Youregulate.com | Privacy Policy

Welcome to the Youregulate website. We appreciate your interest in our company. Protection of the personal data you entrust to us is a priority and we want you to feel safe and secure when you visit our website or use our online offers.

In order to fulfill the information obligation towards you as a party interested in our products per to Art. 12, 13 of the General Data Protection Regulation (GDPR), we subsequently present you our information on data protection.


Who is responsible for data processing?
The responsible entity as per data privacy law is

MDSS GmbH
Schiffgraben 41
30175 Hannover
Tel: 0511 6262 8638
Fax: 0511 6262 8633
info@mdssar.com


Which data do we process? And for which purposes?
If we have received data from you, we basically process them only for the purposes for which we have collected them.

As a rule, these purposes are:

  • Internal and external communication   
  • Assertion of legal claims and defense in case of legal disputes 
  • Information on our products and services (customer surveys included), unless you have objected to the use of your data 
  • Invoicing and debiting
  • Statistical evaluation or market analysis

The data are in general:

  • Your master data (e.g. last name, first name, title, address form)    
  • Contact data (e.g. email address, phone number, mobile phone number)   
  •  Transaction data (e.g. IBAN, BIC, billing address)      
  • Data on your request

And other personal data you may provide to us in the course of our mutual (pre)contractual relation.

Please note that we cannot enumerate all potential data. We do, however, collect only data which you actively provide to us, or which are publicly available.

Data processing for other purposes is considered only if the required legal specifications according to Art. 6 Section 4 of the GDPR apply. In such a case, we will naturally fulfill possible information obligations according to Art. 13 Section 3 of the GDPR and Art. 14 Section 4 of the GDPR.


Which legal provisions is this based on?

  •  Data processing based on the consideration of interests (Art. 6 Section 1 lit. f of the GDPR)    
  • Data protection for compliance with a legal obligation (Art. 6 Section 1 lit. c of the GDPR)    
  • Data processing in order to protect the vital interests of the data subject or of another natural person (Art. 6 Section 1 lit. d of the GDPR) 

If personal data is processed based on your consent, you have the right to withdraw your consent at any time, with effect for the future. You can send your withdrawal to the attention of our data protection officer mentioned further below. 

We base our legitimate interest on the communication with contract relevant contact persons, retention of records beyond possible retention times, in order to provide you a consistent documentation, on claims management. We also use your data for marketing and opinion research purposes, in order to find out the interests and inquiries in regards to future products and services. If necessary, we process your data also for assertion of our legal claims and in our defense in case of legal disputes. Furthermore, we make use of the option of direct marketing as per Recital 47 of the GDPR, we pursue a legitimate interest to inform our clients about our services via communication channels, if said clients have actively contacted us in this matter. 

As the affected person, you have the right to object to the processing of your personal data for these purposes, taking into consideration the provisions of Art. 21 of the GDPR.


How long are the data stored?

We process the data for as long as necessary for the respective purpose. 

If legal retention obligations apply – e.g. in commercial law or fiscal law – personal data are stored for the duration of the obligation. Once the retention period has elapsed, we will verify whether the necessity for processing persists. If it no longer applies, the data will be deleted. 


To which recipients do we disclose data?

In principle, we disclose your personal data to third parties (referred to as recipients) only if it is required for the performance of the mutual contract with you, if disclosure is permitted based on a consideration of interests as per Art. 6 Section 1 lit. f of the GDPR, if we are obliged to disclose them, or if you have given your consent. 

Such recipients are for example connected companies – including laboratories –, which provide support with fulfilling the contract, as well as external certification bodies (trade supervision or others, depending on the certification country) which receive data for registration in accordance with the legal provisions. 

Within the scope of the requirements of the fiscal and commercial law, we may also disclose data to consultants such as tax consultants, banks or other tax authorities. 

Third persons in our case do not include service providers and affiliated companies obliged to adhere to our requirements on data protection. For this purpose, we have concluded data processing contracts, and we ensure thereby that you can exercise your rights towards them as well. Such entities are e.g. IT service providers or software system companies for IT applications (e.g. external IT administrators, ERP system producers etc.) and qualified service providers in the area of document destruction.


Information on the provision of personal data

In order to process your inquiries, we are dependent on your information. When processing your inquiries, the processing of the personal data of the data subjects relates to a corresponding contractual relationship or to legal regulations. You do not necessarily have to provide us with data that is not required by a legal regulation and you can object to the processing. When collecting the data, we will draw your attention to which data is required.


Where do we process data?

