Legal information

Privacy policy

This policy explains how Telemarie processes personal data on its website, through connected services and in connection with the Telemarie device.

1. Privacy and controller details

In accordance with applicable data-protection law, particularly the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and the EU General Data Protection Regulation (GDPR), this policy explains the nature, scope and purposes of our processing of personal data. It also applies to our websites and social-media profiles. Terms such as ‘personal data’ and ‘processing’ have the meanings given in Article 4 GDPR.

The controller within the meaning of Article 4(7) GDPR is Telemarie UG (haftungsbeschränkt), Schudomastrasse 48, 12055 Berlin, Germany; Managing Director: Jan Helwich; email: info@telemarie.de.

2. Types of data, purposes and categories of data subjects

Types of data processed

We process usage data such as access times and pages visited, master data such as names and addresses, and contact details such as telephone numbers, email addresses and fax numbers.

Purposes under Article 13(1)(c) GDPR

We process data to support commercial use of the website, make the website user-friendly, conduct marketing, sales and advertising, provide customer service and customer care, and respond to contact enquiries.

Categories of data subjects under Article 13(1)(e) GDPR

Data subjects include website visitors and users and prospective customers. They are collectively referred to as ‘users’ in this policy.

4. Disclosure to third parties and processors

As a rule, we do not disclose personal data to third parties without your consent. Where disclosure occurs, it is based on one of the legal bases described above—for example, disclosure to an online payment provider to perform a contract, in response to a court order, or to comply with a legal duty relating to criminal prosecution, prevention of danger or enforcement of intellectual-property rights.

We also use processors, such as external providers that host our websites or databases. Transfers to processors under a data-processing agreement are made in accordance with Article 28 GDPR. We select processors carefully, review them regularly, retain the right to issue instructions concerning the data, and require appropriate technical and organisational measures and compliance with the BDSG and GDPR.

5. Transfers to third countries

Most processing is carried out by organisations subject to the GDPR. Where third-party services process data outside the European Union or European Economic Area, the requirements of Articles 44 et seq. GDPR must be met. Processing is therefore based on safeguards such as an adequacy decision recognised by the European Commission or approved Standard Contractual Clauses.

Where, following the invalidation of the former Privacy Shield, we seek your explicit consent under Article 49(1)(a) GDPR for a transfer to the United States, we draw attention to the risk of undisclosed access by US authorities and use for surveillance purposes, potentially without an effective legal remedy for EU citizens.

6. Deletion and retention periods

Unless this policy states otherwise, personal data is deleted or blocked when consent is withdrawn, the purpose of storage ceases to apply, or the data is no longer required for that purpose—unless further retention is required as evidence or by statutory retention duties. These include retention of business correspondence for six years under section 257(1) of the German Commercial Code (HGB) and accounting records for ten years under section 147(1) of the German Fiscal Code (AO). When the applicable period expires, the data is blocked or deleted unless it remains necessary to enter into or perform a contract.

We do not use automated decision-making or profiling.

7. Website provision and server log files

If you use our website for information only and do not register or otherwise submit information, we collect only the personal data transmitted by your browser to our server.

Data collected

  • IP address and internet service provider.
  • Date and time of access.
  • Browser type, language and browser version.
  • Requested content, time zone and access or HTTP status code.
  • Volume of data transferred and referring website.
  • Operating system.

We do not combine this data with your other personal data. It is used to provide a functional, secure and user-friendly website, optimise its functions and content, and perform statistical evaluation. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.

For security purposes, the German source states that this data is stored in server log files for a period measured in days but does not specify the number of days. It is then deleted automatically unless retention is needed as evidence of an attack on the server infrastructure or another legal infringement.

8. Cookies

We use cookies when you visit our website. Cookies are small text files stored by your browser. When you return, they provide information that can recognise your browser automatically. Cookies may also contain user IDs stored in pseudonymous profiles. When you visit, we provide information about the use of cookies, how you can object and how you can prevent storage.

