Data Protection Notices
With this data protection notice, we would like to inform you about the nature, scope, and purpose of the processing of personal data (hereinafter also referred to as "data"). Personal data includes all data that has a personal reference to you, e.g., name, address, email address, or your user behavior. The data protection notice applies to all data processing operations carried out by us, both in the context of our core activities and for the online media we provide.
Responsible for Data Processing
My-Disclose
DIM Internet Media Kft.
Sobieski János utca 36. alagsor 1
1096 Budapest
Hungary
service@My-Disclose.com
Processing of Your Data in the Context of Our Company’s Core Activities
If you are our customer or business partner or are interested in our services, the nature, scope, and purpose of the processing of your data depend on the contractual or pre-contractual relationships existing between us. In this sense, the data we process includes all data provided or collected for the purpose of utilizing contractual or pre-contractual services, which are necessary for handling your inquiry or the contract concluded between us. Unless otherwise stated in the further information of this data protection notice, the processing of your data and its transfer to third parties is limited to the data necessary and appropriate for responding to your inquiries and/or fulfilling the contract concluded between you and us, safeguarding our rights, and complying with legal obligations. We will inform you which data is required for this purpose before or during data collection. Insofar as we use third-party providers to provide our services, the data protection notices of the respective third-party providers apply.
Affected Data:
- Inventory data (e.g., names, addresses)
- Payment data (e.g., bank details, invoices)
- Contact data (e.g., email address, phone number, postal address)
- Contract data (e.g., contract subject, contract duration)
Affected Persons: Interested parties, business and contractual partners
Processing Purpose: Handling contractual services, communication, and responding to contact inquiries, office and organizational procedures
Legal Basis: Contract fulfillment and pre-contractual inquiries, Art. 6(1)(b) GDPR, legal obligation, Art. 6(1)(c) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Your Rights Under the GDPR
Under the GDPR, you have the following rights, which you can assert at any time with the controller named in section 1 of this data protection notice:
- Right to Information: You have the right to request information from us about whether and which data we process about you.
- Right to Rectification: You have the right to request the correction of inaccurate or completion of incomplete data.
- Right to Erasure: You have the right to request the deletion of your data.
- Right to Restriction: In certain cases, you have the right to request that we process your data only to a limited extent.
- Right to Data Portability: You have the right to request that we transfer your data to you or another controller in a structured, commonly used, and machine-readable format.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. The supervisory authority of your usual place of residence, workplace, or our company headquarters is responsible.
Right to Withdraw Consent
You have the right to withdraw your consent to data processing at any time.
Right to Object
You have the right to object at any time to the processing of your data, which we base on our legitimate interest under Art. 6(1)(f) GDPR. If you exercise your right to object, we ask you to provide the reasons. We will then no longer process your personal data unless we can demonstrate to you that compelling legitimate grounds for processing outweigh your interests and rights.
Regardless of the above, you have the right at any time to object to the processing of your personal data for advertising and data analysis purposes.
Please direct your objection to the contact address of the controller provided above.
When Do We Delete Your Data?
We delete your data when we no longer need it or when you instruct us to do so. This means that—unless otherwise stated in the individual data protection notices of this data protection notice—we delete your data,
- when the purpose of the data processing no longer applies and thus the respective legal basis specified in the individual data protection notices no longer exists, e.g.,
- after termination of the contractual or membership relationships existing between us (Art. 6(1)(a) GDPR) or
- after our legitimate interest in further processing or storing your data no longer exists (Art. 6(1)(f) GDPR),
- if you exercise your right to withdraw consent and no other legal basis for processing within the meaning of Art. 6(1)(b-f) GDPR applies,
- if you exercise your right to object and there are no compelling legitimate grounds preventing deletion.
However, if we must retain (certain parts of) your data for other purposes, for example, due to tax retention periods (generally 6 years for business correspondence or 10 years for accounting records) or for asserting, exercising, or defending legal claims arising from contractual relationships (up to four years), or if the data is needed to protect the rights of another natural or legal person, we will delete (that part of) your data only after these periods have expired. Until these periods expire, we limit the processing of this data to these purposes (fulfillment of retention obligations).
Cookies
Our website uses cookies. Cookies are small text files consisting of a series of numbers and letters that are stored on the device you use. Cookies primarily serve to exchange information between the device you use and our website. This includes, among other things, language settings on a website, login status, or the point at which a video was watched.
Two types of cookies are used when visiting our websites:
- Temporary Cookies (Session Cookies): These store a so-called session ID, which allows various requests from your browser to be assigned to the shared session. Session cookies are deleted when you log out or close your browser.
