We attach great importance to the protection and security of personal data. Below you will find the information required in accordance with the Basic Data Protection Regulation ("DSGVO") regarding the processing of personal data when you use the HEYLO service. Personal data are all data with which you can be personally identified.
Who is the person in charge?
HEYLO GmbH, based in Achim, Germany, is responsible for the processing of personal data concerning you. Their contact details can be found in the imprint of the website.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This can be data that you enter in a contact form, newsletter registration or seminar participation, for example.
On the other hand, when visiting our websites and using our services for the provision and administration of the services as well as for security purposes, user data is automatically collected, for example the Internet browser, the operating system or the time of the page call.
All this data is processed and used for the purposes mentioned below and in some cases stored for a limited period of time and - subject to the further descriptions in this data protection declaration - does not allow us to draw any conclusions about a natural person. Your IP address is not stored, nor is the MAC address. The collection and processing of the corresponding personal data is based on Art. 6 para. 1 sentence 1 lit. b DSGVO (contractual purpose), insofar as this is necessary to enable you to use our services.
In addition, the processing is necessary in individual cases to protect the legitimate interests of us or a third party (Art. 6 para. 1 sentence 1 lit. f DSGVO). Our interest in processing corresponding data, such as browser type or other log files, is particularly to ensure the functionality and security of our information technology systems and to optimize the website.
Cookies and analysis services are used when you visit our website. You will find more detailed explanations in this data protection declaration.
You can visit or use our services without having to register or identify yourself. A traceability to your person is therefore not possible.
Use of the data
The following is a brief description of the possibilities for the use of your data.
1. Collection of data
Personal data is collected when you register for a seminar, request a catalogue or subscribe to the newsletter. In the process, information about your person and the necessary data for processing is collected. Of these data, only those details that are required for the contractual relationship are designated as mandatory data.
2. Processing, use and deletion of data
HEYLO uses the collected data for the following basic purposes, although not all data is actually used for all purposes:
The data concerning your person and address (inventory data) will be used to establish and process the user relationship (seminars, contact form).
We use the data on your use of the individual offers (usage data) for the technical processing of the usage service (such as catalogue request or newsletter).
With the complete processing of the contractual relationship, your data will be blocked for further use and deleted after the expiry of the tax and commercial law retention periods, unless you have expressly consented to the further use and exploitation of your data (e.g. newsletter).
When registering for the newsletter, your e-mail address will be used for our own advertising purposes until you unsubscribe from the newsletter.
What do we process your data for?
Part of the data is collected to ensure that the website is provided without errors. Other data can be used to analysis your user behavior.
What rights do you have regarding your data?
Your rights as a person concerned towards the controller are regulated in the General Data Protection Regulation (DSGVO). In the following, we explain the essential content of the most important regulations. You can obtain a more comprehensive overview of your rights by reading in particular Articles 7, 15 to 22 and 77 to 80 of the DSGVO.
1. The right to revoke consents, Art. 7 DSGVO
Many data processing operations are only possible with your express consent. You can revoke a previously given consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing carried out up to the point of revocation remains unaffected by the revocation.
2. Right to lodge an objection at any time, Art. 21 DSGVO
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you, which is carried out on the basis of Article 6(1), first sentence, letter (e) or (f) of the basic data protection regulation. The personal data will then no longer be processed by the controller, unless he can demonstrate compelling reasons for processing that are worthy of protection and outweigh your interests, rights and freedoms. Even if the processing serves the purpose of asserting, exercising or defending legal claims, the controller may continue to process personal data concerning you.
Where personal data are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing.
Art. 21 of the basic data protection regulation also provides for other reasons that give you the right to lodge an objection.
3. Right to information, Art. 15 DSGVO
You have the right to obtain confirmation from the controller as to whether personal data concerning you are being processed. You may also request information about the personal data processed. In this case, the person in charge must provide you with further information on data processing, as specified in Art. 15 of the DPA.