Cookie categories

Essential cookies are strictly necessary to operate the website or store functions such as login, basket contents, user input or the selected website language. Session cookies recognise repeated use during a session, for example login status, and are deleted when you close the browser or log out. Persistent cookies remain after the browser is closed and may be used for login storage, audience measurement and marketing; they are deleted automatically after a period that varies by cookie. Third-party cookies may be set by external providers, particularly advertisers.

You can configure your browser to reject third-party or all cookies. If you do so, some website functions may be unavailable. Details about third-party cookies appear in the relevant providers’ privacy policies.

Data, purposes and legal bases

Cookie-related data may include user data, cookie identifiers, user IDs, pages visited, device information, access times and IP addresses. We use it to optimise our web services technically and commercially and to provide easier and more secure access. Consent-based cookies rely on Article 6(1)(a) GDPR. Essential processing may rely on our legitimate interests under Article 6(1)(f) GDPR, and cookies used to initiate a contract, such as for an order, may rely on Article 6(1)(b) GDPR.

Retention, deletion and opt-out

Data is deleted when no longer required for the purpose for which it was collected. Session data used to provide the website is deleted when the session ends. You can disable or limit cookies in your browser and delete existing cookies at any time, including automatically. Disabling cookies may limit website functionality.

Browser guidance: Chrome: https://support.google.com/chrome/answer/95647; Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac; Firefox: https://support.mozilla.org/kb/clear-cookies-and-site-data-firefox; Microsoft Edge: https://support.microsoft.com/windows/delete-and-manage-cookies.

You can also object to third-party advertising cookies through https://optout.aboutads.info or http://www.youronlinechoices.com.

9. Analytics and marketing measurement

We load analytics and marketing services only after you consent to the relevant category in the cookie banner. Without consent, only necessary functions remain active.

If you allow statistics, we use Matomo Cloud (InnoCraft Ltd., New Zealand) and Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to understand which pages, content and functions help visitors. Processing may include technical usage data, pages visited, referrers, campaign parameters, device data and interactions such as calls-to-action, scroll depth, FAQ openings, video starts, checkout starts and pseudonymous order-success signals.

If you allow marketing, we use Meta Pixel (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland) to measure the effectiveness of advertising and campaigns. Processing may include page views, campaign parameters and interactions such as clicks on ordering or consultation areas.

The legal basis is consent under Article 6(1)(a) GDPR. You may change your choice at any time using the ‘Cookies’ button or reset it by opening the page with the parameter ?cookie-reset=1.

10. Contact by form, email, fax or post

When you contact us through a form, by fax, post or email, we process the information you provide to handle the enquiry.

Where you have consented, the legal basis is Article 6(1)(a) GDPR. Otherwise, processing of contact enquiries, emails, letters and faxes relies on our legitimate interest under Article 6(1)(f) GDPR in answering enquiries, retaining evidence for liability purposes and complying with retention duties for business correspondence. If the contact concerns entering into a contract, Article 6(1)(b) GDPR also applies.

We may store the enquiry and contact details in a customer-relationship-management system or comparable system. Data is deleted when it is no longer required, generally when the conversation is complete and the matter has been conclusively resolved. Enquiries from users with an account or contract are retained for up to two years after the contract ends. Statutory archival duties may require six years’ commercial-law retention or ten years’ tax-law retention.

You may withdraw consent under Article 6(1)(a) GDPR at any time. If you contact us by email, you may also object to storage of your personal data at any time.

11. Payment processing through Stripe

We use Stripe to process orders and rental payments. For customers in the EEA, the provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Checkout is completed on a Stripe-hosted page, including checkout.telemarie.de.

Stripe processes master data such as name and address, contact details, contract and order data, and payment data such as card details, IBAN or SEPA mandate and PayPal identifier. You enter payment data directly with Stripe. We do not receive complete payment credentials; we receive only information needed to perform the contract, such as payment confirmation. Stripe also processes data for fraud prevention.

