1. Controller and Data Protection Officer
Controller under the GDPR
LyconSys GmbH & Co.KG
Hildegardstr. 12A
61231 Bad Nauheim
Germany
Tel.: +49-(0)69-380 979 418 0
E-Mail: info@lyconsys.com
Data Protection Officer
E-Mail: datenschutz@lyconsys.com
2. General Information on Data Processing
We process personal data of our users only insofar as this is necessary for the provision of a functional website and our content and services. The processing of personal data is generally carried out only with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of data is permitted by legal provisions.
3. Your Rights as a Data Subject
You have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR): You may request information about the personal data we process concerning you.
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate or the completion of your personal data stored by us.
- Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data stored by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
- Right to restriction of processing (Art. 18 GDPR): You may request the restriction of the processing of your personal data.
- Right to data portability (Art. 20 GDPR): You may request to receive the personal data you have provided in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Right to object (Art. 21 GDPR): You may object at any time to the processing of your personal data where processing is based on Art. 6(1)(e) or (f) GDPR.
- Right to withdraw consent (Art. 7(3) GDPR): You may withdraw your consent at any time. The lawfulness of processing based on consent before its withdrawal is not affected.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR.
The supervisory authority responsible for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Phone: +49 611 1408-0
E-Mail: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
4. Provision of the Website and Creation of Server Log Files
Description and scope of data processing
When you access our website, our web hosting provider’s system (IONOS / 1&1) automatically collects data and information from the requesting computer. The following data is collected:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the requested file
- Website from which the access was made (referrer URL)
- Browser used and, if applicable, the operating system of your computer and the name of your access provider
- Amount of data transferred
- HTTP status code
Legal basis
The legal basis for the temporary storage of data and log files is Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in ensuring the functionality of the website, optimising the website and ensuring the security of our IT systems.
Storage period
The data is deleted as soon as it is no longer required for the purpose for which it was collected. Server log files are automatically deleted after 30 days at the latest.
5. Contact Form
Description and scope of data processing
Our website has a contact form that can be used for electronic contact. If a user uses this option, the data entered in the input mask is transmitted to us and stored. This typically includes:
- Name
- Email address
- Message content
- IP address of the sender
- Date and time of submission
The data is transmitted via PHP-based processing on the server of our web hosting provider (IONOS / 1&1).
Your consent is obtained for the processing of the data during the submission process, and reference is made to this privacy policy.
Legal basis
The legal basis for the processing of data is Art. 6(1)(a) GDPR when consent has been given. If the contact is made for the performance of a contract or for pre-contractual measures, Art. 6(1)(b) GDPR is an additional legal basis.
Purpose of data processing
The processing of personal data from the input mask serves solely to process the contact enquiry.
Storage period
The data is deleted as soon as it is no longer required for the purpose for which it was collected. For personal data from the contact form input mask, this is the case when the respective conversation with the user has ended and no statutory retention obligations stand in the way. The conversation is deemed to have ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.
6. Contact by Email
Description and scope of data processing
Contact can also be made via the email addresses provided on our website. In this case, the user’s personal data transmitted with the email will be stored. The data is used exclusively for processing the conversation.
Legal basis
The legal basis for the processing of data is Art. 6(1)(f) GDPR (legitimate interest in processing enquiries). If the email contact aims at the conclusion of a contract, Art. 6(1)(b) GDPR is an additional legal basis.
7. Cookies
Description and scope of data processing
Our website uses cookies. Cookies are text files that are stored in or by the internet browser on the user’s computer system.
We distinguish between technically necessary cookies, which are required for the basic functions of the website, and optional cookies (e.g. for analysis purposes).
Technically necessary cookies are set on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in storing these cookies for the technically error-free and optimised provision of our website.
Optional cookies (e.g. analysis cookies from Google Analytics) are only set with your express consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our cookie consent banner.
Objection options
You can set your browser to inform you about the setting of cookies, to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser.
8. Google Analytics
Description and scope of data processing
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
IP anonymisation: We have activated the IP anonymisation function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission to the USA.
Data processed: Anonymised IP address, pages visited, duration of visit, browser and operating system used, referrer, device type and screen resolution.
Legal basis
The use of Google Analytics is based on your express consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the cookie consent banner.
Data transfer to third countries
In connection with Google Analytics, data may be transferred to the USA. Google LLC is certified under the EU-US Data Privacy Framework. Further information on data protection at Google can be found at: https://policies.google.com/privacy
Data processing agreement
We have concluded a data processing agreement with Google.
Objection options
You can prevent Google Analytics from collecting your data by:
- Refusing or withdrawing your consent via the cookie consent banner
- Installing the Google browser add-on to disable Google Analytics: https://tools.google.com/dlpage/gaoptout
- Disabling cookies in your browser (see section “Cookies”)
Storage period
The data sent by us and linked to cookies is automatically deleted after 14 months. Deletion of data whose retention period has been reached takes place automatically once a month.
9. Web Hosting
Our website is hosted by IONOS (1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur). This service provider processes your personal data on our behalf. Processing is based on Art. 6(1)(f) GDPR and Art. 28 GDPR (data processing agreement).
For details, please refer to the IONOS privacy policy: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
10. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.
11. Amendment of this Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy. The new privacy policy will then apply to your next visit.
12. Questions to the Data Protection Officer
If you have any questions about data protection, please contact us by email at: datenschutz@lyconsys.com