Privacy Policy
Status: July 7, 2024
General Information and Mandatory Information on Data Protection
We ("we", "us", "our") take the protection of the data of users ("users" or "you") of our website and/or our mobile app (the "Website" or "Mobile App") very seriously and are committed to protecting the information that users provide to us in connection with the use of our Website and/or Mobile App (collectively, the "Digital Assets"). Furthermore, we are committed to protecting and using your data in accordance with applicable law.
We handle your personal data confidentially and in accordance with statutory data protection regulations as well as this privacy policy.
When you use this Website, various personal data is collected. Personal data is information that can identify you personally. This privacy policy explains what data we collect and how we use it. It also explains how and for what purposes this is done.
Please note that data transmission over the internet (e.g., communication via email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
This privacy policy explains our practices regarding the collection, use, and disclosure of your data through the use of our Digital Assets (the "Services") when you access the Services via your devices.
Please read this privacy policy carefully and ensure that you fully understand our practices regarding your data before using our Services. If you have read and fully understood this policy and do not agree with our practices, you must cease using our Digital Assets and Services. By using our Services, you acknowledge the terms of this privacy policy. Continued use of the Services constitutes your acceptance of this privacy policy and any changes to it.
Name and Address of the Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is:
Name: Sara Haug
Address: Julius-Reiber-Str. 44, 64293 Darmstadt
Email Address: info@sara-haug.com
Website: https://sara-haug.com
General Information on the Legal Basis for Data Processing on This Website
If you have consented to data processing, we process your personal data based on Article 6(1)(a) GDPR or Article 9(2)(a) GDPR if special categories of data are processed according to Article 9(1) GDPR. In the case of explicit consent to the transfer of personal data to third countries, data processing also occurs on the basis of Article 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing additionally occurs on the basis of Section 25(1) of the Telecommunication-Telemedia Data Protection Act (TTDSG). Consent may be revoked at any time. If your data is necessary for the fulfillment of a contract or for carrying out pre-contractual measures, we process your data based on Article 6(1)(b) GDPR. Furthermore, we process your data if it is required to fulfill a legal obligation based on Article 6(1)(c) GDPR. Data processing may also be carried out based on our legitimate interests pursuant to Article 6(1)(f) GDPR. The specific legal bases for processing will be detailed in the following sections of this privacy policy.
Affected Persons
This privacy policy informs you about the type, scope, and purpose of the collection and use of personal data by the website operator Sara Haug.
Categories of affected persons:
Visitors and users of the website: Individuals who visit and use our website.
Customers: Individuals who use our coaching services or register for our workshops.
Prospects: Individuals who inquire about our services and contact us without being a customer.
This privacy policy explains which personal data we collect from these affected persons, how we use this data, and what rights the affected persons have in relation to their personal data.
Definitions
This privacy policy is based on the terms used by the European legislator in the issuance of the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easily readable and understandable for the public as well as our customers and business partners. To ensure this, we would like to explain the terms used:
Personal Data: Personal data is any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing: Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data.
Controller: The controller is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor: The processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Consent: Consent is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Data Subject: The data subject is any identified or identifiable natural person whose personal data is processed by the controller.
Third Parties: Third parties are any natural or legal persons, public authorities, agencies, or bodies other than the data subject, the controller, the processor, and the persons who, under the direct authority of the controller or the processor, are authorized to process personal data.
Recipient: The recipient is a natural or legal person, public authority, agency, or body to whom personal data is disclosed, whether or not a third party.
Profiling: Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements of that natural person.
In this privacy policy, you will learn:
How we collect data
What data we collect
Why we collect this data
To whom we disclose the data
Where the data is stored
How long we retain the data
How we protect the data
How we handle minors
Social media
Hosting
Updates or changes to the privacy policy
Below is an overview of the data we may collect:
Non-identified and non-identifiable information that you provide during the registration process or that is collected through the use of our services ("non-personal data"). Non-personal data does not allow conclusions to be drawn about who provided it. Non-personal data that we collect primarily consists of technical and aggregated usage information.
Individually identifiable information, i.e., any information that can identify you or that could reasonably identify you ("personal data"). Personal data that we collect through our services may include information such as names, email addresses, addresses, phone numbers, IP addresses, and more. If we combine personal data with non-personal data, as long as they are combined, we will treat them as personal data.
How Do We Collect Your Data?
Your data is collected in part by you providing it to us. This could include data you enter into a contact form.
Other data is collected automatically or with your consent when you visit the Website through our IT systems. This mainly includes technical data (e.g., internet browser, operating system, or time of page access). This data is automatically collected as soon as you access the Website.
The main methods we use to collect data are:
Data Collection
Data Collection during Use: We collect data when you use our services. This includes gathering and storing information about your usage, sessions, and related details when you visit our digital assets and utilize our services.
