Data protection

1. Data protection at a glance

General information

The following information offers a straightforward overview of what happens to your personal data when you visit this website. Personal data is all data that enables you to be identified personally. Detailed information on data protection can be found in our

Data collection on this website

Who is responsible for collecting data on this website?

Data is processed on this website by the website operator. Their contact details can be found in the ‘Information on the controller’ section of this privacy policy.

How do we collect your data?

Firstly, your data is collected when you share it with us. This could be data entered into a contact form, for instance.

Other data is collected by our IT systems when you visit our website, which either occurs automatically or with your consent. This is primarily technical data (e.g. your internet browser, operating system or the time of page retrieval). This data is recorded automatically as soon as you access this website.

What do we use your data for?

Some of the data is collected to ensure the error-free provision of the website. Other data can be used to analyse your user behaviour.

What rights do you have over your data?

You have the right to access information on the origin, recipient and purpose of your saved personal data free of charge at any time. You also have the right to request the rectification or erasure of this data. If you have granted consent to data processing, you can withdraw this consent at any time with future effect. Plus, you have the right to request the restriction of the processing of your personal data, under certain circumstances. Furthermore, you have a right to lodge a complaint with the relevant supervisory authority.

You can contact us at any time for more information on these issues and regarding other questions on data protection.

Analysis tools and tools from third-party providers

When you visit this website, your browsing behaviour may be evaluated for statistical purposes. This is primarily undertaken by analysis programs.

Detailed information on these analysis programmes can be found in the following privacy policy.

2. Hosting

External hosting

This website is hosted by an external service provider. The personal data collected on this website is stored on the servers of the hoster. This data could be, primarily, IP addresses, contact enquiries, meta and communication data, contractual data, contact data, names, website accesses and other data generated via a website.

We use a hoster for the purpose of fulfilling contracts towards our potential and existing customers (art. 6 (1) (b) GDPR) and in the interest of the secure, swift and efficient provision of our online offering by a professional provider (art. 6 (1) (f) GDPR). If corresponding consent was sought, processing is solely undertaken on the basis of art. 6 (1) (a) GDPR and section 25 (1) TTDSG, provided the consent relates to the storage of cookies or the accessing of information on the user’s end device (e.g. device fingerprinting) within the meaning of the TTDSG. This consent can be withdrawn at any time.

Our hoster will only process your data to the extent necessary to meet its obligations and will follow our instructions relating to this data.

We use the following hoster:

united-domains AG

Gautinger Straße 10

82319 Starnberg

Commissioned processing

We have concluded a processing agreement with the above provider. This is a contract stipulated under data protection law that ensures this provider only processes the personal data of our website visitors in line with our instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We handle your personal data in confidence and in line with the statutory data protection regulations and this privacy policy.

When you use this website, various pieces of personal data are collected. Personal data is data that enables you to be identified personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purposes this occurs.

We note that the transmission of data on the internet (e.g. during online communication) can be subject to security loopholes. It is not possible to fully protect the data from third-party access.

Information regarding the controller

The controller for data processing on this website is:

BOLD Consulting GmbH
Hammerbrookstraße 93
22097 Hamburg

Phone +49-170-7660987
Email contact@bold.hamburg

The controller is the natural or legal person that makes a decision, whether alone or with others, on the purposes and means of the processing of personal data (e.g. names, email addresses and similar).

Duration of storage

Provided no specific duration of storage is stated within this privacy policy, your personal data will be kept by us until the purpose for the data processing lapses. If you make a justified request for erasure or withdraw your consent to data processing, your data is erased, provided we have no other legally permissible grounds for its storage (e.g. retention periods under tax or commercial law); in this latter case, the data will be erased once these reasons have come to an end.

