Privacy Policy for the Use of the Website

Privacy policy

1) Introduction and contact details of the data controller

1.1 NTC Oberstdorf Sport Entertainment GmbH attaches great importance to the protection and security of your personal data. We therefore inform you in this privacy policy about the type, scope and purpose of the processing of personal data on our website. Personal data is all information that relates to an identified or identifiable natural person. It therefore includes all data by which you can be personally identified, such as name, address or email address.

Processing is any operation or set of operations in connection with personal data, such as the collection, storage, use or deletion of data. The processing can be carried out with or without the aid of automated procedures.

1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is NTC Oberstdorf Sport und Entertainment GmbH, Nebelhornstr. 67, 87561 Oberstdorf, Germany, Tel.: 08322989601, E-Mail: info@ntc-oberstdorf.de. The controller of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

2) General information on data collection when visiting our website

2.1 If you use our website for information purposes, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of transmitted data in bytes
  • Source/reference from which you accessed the site
  • Used browser
  • Operating system used
  • Used IP address (possibly in anonymous form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. A transfer or other use of the data does not take place. However, we reserve the right to retrospectively check the server logfiles should concrete evidence point to unlawful use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the person responsible), this website uses an SSL or. TLS encryption. You can recognize an encrypted connection by the character string "https: //" and the lock symbol in your browser line.

3) hosting

Our website includes tools from companies based in the USA. If these tools are active, your personal data may be passed on to the US servers of the respective companies. We would like to point out that the USA is not a safe third country within the meaning of EU data protection law. US companies are obliged to release personal data to security authorities without you as the data subject being able to take legal action against this. It cannot therefore be ruled out that US authorities (e.g. secret services) will process, evaluate and permanently store your data on US servers for surveillance purposes. We have no influence on these processing activities. (Source: https://www.e-recht24.de)

We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

4) Cookies

In order to make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your device. Some of these cookies are automatically deleted when the browser is closed (so-called "session cookies"), some of these cookies remain longer on your device and allow you to save page settings (so-called "persistent cookies"). In the latter case, you can see the storage duration in the overview of the cookie settings in your web browser.

If personal data is also processed by individual cookies we use, the processing takes place in accordance with Art. 6 Paragraph 1 lit. b GDPR either for the execution of the contract, in accordance with Art. 6 Paragraph 1 lit. According to Art. 6 Para. 1 lit.f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.

You can set your browser so that you are informed about the setting of cookies and individually decide whether to accept them or to exclude the acceptance of cookies for certain cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

5) contact us

When contacting us (e.g. via contact form or email), personal data is processed – exclusively for the purpose of processing and answering your request and only to the extent required for this.

The legal basis for the processing of this data is our legitimate interest in answering your request in accordance with Article 6 (1) (f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted if it can be inferred from the circumstances that the facts in question have been finally clarified and provided that there are no legal storage obligations to the contrary.

6) Data processing when opening a customer account

In accordance with Article 6 Paragraph 1 Letter b GDPR, personal data will continue to be collected and processed to the extent required in each case if you provide it to us when opening a customer account. The data required for opening an account can be found in the input mask of the corresponding form on our website.

A deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. After your customer account has been deleted, your data will be deleted provided that all contracts concluded have been completed, there are no legal retention periods to the contrary and we have no legitimate interest in further storage.

7) Use of customer data for direct advertising

7.1 Registration for our e-mail newsletter

If you sign up for our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing further data is voluntary and is used to address you personally. To send the newsletter, we use the so-called double opt-in procedure, which ensures that you only receive the newsletter once you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the email address provided.

By activating the confirmation link, you give us your consent to the use of your personal data in accordance with Article 6 (1) (a) GDPR. We store your IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace possible misuse of your e-mail address at a later point in time. The data we collect when registering for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a message to the person responsible mentioned at the beginning. After you have unsubscribed, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we will inform you in this declaration.

