Data protection information for the Gira photo mosaic

We, Gira Giersiepen GmbH & Co. KG, take the protection of personal data and its confidential treatment very seriously. We therefore hereby inform you about the processing of your personal data within the scope of the Gira photo mosaic campaign and the rights to which you are entitled. Your personal data is processed exclusively within the scope of the applicable legal provisions of data protection law, in particular the General Data Protection Regulation (hereinafter "DSGVO") and the Federal Data Protection Act ("BDSG").

I. Who is responsible for data processing and who is the data protection officer?

  1. Responsible for the processing of your personal data is:

Gira Giersiepen GmbH & Co. KG

Dahlienstr. 12

42477 Radevormwald

Deutschland

Tel.: +49 2195-6020

info@gira.de

 

  1. You can reach our data protection officer as follows:

Dr. Gregor Scheja

Scheja und Partner Rechtsanwälte mbB

Adenauerallee 136

53113 Bonn

Deutschland

Tel.: (+49) 0228-227 226 0

https://www.scheja-partner.de/kontakt/kontakt.html

www.scheja-partner.de

 

II. What is the subject of data protection?

Gegenstand des Datenschutzes sind personenbezogene Daten. Dies sind alle Informationen, die sich auf eine identifizierte oder identifizierbare natürliche Person (sog. betroffene Person) beziehen. Hierunter fallen z.B. Angaben wie Name, postalische Adresse, E-Mail-Adresse oder Telefonnummer.

 

III. Which of my personal data is processed?

Within the scope of the Gira photo mosaic campaign, we only process your personal data that is related to this. This can be in detail:

  • Photographs of you
  • Your name
  • Your email address
  • Special categories of personal data, such as, where applicable
    • Health data (e.g. by wearing glasses)
    • Information on religious affiliation (visibly worn symbols)

 

IV. What are the purposes of the processing of my personal data and what is the legal basis for this?

We process the photograph taken of you on the basis of the declaration of consent you have given. The purpose pursued with the processing results from the content of the respective declaration of consent. This may apply in the following cases:

  • Contributions in a photo collage as part of the digital event "Light + Building 2022"
  • Contributions in a photo collage at the trade fair stand of Gira Giersiepen GmbH & Co. KG at the "Light + Building 2022" trade fair in Frankfurt
  • Articles on the www.partner.gira.com/en/fotoaktion website of Gira Giersiepen GmbH & Co. KG
  • Contributions to the Gira Giersiepen GmbH & Co. KG intranet
  • Posts on the social media platforms Facebook, Instagram and LinkedIn by Gira Giersiepen GmbH & Co. KG
  • Sending a mail referring to the final overall mosaic

The data processing is based on Art. 6(1)(a) DSGVO.

You can revoke your consent at any time. Please note, however, that this revocation only has an effect for the future, i.e. the legality of the processing of the data already carried out on the basis of your consent up to the time of the revocation is not affected by the revocation.
We delete the data when it is no longer required for the purposes we are pursuing, the storage period specified in the consent has expired or you have revoked the consent and there is no other legal basis. If the latter applies, we delete the data after the other legal basis no longer applies.

 

V. Is my personal data also collected from third parties?

We only process the personal data that we receive directly from you.

 

VI. Is there any automated decision making or profiling?

We do not use automated decision-making or profiling in accordance with Art. 22 DSGVO.

 

VII. Do I have to provide my personal data?

There is no obligation for you to provide personal data; however, if you do not provide us with a photo, we cannot include you in the Gira photo mosaic.

 

VIII. Who has access to my personal data and which recipients receive it?

Within our company, only those departments and the employees working there who absolutely need such access to fulfil their functions or tasks have access to your personal data. These are employees from the marketing department.
We will only share your personal data with external recipients if there is a legal justification for doing so or you have consented to it. External recipients can be:

  • Processors: Service providers we use to provide services in the course of running the photo mosaic campaign or who are entrusted with the maintenance of our IT systems. These processors are carefully selected and regularly checked by us to ensure that your personal data is in good hands. The service providers may only process your personal data for the purposes specified by us.
  • Operators of the social media platforms (Facebook, Instagram and LinkedIn)
  • Public authorities: Authorities and state institutions, such as public prosecutors' offices, courts or tax authorities, to which we may have to transmit personal data in individual cases.

 

IX: Is a transfer of my personal data to third countries intended?

A transfer of your personal data to third countries takes place through access from third countries to the online presences (Facebook, Instagram, LinkedIn) on which your photo is published. The legal basis for this is the consent you have given.

 

X: How long will my personal data be stored?

For the storage period of your personal data, please refer to the respective chapter on data processing under point IV.

 

XI: What are my data subject rights?