Purposes are payment processing, performance of the rental agreement, fraud prevention and compliance with legal obligations, particularly commercial and tax law. The legal bases are Article 6(1)(b) GDPR for the contract, Article 6(1)(f) GDPR for secure and fraud-free processing and, where applicable, Article 6(1)(c) GDPR for legal duties.

The recipient category is payment service providers. Processing may occur outside the EU or EEA, particularly by Stripe, Inc. in the United States. Stripe relies on the European Commission’s Standard Contractual Clauses under Article 46 GDPR for such transfers.

We retain the data for as long as necessary to perform the contract and thereafter in accordance with statutory retention duties—six years under commercial law and ten years under tax law. Further information: https://stripe.com/privacy.

12. Internet speed measurement on Telemarie (Cloudflare)

To check and maintain functionality, the Telemarie device measures its internet connection speed using Cloudflare’s Speed Test API at speed.cloudflare.com. Providers are Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, and/or Cloudflare Germany GmbH, Rosenheimer Straße 143 C, 81671 Munich, Germany.

Processing includes technical connection data, particularly the device IP address and measurement and connection data such as throughput, latency and time of measurement. It is used to assess connection quality, maintain Telemarie’s functionality, diagnose faults and provide support.

The legal bases are Article 6(1)(b) GDPR, because processing is necessary to perform the rental agreement, and Article 6(1)(f) GDPR, reflecting our legitimate interest in reliable technical operation.

Recipients are infrastructure and network-service providers. Processing may occur outside the EU or EEA, particularly in the United States, based on the European Commission’s Standard Contractual Clauses under Article 46 GDPR. Further information: https://www.cloudflare.com/privacypolicy/.

13. YouTube videos

We embed videos from youtube.com so that they can be played directly on our website. YouTube is operated by Google Ireland Limited, registration number 368047, Gordon House, Barrow Street, Dublin 4, Ireland.

Processed usage data may include the page or content viewed and access time. Videos use YouTube’s privacy-enhanced mode, which does not use cookies to personalise playback based on browsing behaviour; recommendations are based on the video currently being played, and viewing in an embedded privacy-enhanced player does not affect recommendations on YouTube. When you start a video, you consent to YouTube recording that you accessed the relevant page or video and using this data for advertising purposes.

The purpose is to provide a user-friendly service and optimise our content. Consent-based processing relies on Article 6(1)(a) GDPR. The German source additionally refers to legitimate interests under Article 6(1)(f) GDPR and, for services connected with a contract, Article 6(1)(b) GDPR.

Data may be transferred to and stored by a third-party provider in the United States, even if you do not have a Google account. If you are signed in, Google may associate it with your account. Google may create profiles for advertising, market research or optimisation. Cookies may remain for up to two years or until you delete them.

You may object to profiling directly with Google. Advertising settings: https://adssettings.google.com/authenticated. YouTube terms: https://www.youtube.com/t/terms. Google advertising privacy information: https://policies.google.com/technologies/ads. Google privacy policy: https://policies.google.com/privacy.

14. Social-media presence

We maintain profiles and fan pages on social networks. When you visit or use one of these profiles, the privacy policy and terms of that network apply.

Networks may process usage, contact, content and master data for market research and advertising. They may build user profiles from behaviour and interests and use them for advertising inside and outside the network. Cookies may store behaviour and interests, and profiles may contain cross-device data, particularly for signed-in members.

For details and opt-out options, consult the network operator’s information. Requests for access and other data-subject rights are generally most effective when directed to the provider because only that provider has direct access to its user data. You may still contact us if you need help.

Purposes include communicating with registered network users, promoting our products and services, presenting and maintaining our public image, and evaluating users and content on our social-media presences. The legal bases are our legitimate interests under Article 6(1)(f) GDPR and, where consent is granted to us or the network, Article 6(1)(a) together with Article 7 GDPR. Recipients are the relevant social networks.

