Privacy Policy
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data includes all data with which you can personally identify yourself. Detailed information on the subject of data protection can be found in our Privacy Policy below this text.
Data collection on our website
Who is responsible for data collection on this website?
Data is processed on this website by the website operators. You can find out their contact data under the Legal Notice on this website.
How do we collect your data?
On the one hand, your data is collected by the fact that you provide it to us. This might be, for example, data that you enter in a contact form.
Other data is automatically collected by our IT systems when you visit the website. In particular, this is technical data (such as Internet browser, operating system or time when you call up a page). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website. Other data can be used to analyse your user behaviour.
Which rights do you have regarding your data?
You are entitled at all times and without charge to information about your stored personal data, its origin, recipients and purpose. You also have the right to demand correction, blocking or deletion of this data. You can contact us at any time at the address in the Legal Notice if you have any questions in this regard or other queries on data protection. Furthermore, you have the right of appeal to the responsible supervisory authority.
You also have the right to demand that processing of your personal data be restricted under certain circumstances. Please see the Privacy Policy under “Right to restriction of processing” for details.
2. Hosting
External hosting
This website is hosted by an external provider (hoster). The personal data collected on this website is stored on the hoster’s servers. This can be, in particular, IP addresses, contact requests, meta and communication data, contract data, contact data, names, website accesses and other data that is generated via a website.
We use the hoster for the purpose of fulfilling the contract to our potential and existing customers (Art. 6 Paragraph 1 Letter b of the GDPR) and in the interest of a secure, fast and efficient provision of our online service through a professional provider (Art. 6 Paragraph 1 Letter f of the GDPR).
Our hoster will only process your data insofar as this is necessary to perform its service obligations and to follow our instructions in relation to this data.
We use the following hoster:
Novatrend Services GmbH
Bahnhofstrasse 18
CH-6340 Baar, Switzerland
Concluding a contract for order processing
To ensure processing compliant with data protection, we have concluded a contract for order processing with our hoster.
3. General notes and mandatory information
Data protection
The operators of these sites take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this Privacy Policy.
When you use this website, various personal data is collected. Personal data is data with which you can personally identify yourself. This Privacy Policy explains which data we collect and what we use it for. It also explains how and for what purpose this takes place.
We would like to point out that transmitting data over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Note on the responsible entity
Smilestones AG
René Rüedi
Industrieplatz 3
CH-8212 Neuhausen am Rheinfall, Switzerland
info@smilestones.ch
The responsible entity is the natural or legal person who decides alone or together with others on the purpose and means of processing of personal data (such as names, email addresses, etc.).
Revoking your consent for data processing
Many data processing operations are only possible with your explicit consent. You can revoke any consent you have issued at any time. An informal communication by email is sufficient for this purpose. The revocation shall not affect the lawfulness of any data processing performed prior to the revocation.
Right to object to the collection of data in special cases as well as against direct advertising (Art. 21 of the GDPR)
If data processing is carried out based on Art. 6 Paragraph 1 Letters e or f of the GDPR, you have the right at any time, for reasons resulting from your particular situation, to file an objection against the processing of your personal data; this also applies for profiling based on these provisions. Please refer to this Privacy Policy for the respective legal foundation on which processing is based. If you file an objection, we will no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims (objection according to Art. 21, Paragraph 1 of the GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning yourself for the purposes of such marketing; this includes profiling to the extent that it is related to such direct marketing. If you object, your personal data will then no longer be used for the purposes of direct marketing (objection according to Art. 21 Paragraph 2 of the GDPR).
Right of appeal to the responsible supervisory authority
In the event of any violation of the GDPR, the data subjects have a right of appeal to a supervisory authority, in particular in the member state of their habitual residence, place of work or the place of the alleged violation. The right of appeal exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have issued to yourself or to a third party data which we process automatically based on your consent or in performance of a contract, in a conventional, machine-readable format. If you request the direct transfer of the data to another responsible party, this will only be carried out insofar as it is technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as purchase orders or enquiries which you send us as a site operator, this page uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and from the lock symbol in your address bar.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Information, blocking, deletion and correction
Within the framework of the applicable legal provisions, you are entitled at all times and without charge to information about your stored personal data, its origin and recipients, the purpose of its processing, and if necessary the right to correct, block or delete this data. You can contact us at any time with questions to this end or any queries regarding personal data via the address in the legal notice.
Right to restriction of processing
You have the right to demand that processing of your personal data be restricted. You can contact us at any time in this regard at the address given in the Legal Notice. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by us, we usually need some time to check this. For the duration of the check, you have the right to demand that processing of your personal data be restricted.
If your personal data was processed/is being processed unlawfully, you can request restriction of data processing instead of deletion.
If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of processing of your personal data instead of the deletion.
If you have filed an objection according to Art. 21 Paragraph 1 of the GDPR, a balance must be struck between your interests and ours. As long as it has not been determined whose interests prevail, you have the right to demand that processing of your personal data be restricted.
