Data privacy

1 name and contact details of the data controller and the company data protection officer

Person responsible:
brickfox GmbH
Hermannstraße 5A
70178 Stuttgart
Baden-Württemberg
Germany
Phone: +49 711 9987140
Fax: +49 711 7616427-9
E-mail: info@brickfox.de

Our company data protection officer Peter Rappold can be reached at the above address or at datenschutz@brickfox.de.

2 Collection and storage of personal data as well as type and purpose of their use

a) When visiting the website
When you visit our website, the browser used on your end device automatically sends information to our website server. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until automatic deletion:

  • Name of the retrieved file
  • Date and time of the retrieval
  • amount of data transferred
  • Message as to whether the retrieval was successful
  • description of the type of web browser used
  • operating system used
  • the previously visited page
  • provider
  • your IP address

The aforementioned data is processed by us for the following purposes:

  • Ensuring a smooth connection of the website,
  • Ensuring a comfortable use of our website,
  • evaluating system security and stability, and
  • for other administrative purposes.

The legal basis for the data processing is Art. 6 para. 1 lit. f DSGVO. Our legitimate interest follows from the data collection purposes listed above. In no case do we use the collected data for the purpose of drawing conclusions about your person.
In addition, we use cookies as well as analysis and marketing services when you visit our website. You can find more detailed explanations on this under points 5 – 7 of this data protection declaration.

b) When using our contact form
For questions of any kind, we offer you the possibility to contact us via a form provided on the website. In doing so, it is necessary to provide your name, your company, a valid e-mail address, telephone number and the specific enquiry so that we know who the enquiry is from and so that we can answer it. Further information can be provided voluntarily.

The personal data collected by us for the use of the contact form will be automatically deleted after completion of your enquiry, unless another legitimising basis (e.g. a specific order) justifies further processing.
Data processing for the purpose of contacting us is carried out in accordance with Art. 6 Para. 1 lit. b DSGVO on the basis of your specific enquiry.

c) When using our newsletter
On our website, you have the option of subscribing to a free e-mail newsletter. When registering for the newsletter, the data from the input mask is transmitted to us.

  • name
  • e-mail address
  • Company (optional)

In addition, the following data is collected during registration:

  • IP address of the calling computer
  • Date and time of registration

Your consent is obtained for the processing of the data during the registration process and reference is made to this data protection declaration.
If you commission us with the provision of services and provide us with your e-mail address, this may subsequently be used by us to send you a newsletter. In such a case, only direct advertising for our own similar goods or services will be sent via the newsletter.
No data will be passed on to third parties in connection with the processing of data for the dispatch of newsletters. The data is used exclusively for sending the newsletter.

The collection of the user’s e-mail address is used to deliver the e-mail newsletter. The collection of other personal data during the registration process serves to prevent misuse of the services or the e-mail address used.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. The user’s email address is therefore stored for as long as the subscription to the newsletter is active.

The other personal data collected during the registration process is usually deleted after a period of seven days.
The subscription to the newsletter can be cancelled by the user concerned at any time. For this purpose, there is a corresponding link in each newsletter. This also enables revocation of consent to the storage of personal data collected during the registration process.
The legal basis for the processing of the data after the user has registered for the newsletter is the user’s consent (Art. 6 para. 1 lit. a DSGVO). The legal basis for sending the newsletter as a result of the sale of goods or services is Art. 6 para. 1 lit. f in conjunction with § 7 para.3 UWG.

Newsletter – performance measurement
The newsletters contain a so-called “pixel”, i.e. a file the size of a pixel, which is retrieved from our server when the newsletter is opened, or if we use a dispatch service provider, from their server. Within the scope of this retrieval, technical information such as information on the browser and your system, as well as your IP address and the time of the retrieval are initially collected.

This information is used for the technical improvement of the services on the basis of the technical data or the target groups and their reading behaviour on the basis of their retrieval locations (which can be determined with the help of the IP address) or the access times. Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is neither our intention nor, if used, that of the dispatch service provider to observe individual users. The analyses serve us much more to recognise the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

3 transfer of data

We do not transfer your personal data to third parties for purposes other than those listed below.
We only pass on your personal data to third parties if:

  • you have given your express consent in accordance with Art. 6 Para.1 lit.a DSGVO,
  • the transfer is necessary in accordance with Art. 6 Para. 1 lit. f DSGVO and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
  • in the event that there is a legal obligation to disclose your data in accordance with Art. 6 Para. 1 lit. c DSGVO, as well as
  • this is legally permissible and necessary for the processing of contractual relationships with you in accordance with Art. 6 Para. 1 lit.b DSGVO.