7.2 Sending the e-mail newsletter to existing customers

If you have provided us with your e-mail address when purchasing goods or services, we reserve the right to regularly send you offers for goods or services from our range by e-mail that are similar to those you have already purchased. According to Section 7 (3) UWG, we do not have to obtain your separate consent for this. In this respect, data processing takes place solely on the basis of our legitimate interest in personalized direct advertising in accordance with Article 6 (1) (f) GDPR. If you initially objected to the use of your e-mail address for this purpose, we will not send you an e-mail.

You are entitled to object to the use of your e-mail address for the aforementioned advertising purpose at any time with effect for the future by notifying the person responsible named at the beginning. For this, you only incur transmission costs according to the basic tariffs. After receipt of your objection, the use of your e-mail address for advertising purposes will be stopped immediately.

8) Data processing for order processing in the online shop

8.1 Insofar as it is necessary for the execution of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Article 6 (1) (b) GDPR.

If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we process the contact details you provided when ordering (name, address, e-mail address) in order to meet our statutory information requirements in accordance with Art. 6 Para . 1 lit. c GDPR personally using a suitable means of communication (e.g. by post or email) about upcoming updates in the legally stipulated period. Your contact details will be used strictly for the purpose of notifications about updates we owe and will only be processed by us for this purpose to the extent necessary for the respective information.

In order to process your order, we also work together with the following service provider (s) who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.

8.2 Use of payment service providers (payment services)

- Mollie

One or more online payment methods from the following provider are available on this website: Mollie BV, Keizersgracht 313, 1016 EE Amsterdam, Netherlands

If you select a payment method from the provider where you pay in advance (e.g. credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) and information about the content of your order will be sent to them passed on in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be passed on for the purpose of payment processing with the provider and only to the extent that it is necessary for this.
- Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg

If you select a payment method from the provider where you pay in advance, the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order in accordance with Art. 6 Paragraph 1 lit. b GDPR passed on. In this case, your data will only be passed on for the purpose of payment processing with the provider and only to the extent that it is necessary for this.

If you select a payment method for which we pay in advance, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, e-mail address, telephone number, data if applicable) during the ordering process an alternative means of payment).

In order to safeguard our legitimate interest in determining your solvency in such cases, we will forward this data to the provider for the purpose of a credit check in accordance with Article 6 (1) (f) GDPR. Based on the personal data you provide and other data (e.g. shopping cart, invoice amount, order history, payment history), the provider checks whether the payment option you have selected can be granted with regard to payment and/or bad debt risks.

The credit report can contain probability values ​​(so-called score values). As far as score values ​​are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values ​​includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

9) Transfer of personal data to third parties

9.1 Personal data will only be passed on to third parties or processors in the following cases:

  • There is a legal permission or legal obligation to pass on the data.
  • The transfer of data is necessary to fulfill a contract in accordance with Art. 6 (1) (b) GDPR.
  • You have expressly consented to the transfer of data.
  • We have a legitimate interest in passing on the data in accordance with Art. 6 (1) (f) GDPR.

Art. 6 (1) (f) GDPR in conjunction with Art. 28 GDPR (conclusion of a contract for data processing) also forms the basis for web hosting. The use of hosting services from our Internet service provider serves to provide and ensure the secure and error-free operation of our website. For this purpose, we or our web hosting provider process personal master data, inventory data, communication data, usage data, contract master data and content data from customers, interested parties and visitors to our pages.

Any transfer of personal data within the framework of commissioning third parties by means of a contract processing agreement is carried out on the basis of Art. 28 GDPR.

9.2 Transfer to Wintersteiger AG

The booking system for winter sports equipment integrated into the site comes from the following provider: WINTERSTEIGER AG, Johann-Michael-Dimmelstraße 9, 4910 Ried im Innkreis, Austria. This system does not run on our website, but on the provider's website, which is protected by SSL encryption.

Personal data is collected during the booking process. This specifically includes name, address, telephone number, email address, date of birth, information on height, weight, driving ability, booking period and, if applicable, payment information (e.g. PayPal account, Wirecard QPay). The information provided during the booking process is used exclusively to simplify your booking, for administrative purposes and to process the contract.

The legal basis for the processing or transmission of your data is Art. 6 Para. 1 lit. b, f GDPR.

No data will be passed on to third parties, with the exception of WINTERSTEIGER AG.