Data Provided Directly by You: We collect data that you provide directly, such as when you contact us via a communication channel (e.g., an email with comments or feedback).
Data from Third-Party Sources: As described below, we may collect data from third-party sources.
Data from Third-Party Authentication: We collect data that you provide when you log into our services through a third-party provider such as Facebook or Google.
Purposes for Data Use
We may use your data for the following purposes:
To provide and operate our services;
To develop, customize, and improve our services;
To respond to your feedback, requests, and inquiries, and to offer assistance;
To analyze usage patterns and requirements;
For internal, statistical, and research purposes;
To enhance our data security and fraud prevention measures;
To investigate violations and enforce our terms and policies, and to comply with applicable laws, regulations, or governmental orders;
To send you updates, notifications, promotional materials, and other information related to our services. You can opt-out of receiving promotional emails at any time by clicking the unsubscribe link provided in those emails.
Recipients of Personal Data
In the course of our business operations, we collaborate with various external entities, which may require the transfer of personal data to these parties. We disclose personal data only under the following conditions:
When necessary for contract fulfillment;
When legally required (e.g., data transfer to tax authorities);
When we have a legitimate interest in accordance with Art. 6(1)(f) GDPR;
When permitted by other legal bases for data transfer;
When using data processors, personal data is shared based on a valid data processing agreement;
In cases of joint processing, a data processing agreement is established.
Disclosure of Data
We may disclose your data to our service providers to operate our services (e.g., data storage through third-party hosting services, technical support, etc.). Additionally, we may disclose your data under the following circumstances:
(i) To investigate, detect, prevent, or address unlawful activities or other misconduct;
(ii) To establish or exercise our rights in defense;
(iii) To protect our rights, property, personal safety, and the safety of our users or the public;
(iv) In the event of a change of control, such as a merger, acquisition, or sale of substantially all assets;
(v) To manage and/or process your data through authorized third parties (e.g., cloud service providers) as necessary for business purposes;
(vi) To collaborate with third parties to improve your user experience.
To avoid misunderstandings, please note that we do not transfer or use non-personal data at our discretion.
Without your consent, we will not disclose your email address or other personal data to advertising companies or networks.
Cookies and Similar Technologies
Our websites use “cookies.” Cookies are small data packets that do not harm your device. They may be temporary (session cookies) or persistent (permanent cookies). Session cookies are deleted automatically after your visit, while permanent cookies remain until you delete them or they are automatically removed by your browser.
Cookies can be first-party (set by us) or third-party (set by other companies). Third-party cookies enable the integration of certain services from third-party providers (e.g., cookies for payment services).
Cookies serve various purposes. Some are technically necessary for the proper functioning of certain website features (e.g., shopping cart function or video display). Others may be used for analyzing user behavior or for advertising purposes.
Cookies necessary for the execution of electronic communication, provision of specific functions (e.g., shopping cart functionality), or optimization of the website (e.g., audience measurement cookies) are stored based on Art. 6(1)(f) GDPR, unless otherwise stated. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of their services. If consent for storing cookies and similar technologies is requested, processing is based solely on that consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG); consent can be withdrawn at any time.
You can configure your browser to notify you of cookie placement and allow cookies only on a case-by-case basis, exclude cookies in specific cases or generally, and activate automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
When you visit or access our services, we authorize third parties to use web beacons, cookies, pixel tags, scripts, and other technologies and analytics services (“tracking technologies”). These tracking technologies may enable third parties to automatically collect your data to enhance navigation, optimize performance, provide a personalized user experience, and for security and fraud prevention purposes.
For more information, please refer to our Cookie Policy.
Contact Form
If you contact us via a contact form, your details from the form, including the contact information you provide, will be stored to process your request and for follow-up questions. We will not share this data without your consent.
Processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the fulfillment of a contract or is necessary for pre-contractual measures. In other cases, processing is based on our legitimate interest in effectively handling requests (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if requested; consent can be withdrawn at any time.
The data you provide in the contact form will remain with us until you request its deletion, withdraw your consent, or the purpose for storing the data ceases to apply (e.g., after processing your request is completed). Mandatory legal provisions, particularly retention periods, remain unaffected.
Inquiries via Email, Phone, or Fax
If you contact us via email, phone, or fax, your inquiry, including all resulting personal data (name, request), will be stored and processed to address your concern. We will not share this data without your consent.
Processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the fulfillment of a contract or is necessary for pre-contractual measures. In other cases, processing is based on our legitimate interest in effectively handling inquiries (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if requested; consent can be withdrawn at any time.
Data Retention and Deletion
The data you have sent to us via contact inquiries will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g., after processing your request is complete). Mandatory statutory provisions – especially statutory retention periods – remain unaffected.