We process your personal data exclusively in data processing centers within the European Union, thus the Data Protection Regulation applies at all times.

Manufacturers of the products may, however, be located outside the European Union. The data transfer is subject to Art. 49 Section 1 of the GDPR as an individual case.


Matomo

On this website data is collected and stored using the web analysis service software Matomo (www.matomo.org), a service of the provider InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand, ("Mataomo") on the basis of our legitimate interest in the statistical analysis of user behaviour for optimisation and marketing purposes in accordance with Art. 6 Para. 1 lit. f DSGVO. From this data, pseudonymized user profiles can be created and evaluated for the same purpose. Cookies may be used for this purpose. Cookies are small text files that are stored locally in the cache of the visitor's Internet browser. Among other things, the cookies enable the recognition of the Internet browser. The data collected with Matomo technology (including your pseudonymised IP address) is processed on our servers.
The information generated by the cookie in the pseudonymous user profile is not used to personally identify the visitor of this website and is not combined with personal data about the bearer of the pseudonym.
If you do not agree with the storage and evaluation of this data from your visit, you can object to the storage and use of this data at any time. In this case a so-called opt-out cookie is stored in your browser, which means that Matomo does not collect any session data. Please note that the complete deletion of your cookies means that the opt-out cookie is also deleted and may have to be reactivated by you.


Cookies used on our Website

When you enter our website, you will be asked by a banner for your consent to data processing through cookies. The consent refers to the following listed cookies and represents a consent according to Art. 6 (1) lit. a GDPR.

If you make a decision, we set a cookie with you around this decision to store. This cookie bears the name "_pk_id.1.6a50" and is stored for 28 days. After the 28 days have expired, you will have to give your consent again or object to the processing on a new visit.


Social Media Buttons

We also want our website to display information, that we share on social networks on this website and give you the possibility to share out information on your social media accounts. For this we use plugins of the providers of the respective services. If you click on the plugin to share a post over the network, a connection will be established with the respective service. This contribution is then made visible in your user account according to your privacy settings for the service - e.g. only to a certain group of people in the network or publicly.

The default settings of the plugins would immediately transfer your personal data to the social network server when you access the website, regardless of whether you click or tap on the plugin or are registered as a user in the social network. To avoid this, we used the Shariff tool. With Shariff the connection to the server of the service is only established when you click on the plugin.

Shariff is provided by c't and heise online as open source software. More information can be found here: https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html

The legal basis for data processing by social networks after the integration of the Shariff tool is Art. 6 para. 1 lit. a) DSGVO. The use of the plugins for advertising purposes only takes place after your active consent.


We currently use the Twitter button with Shariff: The social plugin of the social network Twitter is used on the website. By clicking on the "Twitter" button, you can share a post with your contacts on Twitter and our current tweets on the website will be displayed.

If you are logged in to your Twitter account when you activate the plugin, the data transferred will be assigned to your user account and the shared post will be displayed there.

Twitter is a service of Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Twitter Inc. is certified under the EU-US Privacy Shield https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active, an agreement that ensures compliance with EU privacy laws. You can access Twitter's privacy statement at the following link: https://twitter.com/en/privacy


Your rights as “data subject”

You have the right to obtain information on the personal data processed by us, as per Art. 15 GDPR. If a request for information is not submitted in writing, please understand that we may request documentation proving your identity. 

Furthermore, you have the right of rectification, erasure or restriction of processing, whenever legally permitted according to Art. 16, 17 and 18 of the GDPR. 

An automated individual decision-making as per Art. 22 of the GDPR does not apply.

Furthermore, you have the right of objection to processing within the scope of the legal provisions. The same applies to the right of data portability. In particular, you have the right of objection according to Art. 21 Section 1 and 2 of the GDPR against processing of your data in connection with Art. 6 Section 1 lit. f of the GDPR. You can file the objection informally to the attention of our data protection officer at the following addresses:


Our data protection officer:

We have designated an external data protection officer for our company. You can reach him/her at the following contact:

FKC CONSULT GmbH
Eschenburgstr. 5
23568 Lübeck
E-Mail: privacy@mdssar.com


Right of appeal

You have the right to complain about the processing of your personal data by our company to a supervisory authority in charge of data protection.

Share your knowledge


Copyright 2020 © MDSS GmbH. All rights Reserved.

We use cookies and other tracking technologies to improve your browsing experience on our website, to analyze our website traffic, and to understand where our visitors are coming from. By browsing our website, you consent to our use of cookies and other tracking technologies.