Further information about the provider and its privacy policy can be found at the following address: https://www.wintersteiger.com/de/Unternehmen/Datenschutz

10) web analytics services

10.1 google analytics 4

This website uses Google Analytics 4, a web analysis service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, when you visit the website, Google Analytics sets 4 cookies, which are stored as small text modules on your end device and collect certain information. The scope of this information also includes your IP address, which, however, is shortened by Google by the last digits in order to exclude direct personal reference.

The information is transmitted to Google servers and processed there. Transmissions to Google LLC based in the USA are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, to compile reports on website activity for us and to provide other services related to website activity and internet usage. The shortened IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The data collected as part of the use of Google Analytics 4 is stored for a period of two months and then deleted.

All of the processing described above, in particular the setting of cookies on the end device used, only takes place if you have given us your express consent in accordance with Article 6 (1) (a) GDPR.
Without your consent, Google Analytics 4 will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have concluded an order processing contract with Google, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

Further legal information on Google Analytics 4 can be found at https://policies.google.com/privacy?hl=de&gl=de and under https://policies.google.com/technologies/partner-sites

Demographics
Google Analytics 4 uses the special "demographic characteristics" function and can use this to create statistics that make statements about the age, gender and interests of site visitors. This is done by analyzing advertising and information from third parties. This allows target groups to be identified for marketing activities. However, the collected data cannot be assigned to a specific person and will be deleted after being stored for a period of two months.

Google signals
As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have activated personalized ads and linked your devices to your Google account, Google can analyze your usage behavior across devices and database models, including cross-devices, subject to your consent to the use of Google Analytics in accordance with Article 6(1)(a) GDPR conversions, create. We do not receive any personal data from Google, only statistics. If you want to stop the cross-device analysis, you can disable the "Personalized advertising" function in your Google account settings. To do this, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de For more information about Google Signals, see the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs
As an extension to Google Analytics 4, the “UserIDs” function can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Article 6(1)(a) GDPR, have set up an account on this website and log in to this account on different devices, your activities, including conversions, can be analyzed across devices become.

For data transfers to the USA, the provider has joined the EU-US data protection framework (EU-US Data Privacy Framework), which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

10.2 Google Tag Manager

This website uses the "Google Tag Manager", a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and being able to calibrate, control and attach conditions via a uniform user interface. The Google Tag Manager itself does not store or read any information on user devices. The service also does not carry out any independent data analyses. However, the Google Tag Manager transmits your IP address to Google when the page is accessed and may store it there. Also a transmission to servers of Google LLC. In the US it is possible.

This processing will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US data protection framework (EU-US Data Privacy Framework), which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

Further legal information on Google Tag Manager can be found at https://policies.google.com/privacy?hl=de&gl=de

11) Retargeting/ remarketing and conversion tracking

Google Ads conversion tracking

This website uses the online advertising program "Google Ads" and, as part of Google Ads, conversion tracking by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers with the help of advertising material (so-called Google Adwords) on external websites. In relation to the data of the advertising campaigns, we can determine how successful the individual advertising measures are. We are pursuing the goal of showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of the advertising costs incurred.

The conversion tracking cookie is set when a user clicks on an Ads ad placed by Google. Cookies are small text files that are stored on your device. These cookies usually lose their validity after 30 days and are not used for personal identification. If the user visits certain pages on this website and the cookie has not yet expired, we and Google can see that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. This means that cookies cannot be tracked via the websites of Google Ads customers. The information obtained using the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. The customers find out the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information with which users can be personally identified. When using Google Ads, personal data may also be transmitted to the servers of Google LLC. come in the US.

Details on the processing initiated by Google Ads Conversion Tracking and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

You can also permanently object to the setting of cookies by Google Ads Conversion Tracking by downloading and installing the browser plug-in from Google available under the following link:
https://www.google.com/settings/ads/plugin?hl=de

Please note that certain functions of this website may not be used or may only be of limited use if you have deactivated the use of cookies.
Google's privacy policy can be viewed here: https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU-US data protection framework (EU-US Data Privacy Framework), which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12) Page functionalities

12.1 Google Customer Reviews (formerly Google Certified Dealer Program)

We work with Google through the Google Customer Reviews program. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This program gives us the opportunity to collect customer reviews from users of our website. After making a purchase on our website, you will be asked whether you would like to take part in a Google email survey.