Analysis Tools and Third-Party Tools
When you visit this website, your browsing behavior may be statistically analyzed. This is primarily done using so-called analysis programs.
Use of Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies," which are text files placed on your computer to help analyze how you use the website. The information generated by the cookie about your use of this website (including your IP address) is usually transmitted to and stored on a Google server in the USA.
IP Address Anonymization: We have activated IP anonymization on this website. This means that Google will truncate your IP address within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the US. Only in exceptional cases will the full IP address be sent to a Google server in the US and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
Objection to Data Collection: You can prevent the storage of cookies by adjusting your browser settings accordingly; however, please note that in this case you may not be able to use all features of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and its processing by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout.
Demographic Features in Google Analytics: This website uses the "demographic features" function of Google Analytics. This allows reports to be generated that contain statements about the age, gender, and interests of website visitors. This data originates from interest-based advertising by Google as well as from visitor data from third parties. This data cannot be attributed to a specific person. You can disable this feature at any time via the ad settings in your Google account or generally object to the collection of your data by Google Analytics as described in the "Objection to Data Collection" section.
Order Processing: We have entered into a contract with Google for order processing and fully implement the stringent requirements of German data protection authorities when using Google Analytics.
Retention Period: Data will be stored for a period of 26 months and then automatically deleted.
Further Information: For more information on handling user data with Google Analytics, please refer to Google’s privacy policy: https://support.google.com/analytics/answer/6004245.
By using this website, you consent to the processing of the data collected about you by Google in the manner described and for the purposes previously stated.
Social Media
Instagram
This website integrates functionalities from the Instagram service. These features are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection between your device and the Instagram server is established. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to this website with your user account. We want to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data and its use by Instagram.
The use of this service is based on your consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TDDG. Consent can be revoked at any time.
To the extent that personal data is collected and forwarded to Facebook or Instagram using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited solely to the collection of data and its forwarding to Facebook or Instagram. The processing of the data by Facebook or Instagram following forwarding is not part of the joint responsibility. The obligations we jointly share have been documented in an agreement on joint processing. The text of the agreement can be found here: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook or Instagram tools and for the data protection-compliant implementation of the tools on our website. Facebook is responsible for the data security of the Facebook or Instagram products. Data subjects’ rights (e.g., access requests) regarding data processed by Facebook or Instagram can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
Data transfer to the US is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.
Further information can be found in Instagram’s privacy policy: https://privacycenter.instagram.com/policy/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF undertakes to adhere to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnbGAAS&status=Active
Data Storage
Personal Data
Personal data may be maintained, processed, and stored in the United States, Ireland, South Korea, Taiwan, Israel, and, if necessary for the proper provision of our services and/or legally required (as explained further below), in other jurisdictions.
Data Retention Period
Please note that we retain collected data as long as necessary to provide our services, to comply with our legal and contractual obligations to you, to resolve disputes, and to enforce our agreements. If you make a legitimate request for deletion or withdraw consent for data processing, your data will be deleted, unless we have other legally permissible reasons for retaining your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will occur once these reasons no longer apply.
We may correct, supplement, or delete incorrect or incomplete data at our discretion.
Access, Correction, and Deletion
You have the right to request free information about your stored personal data, its origin, recipients, and the purpose of the data processing, and, if applicable, to request correction or deletion of this data. You can also contact us at any time for further questions regarding personal data.
Right to Restrict Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time to exercise this right. The right to restrict processing exists in the following cases:
If you dispute the accuracy of your stored personal data, we generally need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
If the processing of your personal data is unlawful, you may instead request the restriction of data processing.
If we no longer need your personal data but you need it to assert, exercise, or defend legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
If you have lodged an objection under Art. 21 (1) GDPR, a balance must be struck between your and our interests. While this is being determined, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data – apart from its storage – may only be processed with your consent or for the establishment, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
Withdrawal of Consent
Many data processing operations are only possible with your explicit consent. You can withdraw any consent already given at any time. The legality of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.
Right to Object to Data Collection in Specific Cases and to Direct Marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 (1) LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS FOR WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING PROTECTIVE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21 (1) GDPR).
Processing of Personal Data for Direct Marketing
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will no longer be processed for the purpose of direct marketing (objection pursuant to Article 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, especially in the Member State of their habitual residence, their place of work, or the location of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data which we process based on your consent or in the fulfillment of a contract in a structured, commonly used, and machine-readable format, and to transmit those data to another controller, where technically feasible.
Data Protection Measures
Our hosting provider provides the online platform through which we can offer our services. Your data may be stored through the storage, databases, and general applications of our hosting provider.