You have the following rights regarding the processing of your personal data:

  1. Right to information

You have the right to obtain confirmation from us as to whether or not we are processing personal data about you. If this is the case, you have the right to be informed about your personal data and to receive further information regarding the processing.

  1. Right of rectification

You have the right to request the correction of your inaccurate personal data and to have incomplete personal data completed.

  1. Right to erasure ("right to be forgotten")

In certain circumstances, you have the right to request that we erase your personal data. This right exists, for example, if the personal data is no longer necessary for the purposes for which it was collected or otherwise processed, or if the personal data has been processed unlawfully.

  1. Restriction of processing

Under certain circumstances, you have the right to request that we restrict the processing of your personal data. In this case, we will only store the personal data for which you have given consent or for which the GDPR permits processing. For example, you may have a right to restrict processing if you have contested the accuracy of your personal data.

  1. Data portability

If you have provided us with personal data on the basis of a contract or consent, you may, if the legal requirements are met, request that you receive the personal data you have provided in a structured, common and machine-readable format or that we transfer it to another controller.

  1. Revocation of consent

If you have given us consent to process your personal data, you can revoke this consent at any time with effect for the future. The lawfulness of the processing of your personal data until revocation remains unaffected.

 

  1. Right of appeal to the supervisory authority

In addition, you have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data violates applicable law. To do this, you can contact the data protection authority responsible for your place of residence, workplace or the place of an alleged violation or the data protection authority responsible for us. The competent supervisory authority is the supervisory authority of the federal state in which you live or work or in which an alleged infringement is alleged to have taken place that is the subject of the complaint.

 

XII. Who can I contact with questions or to assert my data protection rights?

If you have any questions about the processing of your personal data or if you wish to exercise your data subject rights as set out in section XI. No. 1 to 7, you can contact us free of charge. Please use our contact details under section I. No. 1.


Status: Sept. /2022

 

Cookie consent

By clicking “Accept all”, you consent to Gira using cookies and similar technologies and processing your website usage data to improve this website and to create your user profile in order to show personalised advertising. Please note that Gira also shares information about your use of the website with our social media, advertising and analytics partners.

You also consent to Gira and third parties processing your website usage data in third countries deemed not to be secure outside the EEA for these purposes, even if a level of data protection comparable to EU law is not guaranteed. Among other things, there is a risk that authorities there can access the processed data and that the rights of data subjects are compromised or excluded.

You can change your settings at any time by clicking the “Cookie settings” link at the bottom of any page. You can withdraw your consent there at any time with future effect.

All cookies that we require in order to display the site to you.

Data processing purposes:

  • Private customer site: Use of all the site's session-based features
  • Business customer site: Authentication, preferences and caching of user inputs

Categories of personal data:

  • Private customer site: IP address, duration of session, user browser, end device
  • Business customer site: Settings and preferences. Including name, address and e-mail if a contact form is filled out. (For reuse on another form within the same session), IP address (anonymised)

Legal basis and legitimate interests pursued, if applicable:

  • Article 6(1)(f) GDPR
  • Legitimate interests pursued: See data processing purposes

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:

  • Storage of data for the duration of the session, until the browser is closed
  • Time of storage: When loading the page

Data processing purposes:Serves to maintain the status of the Home Assistant configuration when using the Gira Home Assistant

Categories of personal data:IP address, configuration ID – a personal reference is only available when configuration is completed (tradesperson selected and data entered)

Legal basis and legitimate interests pursued, if applicable:

  • Article 6(1)(f) GDPR
  • Legitimate interests pursued: See data processing purposes

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:Duration of the session

Data processing purposes:Authentication in the Gira device portal (SDA portal)

Categories of personal data:IP address (anonymised)

Legal basis and legitimate interests pursued, if applicable:Article 6(1)(b) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • ISE Individuelle Software und Elektronik GmbH

Third country transfer:None

Validity period of the cookie:Duration of the session

Data processing purposes:Optimisation of the site for different browser types

Categories of personal data:IP address, duration of session, user browser, end device

Legal basis and legitimate interests pursued, if applicable:Article 6(1)(f) GDPR

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:Duration of the session

Data processing purposes:Protection against cross-site scripts

Categories of personal data:IP address, duration of session, user browser, end device

Legal basis and legitimate interests pursued, if applicable:Article 6(1)(f) GDPR

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:2 hours

Data processing purposes:Transmission of registration role for displaying relevant information and services

Categories of personal data:IP address (anonymised), target group classification (building owner/end user, specialised tradesperson, planner, wholesaler, architect)

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Article 6(1)(f) GDPR
  • Legitimate interests pursued: See data processing purposes

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:6 months

Use of cookies and similar technologies to improve our website and offers.