- Permanent Cookies: Permanent cookies remain stored even after closing the browser. This allows our website to recognize your computer when you return to our website. These cookies store, for example, information about language settings or login information. Additionally, your browsing behavior can be documented and stored with these cookies. This data can be used for statistical, marketing, and personalization purposes.
In addition to the above classification, cookies can also be distinguished based on their purpose:
- Necessary Cookies: These are cookies that are absolutely necessary for the operation of our website, to store logins or shopping carts for the duration of your session, or cookies set for security reasons.
- Statistics, Marketing, and Personalization Cookies: These are cookies used for analysis purposes or reach measurement. Such "tracking" cookies may store information about search terms entered or the frequency of page visits. Additionally, an individual user’s browsing behavior (e.g., viewing specific content, using functions, etc.) may be stored in a user profile. Such profiles are used to display content to users that matches their potential interests. If we use services that store cookies on your device for statistics, marketing, and personalization purposes, we will inform you separately in the following sections of our data protection notice or when obtaining your consent.
Affected Data:
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address).
Affected Persons: Users of our online offerings
Processing Purpose: Delivering our websites, ensuring the operation of our websites, improving our online offerings, communication, and marketing
Legal Basis:
Legitimate Interest, Art. 6(1)(f) GDPR
If we do not obtain your consent to set cookies, we base the processing of your data on our legitimate interest in improving the quality and user-friendliness of our online presence, particularly the content and functions. You can object to the use of cookies set by us in the context of our legitimate interest via your browser’s security settings. There, you can specify whether you want to accept no cookies at all, only accept cookies upon request, or have cookies deleted after each browser session. If cookies are disabled for our website, some functions of the website may not be fully usable.
Consent, Art. 6(1)(a) GDPR
If we ask you to allow certain cookies to be set on your device before visiting our online presence and you consent, the legal basis lies in the consent you have given. We inform you as part of the consent process about which cookies we set in detail. If you do not give this consent, only the so-called technically necessary cookies are set, which are required for the proper operation of our websites and their display in your browser. If you have consented to the setting of cookies, you can withdraw your consent at any time.
Web Hosting
We use a provider to host our websites, on whose servers our websites are stored and made available for access on the internet (hosting). The provider may process all data transmitted via the browser you use, which arises during the use of our websites. This includes, in particular, your IP address, which the provider needs to deliver our online offering to the browser you use, as well as all entries you make via our website. In addition, the provider we use may collect
- the date and time of access to our website
- time zone difference to Greenwich Mean Time (GMT)
- access status (HTTP status)
- the amount of data transferred
- the internet service provider of the accessing system
- the type and version of the browser you use
- the operating system you use
- the website from which you may have accessed our website
- the pages or subpages you visit on our website.
The aforementioned data is stored as log files on our provider’s servers. This is necessary to ensure the stability and security of our website’s operation.
Affected Data:
- Content data (e.g., posts, photos, videos)
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address)
Affected Persons: Users of our online presence
Processing Purpose: Delivering our websites, ensuring the operation of our websites
Legal Basis: Legitimate interest, Art. 6(1)(f) GDPR
Content Delivery Network
We use a Content Delivery Network (CDN) to deliver our websites. A CDN is a network of regionally distributed and internet-connected servers. The CDN provides scalable storage and delivery capacities. This optimizes the loading times of our websites and ensures optimal data throughput even during high load peaks. User requests on our websites are routed through CDN servers. Statistics are generated from these data streams. This serves, on the one hand, to identify potential threats to our websites from malware early and, on the other hand, to continuously improve our offering and make our websites more user-friendly for you as a user.
We would like to point out that, depending on the country of origin of the service provider mentioned below, the data collected via the service may be transferred and processed outside the European Union. In this case, there is a risk that the data protection level required by the GDPR is not maintained, and the enforcement of your rights may not be possible or may be difficult.
Affected Data:
- Content data (e.g., posts, photos, videos)
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address)
Processing Purpose: Technical optimization of the online presence, analysis of errors and user behavior
Legal Basis: Legitimate interest, Art. 6(1)(f) GDPR
Used CDN Providers:
Cloudflare
Service Provider: Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA
Website: https://www.cloudflare.com/
Privacy Policy: https://www.cloudflare.com/privacypolicy/
Scope of Data Collection: https://blog.cloudflare.com/what-cloudflare-logs/
Contacting Us
If you contact us via email, social media, phone, fax, post, our contact form, or otherwise and provide us with personal data such as your name, phone number, or email address, or provide further information about yourself or your request, we process this data to respond to your inquiry within the framework of the pre-contractual or contractual relationships existing between us.