General information on the legal basis of data processing on this website

If you have consented to data processing, we process your personal data on the basis of art. 6 (1) (a) GDPR or art. 9 (2) (a) GDPR, provided special data categories under art. 9 (1) GDPR are being processed. In the event you have expressly consented to the transmission of personal data to third countries, data is also processed on the basis of art. 49 (1) (a) GDPR. If you have consented to the storage of cookies or the accessing of information on your end device (e.g. device fingerprinting), data processing is also undertaken on the basis of section 25 (1) TTDSG. This consent can be withdrawn at any time. If your data is required for the fulfilment of a contract or to execute pre-contractual measures, we process your data on the basis of art. 6 (1) (b) GDPR. In addition, we process your data, provided this is necessary to fulfil a legal obligation, on the basis of art. 6 (1) (c) GDPR. Data processing can also occur on the basis of our legitimate interest under art. 6 (1) (f) GDPR. The following sections of this privacy policy provide information on the relevant legal bases in each case.

Data protection officer

We have appointed a data protection officer for our company.

BOLD Consulting GmbH
Hammerbrookstraße 93
22097 Hamburg

Phone +49-170-7660987
Email contact@bold.hamburg

Information on the transmission of data to the USA and other third countries

Some of the tools we use are provided by companies based in the USA and other third countries that are not secure under data protection law. If these tools are active, your personal data may be transmitted to these third countries and processed there. We note that it is not possible to guarantee these countries have a level of data protection comparable to that of the EU. For example, US companies are obliged to provide personal data to the security authorities without you, as the data subject, being able to object to this judicially. As a result, it cannot be excluded that US authorities (e.g. secret services) could process, evaluate and permanently store your data on US servers for monitoring purposes. These processing activities are outside our control.

Withdrawal of your consent to data processing

Many data processing activities are only possible with your explicit consent. You can withdraw consent that has been granted at any time. The legality of the data processing performed up to this point shall remain unaffected by the withdrawal.

Right to object to the collection of data in particular cases and to direct advertising (art. 21 GDPR)

IF THE DATA IS PROCESSED ON THE BASIS OF ART. 6 (1) (E) OR (F) GDPR, YOU ALWAYS HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS ON WHICH PROCESSING IS CARRIED OUT CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NOT PROCESS YOUR PERSONAL DATA UNLESS WE CAN PROVE COMPELLING REASONS WORTHY OF PROTECTION FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS, OR UNLESS THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ART. 21 (1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF OPERATING DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA REGARDING YOU FOR THE PURPOSES OF ADVERTISING OF THIS NATURE; THIS ALSO APPLIES TO PROFILING, PROVIDED IT IS CONNECTED TO DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEN NO LONGER BE USED FOR DIRECT ADVERTISING (OBJECTION UNDER ART. 21 (2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of breaches of the GDPR, the data subject is entitled to lodge a complaint with a supervisory authority. In particular, this is the authority in the member state of their usual place of residence, place of work or the place of the alleged breach. The right to lodge a complaint remains regardless of other redress judicially or under administrative law.

Right to data portability

You have the right to have data processed automatically by us on the basis of your consent or to fulfil a contract provided to you or a third party in a common, machine-readable format. If you would like the data to be transferred directly to a different controller, this is only undertaken insofar as it is technically possible.

SSL and TLS encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the operator of this website. You can tell that the connection is encrypted because the address line in your browser changes from ‘http://’ to ‘https://’ and there is a padlock symbol in the address bar.

When SSL/TLS encryption has been activated, the data you send to us cannot be read by third parties.

Access, erasure and rectification

Under the applicable legal provisions, you always have the right to receive access, free of charge, to information on your stored personal data, its origin and recipient and the purpose of data processing, and, if applicable, the right to the rectification or erasure of this data. You can contact us at any time for more information on these issues and regarding other questions on personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time to this end. You have the right to restrict processing in the following instances:

  • if you contest the accuracy of the personal data we have stored, we usually need time to check this. While this check is being carried out, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of its processing instead of its erasure.
  • If we no longer need your personal data but you require it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of its erasure.
  • If you have lodged an objection under art. 21 (1) GDPR, your interests must be weighed up against ours. Until it is clear whose interests predominate, you have the right to request the restriction of the processing of your personal data.
  • If you have restricted the processing of your personal data, this data may only be processed – aside from its storage – with your consent or to assert, exercise or defend against legal claims or to protect the rights of another natural or legal person or for important reasons in the public interest relating to the European Union or a member state.