The provider stores your data on secure servers behind a firewall and offers secure HTTPS access to most areas of its services: This site uses SSL or TLS encryption to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator. An encrypted connection can be recognized by the change in the address line of the browser from "http://" to "https://" and the lock symbol in your browser's address bar. When SSL or TLS encryption is activated, data transmitted to us cannot be read by third parties.
Handling of Minors
Despite the measures and efforts taken by us and our hosting provider, we cannot and do not guarantee absolute protection and security of the data you upload, publish, or otherwise share with us or others.
Therefore, we ask you to set secure passwords and not to transmit confidential information to us or others if its disclosure could significantly or persistently harm you. Since email and instant messaging are not considered secure communication forms, please avoid sending confidential information via these channels.
The services are not intended for users who have not reached the age of majority. We will not knowingly collect data from children. If you are not of legal age, you should not download or use the services or provide us with any information.
We reserve the right to request age verification at any time to verify whether minors are using our services. If we become aware that a minor is using our services, we may deny access to our services to such users, suspend them, and delete all data stored about such users. If you have reason to believe that a minor has provided data to us, please contact us as outlined below.
Use of Personal Data
We use your personal data only for the purposes specified in the privacy policy and only if we are convinced that:
The use of your personal data is necessary to fulfill or conclude a contract (e.g., to provide you with the services themselves or customer service/technical support);
The use of your personal data is necessary to comply with legal or regulatory obligations; or
The use of your personal data is necessary to support our legitimate business interests (provided that it is always done in a manner that is proportionate and respects your privacy rights).
Rights Regarding Your Data
You have the right to obtain information free of charge about the origin, recipients, and purpose of your stored personal data at any time. You also have the right to request correction or deletion of this data. If you have given consent to data processing, you may withdraw this consent at any time in the future. Additionally, you have the right to request the restriction of processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
As an EU resident, you can:
Request confirmation as to whether personal data concerning you is being processed, and access your stored personal data and certain additional information;
Request the receipt of personal data you have provided to us in a structured, commonly used, and machine-readable format;
Request correction of your personal data stored with us;
Request deletion of your personal data;
Object to the processing of your personal data by us;
Request the restriction of processing your personal data; or
Lodge a complaint with a supervisory authority.
Please note, however, that these rights are not absolute and may be subject to our legitimate interests and regulatory requirements. If you have general questions about the personal data we collect and how it is used, please contact us as outlined below.
Cross-Border Data Transfers
In providing the services, we may transfer data across borders to affiliated companies or other third parties and from your country/jurisdiction to other countries/jurisdictions worldwide. By using the services, you consent to the transfer of your data outside the EEA.
If you are located in the EEA, your personal data will only be transferred to locations outside the EEA if we are convinced that an adequate or comparable level of data protection is in place. We will take appropriate steps to ensure that we have adequate contractual arrangements with our third parties to ensure that appropriate security measures are in place to minimize the risk of unlawful use, alteration, deletion, loss, or theft of your personal data and that these third parties comply with applicable laws at all times.
Hosting
We host the content of our website with the following provider:
WIX
Provider is Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel (hereinafter “WIX”).
WIX is a tool for creating and hosting websites. When you visit our website, WIX analyzes user behavior, visitor sources, the region of website visitors, and visitor numbers. WIX stores cookies on your browser, which are necessary for displaying the website and ensuring security (necessary cookies).
Data collected through WIX may be stored on servers worldwide. WIX’s servers are located, among other places, in the USA.
Details can be found in WIX's privacy policy: https://de.wix.com/about/privacy.
Data transfers to the USA and other third countries are based on the EU Commission's Standard Contractual Clauses or similar safeguards according to Article 46 GDPR. Details can be found here: https://de.wix.com/about/privacy-dpa-users.
California Consumer Privacy Act (CCPA) Rights
If you use the services as a resident of California, you may be entitled under the California Consumer Privacy Act (CCPA) to request access to and deletion of your data.
To exercise your right to access and deletion, please follow the instructions provided below on how to contact us.
We do not sell personal data of users for the purposes of the CCPA.
Updates or Changes to the Privacy Policy
We may revise this privacy policy from time to time at our discretion. The version posted on the website is always the current one (see "Last Updated" statement). We encourage you to review this privacy policy regularly for changes. For significant changes, we will post a notice on our website. If you continue to use the services after being notified of changes to our privacy policy, this will be considered as your acceptance and agreement to the changes and the terms of such changes.
Contact
For general questions regarding the services or the personal data we collect and how it is used, please contact us at:
Name: Sara Haug
Address: Julius-Reiber-Str. 44
64293 Darmstadt
Email: info@sara-haug.com
Source:
https://www.e-recht24.de and https://support.wix.com/de/article/juristische-textvorlage-für-deine-datenschutzrichtlinie