Affected Data:
- Inventory data (e.g., names, addresses)
- Contact data (e.g., email address, phone number, postal address)
- Content data (texts, photos, videos)
- Contract data (e.g., contract subject, contract duration)
Affected Persons: Interested parties, customers, business and contractual partners
Processing Purpose: Communication and responding to contact inquiries, office and organizational procedures
Legal Basis: Contract fulfillment and pre-contractual inquiries, Art. 6(1)(b) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Registration, Login, and User Account
You have the option to register on our online medium to create a user account. This requires the provision of personal data as indicated in the input form. The data requested there includes, in particular, your name, email address, possibly a username, and the password. This data is stored and processed by us to set up a user account for you and to enable (repeated) login. You can change or delete the data at any time. The data is not passed on to third parties unless it serves the technical and organizational handling of the usage contract existing between us. To protect you and us from abusive registrations, we store the IP address assigned to you at the time of registration, as well as the date and time of the registration.
Affected Data:
- Inventory data (e.g., names, addresses)
- Contact data (e.g., email address, phone number, postal address)
- Contract data (e.g., contract subject, contract duration)
- Payment data (e.g., bank details, invoices)
- Content data (e.g., posts, photos, videos)
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address)
Processing Purpose: Handling contractual services, communication and responding to contact inquiries, security measures.
Legal Basis: Contract fulfillment and pre-contractual inquiries, Art. 6(1)(b) GDPR, legal obligation, Art. 6(1)(c) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Deletion: See the section: “When Do We Delete Your Data?”. In addition, we would like to point out that we delete the data collected during registration and the content data stored in the account, subject to conflicting legal retention obligations, as soon as you delete your account. We therefore ask you to back up the content data stored in your account elsewhere before deleting the account if you want or need to access it after the account is deleted.
Processing of Your Data When Ordering in Our Online Shop
If you place orders via our online shop, we process the information you provide during the ordering process to process your order. This includes, in particular, your name, address, and electronic contact details, information on payment processing, and details about your specific order. We will inform you which data is required during the ordering process.
If it is necessary for the fulfillment of the contract concluded between us, to protect your vital interests, or due to legal provisions, we transfer your data to third parties, such as the logistics company commissioned with delivery, payment service providers for payment processing, and our tax advisor, while respecting your rights. Insofar as we use third-party providers to provide our services, the data protection notices of the respective third-party providers apply.
User Accounts: You can voluntarily create a user account in which you can view and manage your orders. If you terminate your account, your data will be deleted. It is your responsibility to back up your data before termination. We use transient cookies (see the term above under Cookies) to store the shopping cart contents and persistent cookies to store the login status. When you place an order, register for a user account, or log in again, we store your IP address and the time of the respective user action. The purpose of storage is both our and your legitimate interests in protecting against misuse and other unauthorized use.
Advertising Measures: We may also use the data you provide to inform you by post or email about similar interesting products and/or services after a completed order.
Affected Data:
- Inventory data (e.g., names, addresses)
- Payment data (e.g., bank details, invoices)
- Contact data (e.g., email address, phone number, postal address)
- Contract data (e.g., contract subject, contract duration)
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address)
Affected Persons: Customers, interested parties, business and contractual partners
Processing Purpose: Processing orders, communication and, where applicable, marketing and responding to inquiries, data security, office and organizational procedures
Legal Basis: Contract fulfillment and pre-contractual inquiries, Art. 6(1)(b) GDPR, legal obligation, Art. 6(1)(c) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Payment Service Providers
In accordance with our legal obligations or due to our legitimate interests in efficient, secure, and customer-oriented payment processing, persons who have entered into a contract or other legal relationship with us can use banks, credit institutions, and other payment service providers for payment. The payment service providers we offer process inventory data in this context, including name, address, or bank details such as account/credit card numbers, passwords, TANs, verification numbers, as well as information about the concluded contract and details about the payment recipient.
The data collected in this context is necessary to carry out the payment processing by the payment service provider. Only the payment service provider commissioned by us collects and processes this personal information. We do not receive any information about your account or credit card details at any time. We are informed by our payment service provider whether our customers’ payment has been received or not. There is a possibility that our payment service providers may transfer our customers’ data to credit agencies to verify the identity and creditworthiness of the payer. In this regard, we refer to the privacy policy and general terms and conditions (GTC) of our payment service providers.
The GTC and data protection provisions of the respective payment service provider apply. You can find these notices on the website of the relevant service provider or in the transaction application. For further information and for asserting your rights regarding withdrawal and information, we refer to the provisions of the respective service provider.