If you have restricted processing of your personal data, this data may only be processed – apart from its storage – with your consent or to assert, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
4. Data collection on our website
Cookies
The websites sometimes use cookies. Cookies do not damage your computer and contain no viruses. Cookies serve the purpose of making our website more user-friendly, effective and safe. Cookies are small text files that are stored on your computer and by your browser.
Most of the cookies we use are known as “session cookies”. They are automatically deleted when you close the Web page. Other cookies are stored on your end device until you delete them. These cookies allow us to recognise your browser on your next visit to the website.
You can configure your browser to notify you whenever a cookie is set up, to accept cookies only in individual cases, not to accept any cookies in certain cases or not at all and to automatically delete cookies when you close your browser. Deactivating cookies can limit the functionality of this website.
Cookies that are required to perform electronic communication operations or to provide certain functions required by you (such as shopping basket function), are stored based on Art. 6 Paragraph 1 Letter f of the GDPR. The website operator has a legitimate interest in the storage of cookies for providing its service on a technically fault-free and optimised basis. If other cookies (such as cookies for analysing your surfing behaviour) are stored, they are dealt with separately in this Privacy Policy.
Server log files
The provider of the websites automatically collects and stores information in server log files, which your browser automatically transmits to us. These include:
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server query
- IP address
- The data is not merged with other sources of data.
This data is collected based on Art. 6 Paragraph 1 Letter f of the GDPR. The website operator has a legitimate interest in the technically fault-free presentation and optimisation of its website – the server log files need to be collected for this purpose.
Processing data (customer and contract data)
We collect, process and use personal data only insofar as it is required for the substantiation, content-related design or amendment of the legal relationship (master data). This is carried out based on Art. 6 Paragraph 1 Letter b of the GDPR, which permits processing of data to fulfil a contract or pre-contractual measures. We only collect, process and use personal data about the use of our Internet pages (usage data) insofar as this is required to enable the user to use the service or to charge for it.
The collected customer data is deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
5. Plugins and Tools
Enquiry via email, phone or fax
If you contact us via email, phone or fax, your enquiry, including all the personal data connected with it (name, enquiry) will be stored and processed by us for the purpose of handling your request. This data will not be passed on without your consent.
This data is processed based on Art. 6 Paragraph 1 Letter b of the GDPR, provided your query is related to the fulfilment of a contract or is necessary to implement pre-contractual measures. In all other cases, the processing is based on your consent (Art. 6 Paragraph 1 Letter a of the GDPR) and/or on our legitimate interests (Art. 6 Paragraph 1 Letter f of the GDPR), as we have a legitimate interest in the effective handling of the enquiries addressed to us.
The data you have sent to us by contact enquiries will remain with us until you request its deletion, revoke your consent for storage or the purpose of data storage no longer exists (for example, after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Form
If you send us an enquiry using the members’ registration form, we will store your information from the form, including the contact details you have provided, for the purpose of processing the enquiry and for follow-up questions. This data will not be passed on without your consent.
The data entered in this form is thus processed exclusively based on your consent (Art. 6 Paragraph 1 Letter a of the GDPR). You may revoke this consent at any time. An informal communication by email is sufficient for this purpose. The revocation shall not affect the lawfulness of any data processing performed prior to the revocation.
The data you have entered in the form remains with us until you request deletion, revoke your consent for storage or the purpose of data storage no longer exists (for example, after your enquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Google reCAPTCHA
We use “Google reCAPTCHA” (called “reCAPTCHA” below) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to check whether the data entry on this website (such as in a contact form) has been carried out by a person or by an automated programme. For this purpose, reCAPTCHA analyses the behaviour of the website visitor using various features. This analysis starts automatically as soon as the website visitor calls up the website. For analysis purposes, reCAPTCHA evaluates various pieces of information (such as IP address, length of stay of the website visitor on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run completely in the background. Website visitors are not notified that an analysis is taking place.
The data is stored and analysed based on Art. 6 Paragraph 1 Letter f of the GDPR. The website operator has a legitimate interest in protecting its web content from abusive automated spying and from SPAM. Provided that appropriate consent has been requested, processing is carried out based on Art. 6 Paragraph 1 Letter a of the GDPR; consent can be revoked at any time.
You can find more information on Google reCAPTCHA in the Google data protection regulations and the Google terms of use at the following links: https://policies.google.com/privacy?hl=en and https://policies.google.com/terms?hl=en.
OpenStreetMap
We incorporate the maps of the “OpenStreetMap” service, which are offered on the basis of the Open Data Commons Open Database Licence (ODbL) by the OpenStreetMap Foundation (OSMF). Privacy Policy: https://wiki.openstreetmap.org/wiki/Privacy_Policy.
To the best of our knowledge, the user data is only used by OpenStreetMap for the purposes of displaying the map functions and temporary storage of the selected settings. This data can include, in particular, IP addresses and location data of the user, which is however not collected without their consent (usually carried out in the settings of their mobile devices).