Data processing purposes:Statistical analysis of website usage

Categories of personal data:IP address (anonymised/abbreviated), approximate region of the visitor, browser and plug-ins used, browser language setting, time of page view, load time, operating system, screen size, referrer, time of previous visits, number of visits

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:Internal departments, in so far as access is necessary for task fulfilment

Third country transfer:None

Validity period of the cookie:

  • 12 months
  • Time of storage: Following consent

Data processing purposes:Verification of whether data entry on websites is done by a human or by an automated program

Categories of personal data:

  • Private customer site: IP address (anonymised), time spent by the visitor on the website, mouse movements made by the user
  • Business customer site: IP address (anonymised), time spent by the visitor on the website, mouse movements made by the user, date and time of the visit to the website in question, internet address or URL of the website accessed

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:12 months

Data processing purposes:Analysis of website usage. Google Analytics examines, among other things, the location of visitors and the length of time spent on individual pages, thus enabling better page and feature optimisation.

Categories of personal data:Location, time or frequency of visits to our website, IP address (anonymised)

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:14 months

Data processing purposes:Management of website tags via an interface

Categories of personal data:IP address (anonymised)

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:14 months

Data processing purposes:Showing of videos

Categories of personal data:

  • Private customer site: IP address (anonymised), time spent by the visitor on the website, mouse movements made by the user
  • Business customer site: IP address (anonymised), time spent by the visitor on the website, mouse movements made by the user, date and time of the visit to the website in question, internet address or URL of the website accessed

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:Vimeo, LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:longer than 12 months

Data processing purposes:Hotjar allows us to create a kind of heat map of selected pages. This allows us to see how users navigate around the site. We can see where they click, how far they scroll and how they move around the page.

Categories of personal data:- IP address, heat maps of usage

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Hotjar Ltd.

Third country transfer:None

Validity period of the cookie:12 months

Data processing purposes:Showing of videos

Categories of personal data:IP address, date and time and the website visited

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:longer than 12 months

Data processing purposes:Display of interactive maps

Categories of personal data:IP address (anonymised), date and time of the visit to the relevant website, internet address or URL of the website accessed

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:12 months

To be able to recognise your interests and show products customised to you.

Data processing purposes:Doubleclick can be used to place and manage adverts on a website. When, where and how often they should appear is controlled by the operator via campaigns.

Categories of personal data:IP address (anonymised)

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:14 months

Data processing purposes:Gira marketing and sales processes can be digitised and automated by tracking how Gira offers are used. By separating subscribers from website visitors, targeted and more personalised information can be provided. Increased attention enables more follow-up activities and increased customer satisfaction can also be achieved.

Categories of personal data:Date and time, type (object, e.g. eMailing, LeadPage), browser referrer, user agent, link ID (optional), object IDs, optional object-dependent information, individual transfer parameters, geocoordinates or alternatively IP-based geocoordinates (for forms with address entry) via Locr GmbH (recording postal addresses without first and last names) with server location in Germany

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • SC Networks GmbH

Third country transfer:None

Validity period of the cookie:12 months

Data processing purposes:Evaluation of website usage, campaign performance measurement

Categories of personal data:IP address, browser information, website visited, date and time of visit, device information, usage data, click path, geographical location

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Meta Platforms Ireland Ltd, Meta Platforms, Inc. (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:90 days

Data processing purposes:Evaluation of website usage, campaign performance measurement

Categories of personal data:IP address, browser information, website visited, date and time of visit, device information, usage data, click path, geographical location

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Pinterest, Inc. (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:12 months

Data processing purposes:Analysis of website usage, use of this information to serve tailored ads on LinkedIn (retargeting)

Categories of personal data:Device and browser properties, IP address, referrer URL and timestamps

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • LinkedIn Ireland Unlimited Company

Third country transfer:We do not transfer your personal data to third countries. With regard to the transfer of your personal data to third countries by LinkedIn, we refer to their privacy policy: https://www.linkedin.com/legal/privacy-policy

Validity period of the cookie:12 months

Data processing purposes:Evaluation of website usage, campaign performance measurement. Google Ads uses data to place adverts placed by Gira on websites, social media platforms, in search results and other digital platforms and to measure the success of advertising campaigns.

Categories of personal data:IP address, browser information, website visited, date and time of visit, device information, usage data, click path, geographical location

Legal basis and legitimate interests pursued, if applicable:

  • Use of the service: Section 25(1)(1) TTDSG
  • Subsequent processing of personal data: Article 6(1)(a) GDPR

Recipients:

  • Internal departments, in so far as access is necessary for task fulfilment
  • Google Ireland Ltd, Google LLC (USA)

Third country transfer:

  • Third country: USA
  • Adequacy decision/safeguards/exemption: Standard contractual clauses, copy to be requested via the contact details under Point 1, consent pursuant to Article 49(1)(a) GDPR

Validity period of the cookie:90 days