If you give your consent in accordance with Article 6(1)(a) GDPR, we will transmit your email address to Google. You will receive an email from Google Customer Reviews asking you to rate the shopping experience on our website. The review you submit will then be aggregated with our other reviews and displayed on our Google Customer Reviews logo and on our Merchant Center dashboard. Your rating will also be used for Google seller ratings. As part of the use of Google customer reviews, personal data may also be transmitted to the servers of Google LLC. come in the US.

You can revoke your consent at any time by sending a message to the Data Controller or to Google.

For data transfers to the USA, the provider has joined the EU-US data protection framework (EU-US Data Privacy Framework), which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12.2 Online applications using a form

On our website, we advertise current vacancies in a separate section, for which interested parties can apply using the appropriate form.

Applicants must provide all personal data necessary for an informed assessment, including general information such as name, address and contact details, as well as proof of performance and, where appropriate, health-related information. Details on the application can be found in the job advertisement.

In the course of sending the form, the applicant data is transmitted to us in encrypted form in accordance with the state of the art, stored by us and evaluated exclusively for the purpose of processing the application. The processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR (or Section 26 Para. 1 BDSG), in the sense of which going through the application process is considered to be the initiation of an employment contract.

Insofar as special categories of personal data within the meaning of Article 9 (1) GDPR (e.g. health data such as information on the severely disabled) are requested from applicants, processing takes place in accordance with Article 9 (2) lit. b. GDPR, so that we can exercise the rights arising from labor law and social security and social protection law and fulfill our obligations in this regard.

Cumulatively or alternatively, the processing of the special data categories may also be based on Art. 9 para. 1 lit. h DSGVO if it is used for health or occupational health purposes, for assessing the applicant's ability to work, for medical diagnosis, care or treatment in the health or social sector or for the administration of systems and services in the health or social sector he follows.

If the applicant is not selected or if an applicant withdraws his application prematurely, his data submitted in the form and all electronic correspondence, including the application email, will be deleted after 6 months at the latest after notification. This period is based on our legitimate interest in answering any follow-up questions about the application and, if necessary, in being able to meet our obligations to provide evidence from the regulations on the equal treatment of applicants.

In the event of a successful application, the data provided will be processed on the basis of Article 6 (1) (b) GDPR (when processed in Germany in conjunction with Section 26 (1) BDSG) for the purpose of carrying out the employment relationship.

12.3 Matterport

The legal basis for the data transfer to Matterport Inc. is your consent in accordance with Art. 6 (1) a GDPR. This may also mean a transfer of personal data to a country outside the European Union. The data is transferred on the basis of your consent in accordance with Art. 6 Para. 1 lit a in conjunction with Art. 49 Para. 1 lit a GDPR. For email contact with the data protection officer of Matterport Inc.: https://matterport.com/de/node/44. Duration of processing: is variable and ends when the purpose of processing no longer applies.

13) rights of the person concerned

13.1 The applicable data protection law grants you the following rights of data subjects (information and intervention rights) vis-à-vis the person responsible with regard to the processing of your personal data, whereby reference is made to the stated legal basis for the respective exercise requirements:

  • Right to information in accordance with Art. 15 GDPR;
  • Right to rectification in accordance with Art. 16 GDPR;
  • Right to deletion in accordance with Art. 17 GDPR;
  • Right to restriction of processing in accordance with Art. 18 GDPR;
  • Right to information in accordance with Art. 19 GDPR;
  • Right to data portability in accordance with Art. 20 GDPR;
  • Right to revoke consent given in accordance with Art. 7 Para. 3 GDPR;
  • Right to lodge a complaint in accordance with Art. 77 GDPR.

 

14) Duration of storage of personal data

The data is stored taking into account statutory retention periods, in particular tax and commercial law retention periods. After the deadline has expired, the data will be deleted if it is no longer required to fulfill or initiate a contract and you have not consented to further processing and use.