4. Right to correct incorrect personal data, Art. 16 DSGVO
You have the right to ask the data controller to correct incorrect personal data concerning you and/or to complete incomplete personal data without delay.
5. The right to delete personal data, Art. 17 DSGVO
You have the right to obtain from the data controller, without delay, the deletion of personal data concerning you if they are no longer needed for the purposes for which they were collected. Art. 17 DSGVO also provides for other reasons that give you the right to have your personal data deleted.
6. Right to restrict data processing, Art. 18 DSGVO
Art. 18 DSGVO regulates certain situations in which you have the right to request a restriction of data processing. This applies in particular in the event that you object to personal data relating to you being processed. For the duration of the audit, you may exercise your right to restrict data processing in accordance with Art. 18 DSGVO.
7. Right to data transferability, Art. 20 DSGVO
Under the conditions of Art. 20 DSGVO you have the right to data transferability. This includes the right to receive personal data concerning you, which you have provided to the person in charge, in a structured, common and machine-readable format and the right to transfer this data to other persons in charge without hindrance. As far as this is technically feasible, you can also request that the data be transferred directly to another responsible party.
8. Right to appeal to a supervisory authority, Art. 77 DSGVO
If you believe that the controller has infringed the basic data protection regulation by processing personal data relating to you, you have the right to complain to the competent supervisory authority. In addition to the other supervisory authorities mentioned in Art. 77 DSGVO, the supervisory authority of the place of the suspected infringement is responsible in particular.
Data collection on our website
The processing is carried out on the basis of Art.15 (3) TMG as well as Art. 6 (1) lit. f DSGVO from the legitimate interest in the above-mentioned purposes. The data collected from you in this way is pseudonym missed by technical precautions. It is therefore no longer possible to assign the data to your person. The data will not be stored together with other personal data of yours.
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you, based on Art. 6 (1) f of the DPA.
The links below will tell you how to manage (including deactivating) cookies in the most important browsers:
Chrome Browser: https://support.google.com/accounts/answer/61416?hl=de
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer- delete-manage-cookies
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Safari: https://support.apple.com/de-de/guide/safari/manage-cookies-and-website-data- sfri11471/mac2.
2. Server log files
You can visit our websites without giving any personal information. Every time you access our website, usage data is transmitted by your Internet browser and stored in log files (server log files). These stored data include, for example, the name of the page called up, the date and time of the call, the amount of data transferred and the requesting provider. This data is used exclusively to ensure the trouble-free operation of our website and to improve our services. It is not possible to assign this data to a specific person.
3. Use of the e-mail address for sending newsletters
You would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address and agree to receive the newsletter. The processing is carried out on the basis of Art. 6 (1) lit. a DSGVO with your consent. We use this data exclusively for sending the requested information and offers.
In order to ensure that the newsletter is sent by mutual agreement, we use the so-called double opt- in procedure. In the course of this, the potential recipient can be included in a distribution list.
Subsequently, the user receives a confirmation e-mail to confirm the registration in a legally secure manner. The address will only be actively included in the distribution list if confirmation is received.
Newsletter2Go is used as newsletter software. Your data will be transmitted to the Newsletter2Go GmbH. Newsletter2Go is not allowed to sell your data and use it for other purposes than for sending newsletters. Newsletter2Go is a German, certified provider, which was selected according to the requirements of the Data Protection Basic Regulation and the Federal Data Protection Act.
Further information can be found here: https://www.newsletter2go.de/informationen-newsletter- empfaenger/
4. Contact form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not pass on this data.
The processing of the data entered in the contact form is thus exclusively based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke this consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing operations carried out up to the time of revocation shall remain unaffected by the revocation.
The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to store it or the purpose for which it was stored ceases to apply (e.g. after your request has been processed). Mandatory statutory provisions - in particular retention periods - remain unaffected.
5. User account dealer portal
You can log in as a dealer on our website to use additional features on the site. We use the data entered for this purpose (e-mail address) only for the purpose of using the respective offer or service for which you have registered.