4 cookies

We use so-called cookies in some areas of our website. Through such file elements, your computer can be identified as a technical unit during your visit to this website in order to make it easier for you to use our offer – also during repeat visits.

However, you usually have the option of setting your internet browser to inform you of the occurrence of cookies, so that you can allow or exclude them, or delete existing cookies.

Please use the help function of your internet browser to obtain information on how to change these settings. We would like to point out that individual functions of our website may not work if you have deactivated the use of cookies.

Cookies do not allow a server to read private data from your computer or the data stored by another server. They do not cause any damage to your computer and do not contain viruses.

Unless specifically regulated below, we base the use of cookies on Art. 6 para.1 lit.f DSGVO. The processing is carried out to improve the functioning of our website. It is therefore necessary to protect our legitimate interests.

5 use of tools, marketing services

Here you will find a list of the tools and marketing services used, followed by the respective detailed explanations.

  1. google analytics
  2. google re/marketing services
  3. Facebook “visitor action pixel
  4. akismet anti-spam checking
  5. bing Ads
  6. matelso
  7. hotjar
  8. linkedin
  9. other third party services and content

5.1 Use of Google Analytics

We use Google Analytics, a web analytics service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (see https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active ).

Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyse how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, due to the activation of IP anonymisation on this website, your IP address will be truncated beforehand by Google within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on our behalf for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You may also refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de).

We would like to point out that the code “gat._anonymizeIp();” has been added to Google Analytics on this website to ensure anonymised collection of IP addresses (so-called IP masking).

You can also prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie will then be set, which prevents the further collection of your data when visiting this website. This procedure is particularly recommended when accessing our site via mobile devices.

You can find more information on the terms of use and data protection at www.google.com/analytics/terms/de.html or at www.google.com/intl/de/analytics/privacyoverview.html.

We base the use of the aforementioned analysis tool on Art.6 para.1 lit.f DSGVO: the processing is carried out to analyse user behaviour and is therefore necessary to protect our legitimate interests.

Deactivate Google Analytics

5.2. Google Advertising and Marketing Services

We utilize the marketing and remarketing services (referred to as “Google Marketing Services”) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

Google is certified under the Privacy Shield agreement, ensuring compliance with European data protection regulations (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

The Google Marketing Services enable us to display targeted ads on our website and other platforms, tailored to users’ potential interests. For instance, when a user sees ads for products they’ve previously shown interest in on other websites, it’s referred to as “remarketing.” To achieve this, Google runs a Google code and embeds (re)marketing tags (invisible graphics or code, also known as “pixels”) directly into our website when it’s accessed, allowing the storage of an individual cookie – a small file – on the user’s device. These cookies can be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com, or googleadservices.com. This file notes which websites the user visited, what content they engaged with, which offers they clicked on, as well as technical information about their browser and operating system, referring websites, visit duration, and additional details about online usage. Additionally, the user’s IP address is collected. We inform you that within Google Analytics, IP addresses are shortened within member states of the European Union or other contracting states of the Agreement on the European Economic Area before being transferred to a server in the USA and subsequently shortened. The IP address is not merged with other data from Google’s offerings. Google may link the aforementioned information with data from other sources. Subsequently, when the user visits other websites, ads tailored to their interests may be displayed.

User data is pseudonymously processed within the Google Marketing Services. This means that Google stores and processes relevant data related to cookies within pseudonymous user profiles. From Google’s perspective, the ads are not managed and displayed for a specifically identified individual but rather for the cookie holder, regardless of their identity. However, this does not apply if a user explicitly permits Google to process their data without pseudonymization. Information collected by Google Marketing Services about users is transmitted to Google and stored on Google’s servers in the USA.

One of the Google Marketing Services we use is the “Google AdWords” online advertising program. In the case of Google AdWords, each AdWords customer receives a different “conversion cookie.” As a result, cookies cannot be tracked across the websites of AdWords customers. The information obtained via the cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers receive the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, users’ personal identification is not revealed.

Furthermore, we use the “Google Tag Manager” to integrate and manage Google Analytics and Marketing Services on our website.

For more information about Google’s data usage for marketing purposes, visit: https://www.google.com/policies/technologies/ads, and Google’s Privacy Policy can be found at https://www.google.com/policies/privacy.

If you wish to opt-out of interest-based advertising through Google Marketing Services, you can use the settings and opt-out options provided by Google: http://www.google.com/ads/preferences.

We base this use on Article 6(1)(a) of the GDPR.

5.3. Use of Facebook Visitor Action Pixel

With your consent, the “Visitor Action Pixel” of Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA (“Facebook”), is employed within our online presence.

