also collect, process and store such data in other locations, including the United States.
User user data
Wix may collect and process information about our users' users. We do this exclusively in the name and on instruction of our users. Our users are solely responsible for the data of their users, including its legality, security and integrity. Wix has no direct relationship with the users of users.
Transfer of personal data to third parties
We may share the information of our visitors, users and their users of users with various third parties, including certain service providers, law enforcement agencies and application developers. The information may only be shared in accordance with this policy.
d) Amazon Web Services
For hosting the database contents, we use the Amazon Relational Database Service (RDS) of Amazon Web Services Inc., 410 Terry Avenue North, Seattle WA 98109, USA (hereinafter "AWS") in accordance with Art. 6 Para. 1. 1 lit. b) DS-GVO. All data collected within the scope of our offers are automatically encrypted and stored exclusively in a German computer center (Frankfurt/Main), which is certified according to ISO 27001, 27017 and 2018 as well as PCI DSS Level 1.
We use the Amazon SMS Service of AWS to send SMS, e.g. in the signup process in the app to send you the verification code. We use the Amazon Simple Email Service of AWS to send e-mails, e.g. after registration in the app or to send newsletters. For the purpose of e-mail dispatch, the e-mail addresses of the users are temporarily transmitted (during dispatch) to an AWS server within the EU. AWS and its US parent company Amazon.com Inc. are certified under the EU-US Privacy Shield, which confirms the adequacy of the data protection level according to Art. 45 DS-GVO.
The data transmitted to AWS is stored on the servers until we delete it.
You can find more information about Amazon Simple Email Service, AWS and data protection at https://aws.amazon.com/de/ses/ and in the data protection information.
6. storage duration
The data stored with us are deleted as soon as they revoke any consent or if the data are no longer required for their purpose and there are no legitimate interests or legal storage obligations to prevent the deletion. If the data are not deleted because they are required for other and legally permissible purposes, their processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to user data which must be stored for commercial or tax reasons. According to legal requirements, the data is stored for 6 years in accordance with § 257 para. 1 HGB (e.g. commercial letters, accounting records, etc.) and for 10 years in accordance with § 147 para. 1 AO (e.g. commercial and business letters, tax-relevant documents).
7. rights of affected parties
They are entitled to the following rights:
a. Right to information
You have the right to request confirmation from us as to whether personal data concerning you will be processed.
b. Correction/deletion/restriction of processing
You also have the right to require us to Incorrect personal data concerning you are corrected immediately (right to correction); personal data concerning you are deleted immediately (right to deletion) and the processing is restricted (right to restrict the processing).
c. Right to data transferability
You have the right to receive personal data concerning you which you have provided to us in a structured, common and machine-readable format and to forward this data to another responsible person.
d. Right of withdrawal
You have the right to revoke your consent at any time. The revocation of your consent does not affect the legality of the processing carried out on the basis of your consent until you revoke your consent.
e. Right of objection
If the processing of personal data concerning you is necessary for the performance of a task which is in the public interest (Art. 6 para. 1 letter e) DSGVO) or to safeguard our legitimate interests (Art. 6 para. 1 letter f) DSGVO), you have the right to object.
f. Right of appeal
If you are of the opinion that the processing of your personal data violates the DSGVO, you have the right to complain to a supervisory authority without prejudice to other legal remedies.
8 Amendments to the data protection declaration
We reserve the right to adapt this data protection declaration in the event of any change in the legal situation, the service or data processing. However, this only applies to declarations on data processing. If the user's consent is required or if elements of the data protection declaration contain provisions governing the contractual relationship with the user, the changes will only be made with the user's consent. Users can inform themselves about any changes regularly in this data protection declaration.