The processing of the data entered during login is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke any consent you have given at any time. For this purpose, an informal communication by e-mail to us is sufficient.
The legality of the data processing already carried out remains unaffected by the revocation.
The data collected during registration is stored by us for as long as you are registered for our login area and is then deleted. Legal retention periods remain unaffected.
6. Use of Google reCAPTCHA
We use the service reCAPTCHA of Google Inc. on our website. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). The query serves the purpose of distinguishing whether the input is made by a human being or by automated, machine processing. The query includes the sending of the IP address and possibly other data required by Google for the service reCAPTCHA to Google. For this purpose, your input is transmitted to Google and used there. Your IP address will, however, be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of this service. The IP address transmitted by your browser in the context of reCAPTCHA is not merged with other data from Google. Your data may also be transferred to the USA. Data transfers to the USA are subject to a European Commission adequacy decision, the Privacy Shield. Google participates in the "Privacy Shield" and has submitted to the guidelines. By clicking on the query you agree to the processing of your data.
Processing is carried out on the basis of Art. 6 (1) lit. a DSGVO with your consent. You can revoke your consent at any time without affecting the legality of the processing that has taken place on the basis of the consent until the revocation.
7. Dealer search
You can register as a dealer for our dealer search. Then you will be suggested to the site visitors as the next dealer in a proximity search. We use the data entered for this purpose (company name, location, contact person, address, shop e-mail) exclusively for the purpose of using the respective offer or service for which you have registered.
The processing of the data is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke any consent you have given at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing already carried out remains unaffected by the revocation.
The data collected during registration is stored by us for as long as you are registered for our dealer search and is then deleted. Legal retention periods remain unaffected.
8. Commerce Connector
We work together with the service provider Commerce Connector. Through this service, we use digital touchpoints to alert visitors to potential retailers where a particular product can be purchased. The list of merchants that sell your selected product via the manufacturer's digital touchpoint is provided by our software-based service Commerce Connector Buy Now online.
If you click on the "order online" button and then a shop logo of a dealer you have selected, you will be directed to the website of the respective dealer and directly to the product you are interested in. When using the software-based service Commerce Connector Buy Now online, cookies are sometimes used for so-called "sales tracking", which provides us with information about your purchase from a retailer. Cookies are text files that your browser stores on your computer. They contain information on how to use a digital touchpoint.
When you click on the "Order Online" button or a shop logo, a cookie is stored on your device for a limited period of time (usually 7 days). If you make a purchase from the retailer during this period, Commerce Connector may access the cookie to obtain the information that you reached the participating retailer's Web site through the manufacturer's digital contact point. In addition, the merchant will provide you with information about your purchase when you reach the merchant's order confirmation page.
The service provider and we do not receive any information that could identify you (except the unique number in the cookie). Commerce Connector uses the purchase information exclusively to create anonymous sales statistics of products for HEYLO.
9. Processing of data (customer and contract data)
We collect, process and use personal data only to the extent that they are necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b DSGVO, which allows the processing of data for the fulfilment of a contract or pre-contractual measures. We collect, process and use personal data about the use of our Internet pages (usage data) only to the extent necessary to enable or charge the user for the use of the service. The collected customer data will be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.
Analysis tools and advertising
1. Google Analytics
On our website we use the web analysis service Google Analytics of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). The data processing serves the purpose of analyzing this website and its visitors. To this end, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activities and to provide further services to the website operator in connection with website and Internet use. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other data from Google.
You can prevent the storage of cookies by selecting the appropriate technical settings in your browser software; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link [https://tools.google.com/dlpage/gaoptout?hl=de]. In order to prevent Google Analytics from collecting data across devices, you can set an opt-out cookie. Opt-out cookies prevent the future collection of your data when you visit this website. You must perform the opt-out on all systems and devices in use in order for it to be fully effective. If you click here, the opt-out cookie will be set: Disable Google Analytics
2. Use of Google's remarketing or "similar target groups" function
We use the remarketing or "Similar Target Groups" feature of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google") on our website.