The data can be processed in the USA. You can find more information in the OpenStreetMap Privacy Policy: https://wiki.openstreetmap.org/wiki/Privacy_Policy.
Google Web Fonts
This site uses Web Fonts provided by Google for the uniform presentation of fonts. The Google Fonts are installed locally. There is no connection to Google servers.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses what is known as “cookies”. These are text files stored on your computer that enable your website use to be analysed. The information generated by the cookie regarding your use of this website is usually transmitted to a Google server in the USA and stored there.
IP anonymisation
We have activated the function IP anonymisation on this website. This means that your IP address will be truncated by Google within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities and to provide other services relating to website and Internet use to the website operator. The IP address sent by your browser as part of Google Analytics will not be combined with other data from Google.
Browser plugin
You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this, you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) to Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
You can find more information on how Google Analytics handles user data in Google’s Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=en
Order data processing
We have concluded a contract with Google for order data processing and fully implement the strict requirements of the German data protection authorities in the use of Google Analytics.
Demographic features in Google Analytics
This website uses the function “demographic features” from Google Analytics. This enables reports to be created which contain information on the age, gender and interests of the website visitor. This data comes from interest-based advertising from Google as well as from visitor data from third-party providers. This data cannot be assigned to a particular person. You can deactivate this function at any time via the display settings in your Google account or generally disallow entry of your data by Google Analytics as shown under the point “Objection to data collection”.
WordPress statistics
This website uses “WordPress statistics” to evaluate visitor access statistically. The provider is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110-4929, USA.
WordPress statistics uses technologies that enable the recognition of the user for the purposes of analysing user behaviour (such as cookies or device fingerprinting). For analysis purposes, WordPress Statistics collects, for example, log files (referrer, IP address, browsers etc.), the origin of the website visitors (country, town) and which actions they have performed on the site (such as clicks, views, downloads). The information collected in this manner on the use of this website is stored on servers in the USA. Your IP address will be anonymised after processing and before storage. This analysis tool is used on the basis of Art. 6 Paragraph 1 Letter f of the GDPR. The website operator has a justified interest in the anonymised analysis of user behaviour, to optimise both its web content as well as its advertising. Provided that appropriate consent has been requested, (such as consent to store cookies), processing is carried out exclusively based on Art. 6 Paragraph 1 Letter a of the GDPR; consent can be revoked at any time.
YouTube
Our Website uses plug-ins for the YouTube website operated by Google. The operator of the website is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
If you visit one of our websites equipped with a YouTube plug-in, a connection is established to the YouTube servers. The YouTube server is then informed about which of our websites you have visited.
In addition, YouTube can store various cookies on your end device. Using these cookies, YouTube can obtain information on users of our website. This information is used, for example, to collect video statistics, to improve user-friendliness and to prevent scamming attempts. The cookies remain stored on your end device until you delete them.
If you are logged into your YouTube account, YouTube can directly associate your surfing behaviour with your personal profile. You can prevent this by logging out of your YouTube account.
YouTube is used in the interests of an attractive presentation of our online content. This represents a legitimate interest in terms of Art. 6 Paragraph 1 Letter f of the GDPR.
You will find further information on how user data is handled in the YouTube Privacy Policy at: https://policies.google.com/privacy?hl=en.
MailChimp
This website uses the services of MailChimp to send newsletters. The provider is the Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
MailChimp is a service with can be used to organise and analyse the dispatch of newsletters. When you enter data for the purposes of newsletter subscriptions (such as email address), this is stored on the MailChimp servers in the USA.
MailChimp is certified according to the “EU-US Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA which aims to ensure the compliance of European data protection standards in the USA.
We can analyse our newsletter campaigns using MailChimp. When you open an email sent using MailChimp, a file contained in the email (called a web beacon) connects with the MailChimp servers in the USA. It can thus be determined whether a newsletter message has been opened and which links, if any, have been clicked. In addition, technical information is collected (such as time of retrieval, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for statistical analysis of newsletter campaigns. The results of these analyses can be used to adapt newsletters better to the interests of recipients in the future.
If you do not want an analysis via MailChimp, you will have to unsubscribe from the newsletter. We place a corresponding link in each newsletter message for this purpose. In addition, you can also unsubscribe from the newsletter directly on the website.
Data processing is based on your consent (Art. 6 Paragraph 1 Letter a of the GDPR). You may revoke this consent at any time by unsubscribing from the newsletter. The revocation does not affect the lawfulness of any data processing performed prior to the revocation.
The data stored by us from you for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted both from our servers as well as from the MailChimp servers after you have unsubscribed from the newsletter. Data which we have stored for other purposes (such as email addresses for the members’ area) is not affected by this.
For more information, please refer to the MailChimp data protection regulations at: https://mailchimp.com/legal/terms/.
Concluding a data processing agreement
We have concluded a “Data Processing Agreement” with MailChimp in which we have obliged MailChimp to protect our customers’ data and not to forward it to third parties.