Facebook provider identified in the German source: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Privacy information: https://www.facebook.com/about/privacy/. Advertising opt-out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com. Objection: https://www.facebook.com/help/contact/2061665240770586. Joint-controller addendum: https://www.facebook.com/legal/terms/page_controller_addendum. Page Insights information: https://www.facebook.com/legal/terms/information_about_page_insights_data.

15. Social-media plug-ins

Where social-media plug-ins are used, the website uses the Shariff two-click solution from c’t/heise.de. Provider: Heise Medien GmbH & Co. KG, Karl-Wiechert-Allee 10, 30625 Hanover, Germany. Information: https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.

Shariff does not transmit personal data to plug-in providers merely when our website is loaded. A control beside the relevant network logo lets you activate a plug-in. Activation constitutes consent: the network is informed that you visited our website and your personal data is transmitted to and stored by the plug-in provider. Third-party cookies may be used. Some providers, including Facebook and XING according to their statements, anonymise IP addresses immediately after collection. Providers may store the collected data in usage profiles. You may withdraw consent at any time by deactivating the control.

Purposes include improving the website, raising awareness through social networks, enabling interaction, advertising, analysis and needs-based design. Legal bases are legitimate interests under Article 6(1)(f) GDPR, consent under Article 6(1)(a) together with Article 7 GDPR, and Article 6(1)(b) GDPR for pre-contractual enquiries or contractual performance. Recipients are the relevant social networks. You may object to profile creation directly with the plug-in provider.

16. Facebook

The German source states that Facebook.com plug-ins are integrated using Shariff’s two-click solution. The EU provider identified there is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The plug-ins can be identified by the Facebook ‘f’ or labels such as ‘Like’ or ‘Share’.

If you intentionally activate the plug-in, your browser connects to Facebook’s servers. Facebook receives information, including your IP address, that you visited our website and may transfer it to and store it on servers in the United States. If you are signed in, Facebook may associate the information with your account. Actions such as selecting ‘Like’ may also be transferred and stored and displayed on your profile or to your friends.

Information about the purpose and scope of collection, further processing, rights and privacy settings: https://www.facebook.com/about/privacy/. Like-button collection: https://www.facebook.com/help/186325668085084. Advertising preferences: https://www.facebook.com/ads/preferences/.

If you sign out of Facebook and delete cookies before visiting our website, activating the plug-in will not associate information about the visit with your Facebook profile. Joint-controller addendum: https://www.facebook.com/legal/terms/page_controller_addendum. Page Insights information: https://www.facebook.com/legal/terms/information_about_page_insights_data.

17. Your data-protection rights

Withdrawal of consent and objection

Where processing relies on consent under Article 6(1)(a) and Article 7 GDPR, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where processing relies on balancing legitimate interests under Article 6(1)(f) GDPR, you may object. Please explain why your particular circumstances mean we should not process the data as described. We will assess the objection and stop or adjust processing unless we demonstrate compelling legitimate grounds to continue.

You may object at any time, free of charge, to processing for advertising and data-analysis purposes by contacting Telemarie at the controller details above.

Access

Under Article 15 GDPR, you may ask whether we process personal data about you and, if so, obtain access. This includes information about purposes, data categories, recipient categories, intended retention and the source where data was not collected directly from you.

Rectification

Under Article 16 GDPR, you may have inaccurate data corrected and incomplete data completed.

Erasure

Under Article 17 GDPR, you may request deletion unless statutory or contractual retention periods or other legal duties or rights require continued storage.

Restriction

Under Article 18 GDPR, you may request restriction if you contest accuracy while we verify it; processing is unlawful and you prefer restriction to deletion; we no longer need the data but you need it for legal claims; or you have objected under Article 21(1) and verification of overriding grounds is pending.

Data portability

Under Article 20 GDPR, you may receive personal data concerning you in a structured, commonly used, machine-readable format or request transfer to another controller.

Complaint

You may lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.

18. Data security

We have implemented appropriate technical and organisational security measures to protect personal data transmitted to us and to help ensure compliance by us and our external service providers. Among other measures, data transmitted between your browser and our server is encrypted through a secure SSL connection.