4. Data collection on this website:

Cookies

Our websites use ‘cookies’. Cookies are small text files; they do not damage your end device. They are either stored on your end device temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.

Sometimes, cookies from third-party companies may be stored on your end device when you access our website (third-party cookies). They enables us or you to use certain third-party services (e.g. cookies for processing payment services).

Cookies fulfil various functions. Numerous cookies are technically necessary as certain website features would not work without them (e.g. the shopping basket feature or video playback). Other cookies serve to evaluate user behaviour or display advertising.

Cookies required to implement electronic communication processes, to provide certain features desired by you (e.g. the shopping basket feature) or to optimise the website (e.g. cookies for measuring the web audience), known as necessary cookies, are stored on the basis of art. 6 (1) (f) GDPR, provided there is no other legal basis stated. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimised provision of its services. If there is consent to the storage of cookies and comparable recognition technologies, the processing is solely undertaken on the basis of this consent (art. 6 (1) (a) GDPR and section 25 (1) TTDSG); this consent may be withdrawn at any time.

You can adjust your browser settings so you are informed about the storage of cookies and only permit cookies in individual situations, exclude the acceptance of cookies in particular circumstances or in general and activate the automatic deletion of cookies when you close your browser. The functionality of this website may be impaired when you deactivate cookies.

If third-party or analysis cookies are used, we will inform you about this separately in this privacy policy and ask for your consent if required.

Consent with Borlabs Cookie

Our website uses Borlabs Cookie’s consent technology to collect your consent to the storage of certain cookies in your browser or to the use of particular technologies and document this in compliance with data protection. This technology is provided by Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg (hereinafter ‘Borlabs’).

When you access our website, a Borlabs cookie is stored in your browser. This cookie stores the consent you grant or the withdrawal of this consent. This data is not disclosed to the provider of Borlabs Cookie.

Once recorded, the data is stored until you ask us to erase it or delete the Borlabs cookie itself, or the purpose of the data storage lapses. Mandatory statutory retention periods remain unaffected by this. Details on data processing by Borlabs Cookie can be found at https://borlabs.io/kb/what-information-does-borlabs-cookie-store/.

Borlabs Cookie consent technology is used to seek the legally required consent for the use of cookies. The legal basis for this is art. 6 (1) (c) GDPR.

Contact form

If you send us an enquiry via the contact form, your details from the enquiry form, including the contact data provided there, will be stored by us to process the enquiry and in the event of follow-up questions. We do not disclose this data without your consent.

This data is processed on the basis of art. 6 (1) (b) GDPR, provided your enquiry is connected to the fulfilment of a contract or is required to implement pre-contractual measures. In all other instances, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (art. 6 (1) (f) GDPR) or on your consent (art. 6 (1) (a) GDPR), provided this was requested; this consent can be withdrawn at any time.

The details stated by you in the consent form are kept by us until you request their erasure, you withdraw your consent to this storage or the purpose of data processing lapses (e.g. once your enquiry has been processed). Mandatory statutory provisions – in particular, retention periods – remain unaffected by this.

Enquiries made by email, phone or fax

When you contact us by email, phone or fax, your enquiry and all the associated personal data (name, enquiry) will be stored by us and processed for the purposes of handling your enquiry. We do not disclose this data without your consent.

This data is processed on the basis of art. 6 (1) (b) GDPR, provided your enquiry is connected to the fulfilment of a contract or is required to implement pre-contractual measures. In all other instances, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (art. 6 (1) (f) GDPR) or on your consent (art. 6 (1) (a) GDPR), provided this was requested; this consent can be withdrawn at any time.