If you are ordinarily resident in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the data controller. Google Ireland Limited is therefore the company affiliated with Google which is responsible for processing your data and ensuring compliance with applicable data protection laws. The application serves the purpose of analyzing visitor behavior and visitor interests.
3. Use of social plug-ins by means of "Shariff
We use social networking plug-ins on our website. In order to keep you in control of your data, we use the data protection secure "Shariff" buttons. No links to the servers of the social networks will be established without your express consent and consequently no data will be transmitted.
"Shariff" is a development of the specialists of the computer magazine c't. It enables more privacy on the net and replaces the usual "Share" buttons of social networks. More information about the Shariff project can be found here https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit- Datenschutz-2467514.html. If you click on the buttons, a pop-up window appears in which you can log in with your data at the respective provider. Only after this active login by you will a direct connection to the social networks be established.
By logging in, you give your consent to the transfer of your data to the respective social media provider. Among other things, your IP address as well as the information which of our pages you have visited will be transmitted. If you are connected to one or more of your social network accounts at the same time, the information collected is also associated with your corresponding profiles. You can only prevent this association by logging out of your social media accounts before visiting our website and before activating the buttons. The social networks mentioned below are integrated by means of the "Shariff" function.
Further information on the scope and purpose of the collection and use of the data as well as on your rights and possibilities for the protection of your privacy can be found in the linked data protection notices of the providers.
Facebook of the Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA) https://www.facebook.com/policy.php
Xing of XING SE (Dammtorstrafle 30, 20354 Hamburg, Germany) https://www.xing.com/privacy
4. Use of YouTube
We use on our website the function for embedding YouTube videos from YouTube LLC. (901 Cherry Ave., San Bruno, CA 94066, USA; 'YouTube'). YouTube is a joint venture with Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google").
The function displays videos stored on YouTube in an iFrame on the website. The option "Advanced privacy mode" is activated. As a result, YouTube does not store any information about visitors to the site. Only when you watch a video is information about it sent to YouTube and stored there.
5. Use of GoogleMaps
On our website we use the function for embedding GoogleMaps maps from Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google").
The function enables the visual display of geographical information and interactive maps. Google also collects, processes and uses data of the visitors of the pages when they call up the pages in which GoogleMaps maps are integrated. Further information on the collection and use of data by Google can be found in the Google data protection information at https://www.google.com/privacypolicy.html. There you also have the possibility to change your settings in the Privacy Center, so that you can manage and protect your data processed by Google. Your data may also be transferred to the USA. Data transfers to the USA are subject to an adequacy finding by the European Commission.
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you, based on Art. 6 (1) f of the DPA.
6. Google AdWords and Google Conversion Tracking
This website uses Google AdWords. AdWords is an online advertising program of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google").
In the context of Google AdWords we use the so-called conversion tracking. When you click on an ad served by Google, a cookie is set for conversion tracking. These cookies lose their validity after 30 days and are not used to personally identify users. If the user visits certain pages of this website and the cookie has not expired, Google and we may recognize that the user clicked on the ad and was redirected to that page. Every Google AdWords customer receives a different cookie. The cookies cannot be tracked on the websites of AdWords customers. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, you will not receive information that can be used to identify users personally. If you do not wish to participate in tracking, you can opt out of this use by slightly disabling the Google Conversion Tracking cookie on your web browser under User Preferences. They will not be included in the conversion tracking statistics.
The storage of "conversion cookies" is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the analysis of user behavior in order to optimize both his website and his advertising.
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If you disable cookies, the functionality of this website may be limited.
Duration of storage
After complete processing of the contract, the data is initially stored for the duration of the warranty period, then taking into account statutory, in particular tax and commercial law retention periods, and then deleted after the period has expired, unless you have consented to further processing and us.
last update: 29/01/2020