Privacy policy
This is a courtesy translation. In legal terms, only the German version is binding. Read the German version
Principles of data processing at Entracon Planungsgesellschaft mbH and Entracon Projektservice GmbH.
Name and address of the controller
The controller within the meaning of the General Data Protection Regulation, other national data protection laws of the member states and further data protection provisions is:
Entracon Planungsgesellschaft mbH
Dr. Philipp Schwittek
Frielinghauser Straße 5
59071 Hamm
Deutschland
E-mail: p.schwittek@entracon.de
Website: www.entracon.de
I. General information on data processing
Scope of processing personal data
As a rule, we process personal data of our users only to the extent necessary to provide a functioning website and to deliver our content and services. Personal data of our users is generally processed only with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted by law.
Legal basis for processing personal data
Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6 (1) (a) GDPR serves as the legal basis. Where processing of personal data is necessary for the performance of a contract to which the data subject is party, Art. 6 (1) (b) GDPR serves as the legal basis; this also applies to pre-contractual measures. Where processing is necessary to fulfil a legal obligation, Art. 6 (1) (c) GDPR serves as the legal basis. Where processing is necessary to safeguard a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not override it, Art. 6 (1) (f) GDPR serves as the legal basis.
Erasure and storage period
The personal data of the data subject is erased or blocked as soon as the purpose of storage no longer applies. Storage beyond that may take place where provided for by European or national legislation. Data is also blocked or erased when a prescribed storage period expires, unless further storage is necessary for the conclusion or performance of a contract.
II. Provision of the website and log files
Each time our website is accessed, our system automatically records data and information from the computer system of the accessing device. The following data is collected:
- browser type and version
- the user's operating system
- the user's internet service provider
- the user's IP address
- date and time of access
- websites from which the user's system reaches our site
- websites accessed by the user's system via our site
The legal basis for the temporary storage of the data and the log files is Art. 6 (1) (f) GDPR. Storage serves to ensure the functioning of the website and to optimise and safeguard the security of our information technology systems. The data is not evaluated for marketing purposes in this context. It is erased as soon as it is no longer required for the purpose of its collection – in the case of log files after seven days at the latest.
III. Use of cookies
This website uses strictly necessary cookies only. Their purpose is to simplify the use of the website – for example, remembering your language setting. No consent is required for this; the legal basis is Art. 6 (1) (f) GDPR. We do not use cookies for analytics or advertising.
IV. Audience measurement without cookies
Scope and purpose of the processing
We want to know which of our content is read and how many people it reaches. To that end we count two things: how often a page was opened on a given day, and how many distinct visitors were on the website that day. We use neither cookies nor any other identifier on your device for this, we read nothing from your device, and we embed no external service. The data never leaves our server.
How the visitor figure is produced
So that the same visitor is not counted twice within one day, we form a checksum (SHA-256) from a random value generated anew each day, your IP address and your browser identification. Only this checksum is stored, never your IP address, and your IP address cannot be recovered from it. The random value changes daily at midnight, so the same person receives an entirely different checksum the next day. Recognition across several days is therefore impossible – and not something we want.
Storage period
During the night after each completed day, the checksums and the corresponding random value are deleted. All that remains are daily totals – numbers of visitors, visits and page views – with no link to any person.
Legal basis
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in being able to judge the reach and clarity of our content. As no information is stored on or read from your device, no consent under section 25 TDDDG is required either. You may object to this processing at any time using the contact details given below.
Click and scroll measurement
In addition we record, as totals only, where on a page people click and how far they scroll. Only rounded positions are stored, as daily totals per page and device class – with no identifier, no mouse tracking and no link to any person. This tells us whether important content is being missed.
V. Contact, call-back requests and live chat
Contact by e-mail or phone
If you contact us by e-mail or telephone, we process your details exclusively to handle your enquiry. The legal basis is Art. 6 (1) (b) or (f) GDPR. The data is erased as soon as it is no longer required for the purpose of its collection and no statutory retention periods prevent this.
Call-back request via the contact window
You can request a callback via the contact panel on this website. In doing so, we process your name, telephone number, e-mail address and – where provided – your availability and your request. We use these details solely to call you back. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR.
Your callback request is created as a ticket in our own helpdesk system rapidFOX. rapidFOX is software developed by Entracon; processing takes place on servers in Germany. No transfer to third parties takes place.
Live chat
This website offers a live chat, which is likewise operated via rapidFOX. The chat window is loaded only when you actively open it – no data whatsoever is transmitted to the chat system beforehand. When you open the chat, your messages, a randomly generated session identifier and – where you provide it voluntarily – your e-mail address are processed in order to answer your enquiry. The legal basis is Art. 6 (1) (f) GDPR. The session identifier is stored locally in your browser so that a conversation you have started can be continued; you can delete it at any time via your browser settings.
VI. Rights of the data subject
If personal data concerning you is processed, you have the following rights:
- Access (Art. 15 GDPR) to the data processed about you, the purposes, the recipients, the storage period and the origin of the data.
- Rectification (Art. 16 GDPR) of inaccurate or incomplete data — without undue delay.
- Restriction of processing (Art. 18 GDPR), for instance while the accuracy of your data is being verified.
- Erasure (Art. 17 GDPR), where the data is no longer needed for its purpose, you withdraw consent, or processing was unlawful.
- Notification (Art. 19 GDPR) of all recipients about a rectification, erasure or restriction.
- Data portability (Art. 20 GDPR) in a structured, commonly used and machine-readable format.
- Objection (Art. 21 GDPR) to processing based on Art. 6 (1) (e) or (f) GDPR, and at any time to direct marketing.
- Withdrawal of consent (Art. 7 (3) GDPR) with effect for the future.
- No automated individual decision-making (Art. 22 GDPR) — we do not take decisions with legal effect by automated means alone.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority – in particular in the member state of your residence, your place of work or the place of the alleged infringement – if you consider that the processing of personal data concerning you infringes the GDPR.
For North Rhine-Westphalia this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
To exercise your rights, an informal message to this address is sufficient: p.schwittek@entracon.de.