The details stated by you in your contact enquiry are kept by us until you request their erasure, you withdraw your consent to this storage or the purpose of data processing lapses (e.g. once your enquiry has been processed). Mandatory statutory provisions – in particular, statutory retention periods – remain unaffected by this.

5. Plugins and tools

Google Web Fonts (local hosting)

This page uses web fonts, provided by Google, for the uniform depiction of fonts. Google Fonts are installed locally, without a connection being made to Google’s servers.

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy.

Google Maps

This website uses the map service Google Maps. This is provided by Google Ireland Limited (‘Google’), Gordon House, Barrow Street, Dublin 4, Ireland.

It is necessary to store your IP address so you can use the functions of Google Maps. This information is normally transmitted to a Google server in the USA and stored there. This data transfer is out of the control of the provider of this website. When Google Maps is activated, Google can use Google Web Fonts for the purpose of the uniform depiction of fonts. When you access Google Maps, your browser loads the necessary Web Fonts to your browser cache so it can display text and fonts correctly.

The use of Google Maps is in the interests of an appealing depiction of our online offering and of the ease of finding the places we state on the website. This represents a legitimate interest within the meaning of art. 6 (1) (f) GDPR. If corresponding consent was sought, processing is solely undertaken on the basis of art. 6 (1) (a) GDPR and section 25 (1) TTDSG, provided the consent relates to the storage of cookies or the accessing of information on the user’s end device (e.g. device fingerprinting) within the meaning of the TTDSG. This consent can be withdrawn at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information about the handling of user data can be found in Google’s privacy policy: https://policies.google.com/privacy.

Google reCAPTCHA

We use ‘Google reCAPTCHA’ (hereinafter ‘reCAPTCHA’) on this website. This is provided by Google Ireland Limited (‘Google’), Gordon House, Barrow Street, Dublin 4, Ireland.

reCAPTCHA serves to check whether data is being entered on this website (e.g. in a contact form) by a human or an automated program. To this end, reCAPTCHA analyses the behaviour of the website visitor using various characteristics. The analysis starts automatically as soon as the website visitor accesses the website. reCAPTCHA evaluates various pieces of information for this analysis (e.g. IP address, duration that the website visitor spent on the website or mouse movements by the user). The data recorded during the analysis is forwarded to Google.

The reCAPTCHA analyses run fully in the background: website visitors are not informed that an analysis is taking place.

The data is stored and analysed on the basis of art. 6 (1) (f) GDPR. The website operator has a legitimate interest in protecting its web offering from abusive automated spying and spam. If corresponding consent was sought, processing is solely undertaken on the basis of art. 6 (1) (a) GDPR and section 25 (1) TTDSG, provided the consent relates to the storage of cookies or the accessing of information on the user’s end device (e.g. device fingerprinting) within the meaning of the TTDSG. This consent can be withdrawn at any time.

Further information about Google reCAPTCHA can be found in Google’s privacy policy and Google’s terms of use via the following links:https://policies.google.com/privacy und https://policies.google.com/terms?hl=en.

iThemes Security

We have integrated iThemes Security into this website. The provider is iThemes Media LLC, 1720 South Kelly Avenue Edmond, OK 73013, USA (hereinafter ‘iThemes Security’).

iThemes Security serves to protect our website from undesired access or malicious cyber attacks. To this end, iThemes Security collects data including your IP address, the time and source of login attempts and log data (e.g. the browser used). iThemes Security is installed locally on our servers.

iThemes Security transmits the IP addresses of repeated attackers to iThemes’ central database in the USA (network brute force protection) to prevent attacks of this nature in the future.

iThemes Security is used on the basis of art. 6 (1) (f) GDPR. The website operator has a legitimate interest in protecting its website as effectively as possible against cyber attacks. If corresponding consent was sought, processing is solely undertaken on the basis of art. 6 (1) (a) GDPR and section 25 (1) TTDSG, provided the consent relates to the storage of cookies or the accessing of information on the user’s end device (e.g. device fingerprinting) within the meaning of the TTDSG. This consent can be withdrawn at any time.

Ereacht - bold