Affected Data:
- Inventory data (e.g., name, address)
- Usage data (e.g., visited websites, interest in specific topics, access times)
- Payment data (e.g., bank details, invoices, payment history)
- Contract data (e.g., duration, customer category, contract subject)
- Communication and metadata (e.g., IP address, information about the device or computer system)
Processing Purpose: Effective, secure, and customer-oriented payment offerings (service) and processing of payments in accordance with contractual agreements
Legal Basis: Contract fulfillment and pre-contractual inquiries, Art. 6(1)(b) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Withdrawal Options: You can withdraw your consent to the use of personal data at any time with the respective payment service provider. Despite withdrawal, the payment service provider may still be entitled to process, use, and transfer personal data that is strictly necessary for contractual payment processing. Regarding the storage and timely deletion of personal data, we refer to the respective data protection provisions of the payment service provider.
We use the following payment service providers:
CatalystPay
Service Provider: CatalystPay Limited, Office 525, Scottish Provident Building, Donegall Square West, Belfast, BT1 6JH, United Kingdom
Website: https://catalystpay.com/
Privacy Policy: https://catalystpay.com/legal/privacy
Advertising via Email, Post, or Phone
For our promotional communication via email, post, or phone, we process personal data. You can object to receiving our advertising measures at any time or withdraw the previously given consent to receive our promotional communication at any time. To be able to prove, in case of doubt, that your consent existed after your objection or withdrawal, we may store your data for up to 4 years after your objection/withdrawal. We will not use your data for further purposes after your objection/withdrawal. If you want us to delete your data earlier, we will do so after you confirm that you originally gave us consent.
Affected Data:
- Contact data (e.g., email, phone number, postal address)
- Inventory data (e.g., names, addresses)
Affected Persons: Communication partners
Processing Purpose: Direct advertising measures (marketing) via email, post, or phone
Legal Basis: Consent, Art. 6(1)(a) GDPR, legitimate interest, Art. 6(1)(f) GDPR
Web Analysis and Statistics
To capture and statistically evaluate visitor flows on our online presence, we use web analysis services. Such services collect, among other things, data about which website you came from to our online presence (so-called referrers), which pages of our online presence you accessed, how long you visited our pages, and which interactions you performed there. In addition, data about the browser, computer system, and device type you use is collected. Furthermore, demographic information, such as age or gender, can be collected as pseudonymous values through such a service. If you have consented to the collection of your location data, this may also be processed, depending on the provider.
To collect and store this data, the web analysis service we use typically sets a cookie on the device you use, which also collects the IP address assigned to you. However, this is shortened via a so-called IP masking procedure, so that the IP address can no longer be linked to your visit to our website. Otherwise, no clear data such as names or email addresses is stored. Neither we nor the service we use know the identity of the visitors to our websites.
We would like to point out that, depending on the country of origin of the service provider mentioned below, the data collected via the service may be transferred and processed outside the European Union. In this case, there is a risk that the data protection level required by the GDPR is not maintained, and the enforcement of your rights may not be possible or may be difficult.
Affected Data:
- Usage data (e.g., access times, clicked websites)
- Communication data (e.g., information about the device used, IP address).
Affected Persons: Users of our online offerings
Processing Purpose: Reach measurement, campaign success monitoring, remarketing, and interest- and behavior-based marketing
Legal Basis: If we have asked for your consent before using the respective service, this is the legal basis, Art. 6(1)(a) GDPR. Otherwise, we use the respective service based on our legitimate interest in analyzing visitor flows to our websites to continuously improve functions, offerings, and the user experience, Art. 6(1)(f) GDPR.
We use the following web analysis services:
Google Analytics
Service Provider: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Headquarters within the EU: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://marketingplatform.google.com/about/analytics/
Privacy Policy: https://policies.google.com/privacy?hl=de
Opt-Out Option: If you do not want your data to be used by Google Analytics, you can set a so-called opt-out plugin, which will prevent your data from being collected on our website in the future. You can obtain this plugin here: https://tools.google.com/dlpage/gaoptout?hl=de
Security Measures
We also implement technical and organizational security measures in accordance with the state of the art to comply with data protection laws and to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties.
Current Status and Changes to This Data Protection Notice
This data protection notice is currently valid and has the status of November 2024. Due to changed legal or regulatory requirements, it may be necessary to adapt this data protection notice.
This data protection notice was created with the help of the data protection generator from SOS Recht. SOS Recht is an offering of Mueller.legal Rechtsanwälte Partnerschaft based in Berlin.