The “Visitor Action Pixel” allows actions of users to be tracked when they are redirected to a provider’s website by clicking on a Facebook advertisement. This enables us to measure the effectiveness of Facebook advertisements for statistical and market research purposes and to optimize our marketing efforts accordingly. The data collected is anonymous to us; we cannot view individual user’s personal data or draw conclusions from it.

Facebook stores and processes this data. Facebook can associate this data with your Facebook account. You can enable Facebook and its partners to display advertisements on and off Facebook. For these purposes, a cookie may be stored on your computer. For more information about the collection and use of data by Facebook, as well as your rights and options to protect your privacy, please refer to Facebook’s Data Policy: https://www.facebook.com/about/privacy/

Consent for the use of the Facebook Visitor Action Pixel may only be given by users who are older than 13 years of age. You can revoke your consent here.

We base this use on Article 6(1)(a) of the GDPR.

5.4. Use of Akismet Anti-Spam Verification

Our online offering utilizes the service “Akismet,” provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. With the help of this service, comments from real people are distinguished from spam comments. For this purpose, all comment details are sent to a server in the USA, where they are analyzed and stored for comparison purposes for four days. If a comment is classified as spam, the data will be stored beyond this period. These details include the entered name, email address, IP address, comment content, referrer, information about the used browser and computer system, and the time of entry.

Automattic is certified under the Privacy Shield Agreement, providing a guarantee of compliance with European data protection laws (https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC&status=Active).

Further information about the collection and use of data by Akismet can be found in Automattic’s privacy policy: https://automattic.com/privacy/.

Users are welcome to use pseudonyms or refrain from entering their name or email address. You can prevent the transmission of data completely by not using our comment system. This would be a pity, but unfortunately, we do not see any alternatives that work as effectively.

We base this use on Article 6(1)(a) of the GDPR.

5.5. Use of Bing Ads

On our website, data is collected and stored using Bing Ads technologies, from which usage profiles are created using pseudonyms. This is a service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. This service allows us to track the activities of users on our website when they arrive via Bing Ads advertisements. If you arrive on our website through such an ad, a cookie will be placed on your computer. A Bing UET (Universal Event Tracking) tag is integrated into our website. This is a code that, in conjunction with the cookie, stores some non-personal data about the usage of the website. This data includes, among other things, the duration of your visit to the website, which sections of the website were accessed, and through which ad users arrived at the website. Information about your identity is not captured.

The collected information is transmitted to Microsoft servers in the USA and stored there for a maximum of 180 days. You can prevent the collection of data generated by the cookie and related to your use of the website, as well as the processing of this data, by disabling cookies. However, this may restrict the functionality of the website.

Furthermore, Microsoft might engage in Cross-Device Tracking, which allows them to track your usage behavior across multiple electronic devices, enabling personalized advertising on Microsoft websites and apps. You can deactivate this behavior at http://choice.microsoft.com/de-de/opt-out.

For more information about Bing’s analysis services, please visit the Bing Ads website (https://help.bingads.microsoft.com/#apex/3/de/53056/2). For more information about privacy at Microsoft and Bing, please refer to Microsoft’s privacy statement (https://privacy.microsoft.com/de-de/privacystatement).

We base this use on Article 6(1)(a) of the GDPR.

5.6. Use of MaTelSo

For telephone tracking services, we utilize the company MaTelSo GmbH, Heilbronner Str. 150, 70191 Stuttgart, Germany. This company stores the displayed phone number and the time in a cookie called “mat_tel.” Once a call takes place, the shortened caller’s phone number, call duration, and call success status are stored in the MaTelSo system. This data is then pseudonymized and sent to Google Analytics as a web event to conduct conversion tracking.

We base this use on Article 6(1)(a) of the GDPR.

5.7. Use of Hotjar

We employ Hotjar to gain a better understanding of our users’ needs and optimize the offerings on this website. By utilizing Hotjar’s technology, we enhance our comprehension of user experiences (such as the amount of time users spend on specific pages, the links they click on, their preferences, and dislikes, etc.). This assists us in tailoring our offerings according to user feedback. Hotjar uses cookies and other technologies to collect information about user behavior and their devices (including the device’s IP address, which is only captured and stored in an anonymized form, screen size, device type – Unique Device Identifiers, information about the browser used, location – country only, preferred language for displaying our website). Hotjar stores this information in a pseudonymized user profile. The data is not used by Hotjar or us to identify individual users or combined with additional data about individual users.

For more information, please refer to Hotjar’s Privacy Policy here.

You can choose to reject the creation of a user profile, the collection of information about your visit to our website by Hotjar, and the placement of Hotjar tracking cookies on other websites by clicking on this Opt-Out Link.

We base this use on Article 6(1)(a) of the GDPR.

5.8. Use of LinkedIn

Our website utilizes features from the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Whenever you access one of our pages containing LinkedIn features, a connection to LinkedIn’s servers is established. LinkedIn is notified that you have visited our website with your IP address. If you click the “Recommend” button on LinkedIn and are logged into your LinkedIn account, LinkedIn can associate your visit to our website with you and your user account. We want to inform you that as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.

For more information, please refer to LinkedIn’s Privacy Policy: https://www.linkedin.com/legal/privacy-policy

We base this use on Article 6(1)(a) of the GDPR.

5.9 Integration of Additional Third-Party Services and Content

Within our online offering, based on our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offering within the meaning of Art. 6(1)(f) of the GDPR), we use content or service offerings from third-party providers to incorporate their content and services, such as videos or fonts (hereinafter uniformly referred to as “content”).

This always presupposes that the third-party providers of this content perceive the users’ IP address, as they could not send the content to their browser without the IP address. The IP address is therefore necessary for the presentation of this content. We endeavor to only use content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “pixels”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic to the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may include technical information about the browser and operating system, referring websites, visit time, as well as further information about the use of our online offering. It may also be linked with such information from other sources.

a. YouTube

We integrate videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

b. Google Fonts

We integrate fonts (“Google Fonts”) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

c. Google+

We integrate Google+ provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

6. Deletion of Data

The data stored by us will be deleted as soon as they are no longer necessary for their intended purpose and there are no legal retention obligations preventing their deletion. If user data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies, for example, to user data that must be retained for commercial or tax reasons.

According to legal requirements, retention is carried out for 6 years in accordance with § 257 para. 1 HGB (commercial books, business letters, etc.) and for 10 years in accordance with § 147 para. 1 AO (commercial and business letters, documents relevant for taxation, etc.).

7 Rights of Data Subjects

You have the following rights as data subjects:

7.1. Right to Information

You have the right to request confirmation from us as to whether or not personal data concerning you is being processed.

7.2. Rectification/Erasure/Restriction of Processing

Furthermore, you have the right to request from us that: • Incorrect personal data concerning you be corrected without undue delay (Right to rectification); • Personal data concerning you be erased without undue delay (Right to erasure), and • Processing be restricted (Right to restriction of processing).

7.3. Right to Data Portability

You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller.

7.4. Right to Withdraw Consent

You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

7.5. Right to Object

If the processing of personal data concerning you is necessary for the performance of a task carried out in the public interest (Art. 6(1)(e) GDPR) or for the purposes of legitimate interests pursued by us (Art. 6(1)(f) GDPR), you have the right to object to such processing.

7.6. Right to Lodge a Complaint

If you believe that the processing of personal data concerning you violates the GDPR, you have the right to lodge a complaint with a supervisory authority without prejudice to other remedies.

7.7. Changes to the Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements, our services, or data processing practices. However, this only applies to statements regarding data processing. If user consents are required or if parts of the privacy policy contain provisions of the contractual relationship with users, changes will only be made with the user’s consent.

Users can regularly check for any changes in this privacy policy.

Disclaimer:

Liability for Content

The contents of our pages have been created with the utmost care. However, we cannot guarantee the accuracy, completeness, or timeliness of the content. As a service provider, we are responsible for our own content on these pages according to general laws. However, we are not obliged to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information according to general laws remain unaffected. However, liability in this regard is only possible from the time of knowledge of a specific legal violation. Upon becoming aware of corresponding legal violations, we will remove such content immediately.

Liability for Links

Our website may contain links to external websites of third parties, over which we have no control. Therefore, we cannot assume any liability for these external contents. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal violations at the time of linking. Illegal content was not recognizable at the time of linking. However, a permanent content control of the linked pages is not reasonable without concrete evidence of a violation of the law. Upon becoming aware of violations, we will remove such links immediately.

Copyright

The content and works created by the site operators on these pages are subject to German copyright law. The reproduction, editing, distribution, and any kind of exploitation outside the limits of copyright require the written consent of the respective author or creator. Downloads and copies of this page are only permitted for private, non-commercial use. Insofar as the content on this page was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is marked as such. Should you nevertheless become aware of a copyright infringement, please let us know. Upon becoming aware of violations, we will remove such content immediately. By using this website, you consent to the processing of data about you by us and by Google in the manner and for the purposes set out above.

Inclusion, Validity, and Currency of the Privacy Policy

By using our website, you consent to the data usage described above. The privacy policy is currently valid and dated as of May 25, 2018.

Due to the continuous development of our website or the implementation of new technologies, it may become necessary to change this privacy policy. We reserve the right to amend the privacy policy at any time with effect for the future. We recommend that you periodically review the current privacy policy.