Data protection policy of the Ullstein Concepts GmbH

Every natural person has the right to determine the use of their personal data. The Ullstein Concepts GmbH, takes the protection of personal data of our customers and those interested in our proucts very seriously. Therefore we consider it our duty to protect the data which the users entrusted to us. We are keen to protect your privacy at all times. In case the users voluntarily provide personal data, these are collected and stored in accordance with the statutory data protection provisions of the EU General Data Protection Regulation GDPR). Of course, all data will be treated confidentially. With the following data protection information, we would like to explain in detail which data are collected and what happens with these data. We want to ensure that visitors of our website and our customers are informed about the collection, processing and use of personal data openly and transparently through this transparent and comprehensible information in our privacy policy. This privacy policy applies to the website of Ullstein Concepts GmbH (www.ullsteinconcepts.com). It will be linked accordingly to this statement.

Who is responsible for your personal information in our company?

Responsible body:
Responsible body for the collection, processing and use of your personal data acc. Art. 4 para. 7 GDPR is the

Ullstein Concepts GmbH
Bahnhofstrasse 20
85416 Langenbach


Contact person for your data protection questions is
Ms Miriam Besna

datenschutz@ullsteinconcepts.com

Tel .: 089-809902-887

Personal data during the process of completing a sales contract

What data do we collect?
During the initiation or conclusion of a purchase contract, it is of course necessary to request and process your personal data. These include name, address and, if necessary, telephone number or e-mail. We use your personal data for processing your purchases at Ullstein Concepts GmbH and for sending messages that are directly related to the order. We use your personal information to process your payments. We also use your information to process complaints and product warranty claims.

What kind of personal information do we process?
We process the following categories of personal data: Contact details such as name, address, e-mail address and telephone number Payment information and history ordering.

Who has access to your personal information?
In addition to the access that our employees have to your data, in the course of order processing we require to pass on your data to the following third parties. A passing on to third parties takes place exclusively for the purpose of the execution of your order and only to the extent necessary for the execution of the order.

Personal data in context of regular contact request without the aim of initiating a business

What data do we collect?
In the course of establishing contact with us via phone, e-mail or contact form, the following personal data is collected voluntarily. These data are given voluntary and are collected to answer your request properly.

What kind of personal information do we process?
We process the following categories of personal data: Contact details such as name, address, e-mail address and telephone number as well as further information as far as these are necessary to answer your inquiry.

Who has access to this data?
The employees of our company have access to this data. Where are your data stored: Your data is stored within our merchandise management software on servers located within the European Economic Area.

What is the legal basis:
The data is used to answer your request. Basis for this is: Art. 6 GDPR Abs. A.

How long do we store your data?
The personal data within a contact request are not stored during telephone conversations. For e-mail correspondence and electronic contact requests, these are only stored within the e-mail inboxes of the respective processor. A storage within an evaluable software (merchandise management software or other database) does not take place. The mailboxes are archived in regular deletion routines and archival routines within 12 months of the expiration of 3 years and finally deleted within 12 months after the expiration of 10 years.

Newsletter

What data do we store?
For the newsletter, only the e-mail address of the subscriber is collected and stored in order to send them information about our products and services at irregular intervals. After the registration, the subscriber receives a confirmation e-mail in which an activation link must be activated in order to complete the registration. This corresponds to the double opt-in procedure. Your data will not be shared with third parties.
With Google Analytics we are tracking the interaction, with the key figures opening rate and click-rate, with our newsletters. To learn more about this read the paragraph "Google Analytics" This is in addition to the e-commerce tracking (see also "Google Data Sharing to Third Parties").

Who has access to your personal information?
The employees of our company have access to this data.

Where will your data be stored:
Your data will be stored within our merchandise management software on servers located within the European Economic Area.

What is the legal basis:
Art. 6 GDPR para. A

How long do we save your data?
We will save your newsletter registration for an indefinite period or your cancellation. Consent to receive the newsletter can be revoked by e-mail to the e-mail address stated in the masthead or by clicking on the unsubscribe link in the newsletter.

Personal data during the visit of our website

What data do we store during your visit to our website?
It is usually possible to use our services without providing personal data, under the condition that it is technically feasible. When visiting our website www.ullsteinconcepts.com, the statistical evaluation will collect, store and use information regarding the IP address of the user, the date and time of retrieval, the previously visited website, browser, etc. The collected data will be anonymised and used exclusively to optimize our website. The IP addresses are anonymized after one hour. The IP addresses are not passed on neither before nor after the anonymization. We reserve the right to create pseudonymised usage profiles in the future. You can find out which cookies or services are used for this purpose in the section "Cookies". Additional personal information will only be collected through contact requests or orders (see sections A and B).

Data security measures
Our site is encrypted with HTTPS. This applies both to entries made and data collected via e-commerce tracking to handle your requests. You can recognize an encrypted connection by the string "https: //" and the lock icon in your browser bar.

Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your computer and that allow an analysis of the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. All IP addresses submitted to Google Analytics will be shortened with the function "anonymize_ip", within member states of the EU or in states participating in the agreement of the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. A combination of IP address and other data does not occur. On our behalf, Google will use this information to evaluate your usage of the website, to compile reports on website activity and to provide other services related to website usage and internet usage to Ullstein Concepts GmbH.

Furthermore we use a method called "pixel-tracking" and the "tagging" of links in newsletters, in order evaluate those newsletter in Google Analytics. During that process the newsletter recipient, will be attributed with a, randomly generated user-id. This allows for the determination of the opening rate. In extreme single cases, it could be technically possible to match single openings to a webshop-order.

Data Sharing to Third Parties
In order to improve the visitor experience and the shop performance, cookies are stored (see "Cookie Policy"). These are being linked to data about user behavior. Summarized data for example is collected via Google Site Tag:

• Click paths, number of transactions, selected language & region settings when visiting the website (selected language when calling the website and which linguistic region when called up), technical data (browser, screen resolution, ...)

• Type of interaction (length of stay, abandonment rates, new & returning visitors

We use Google Analytics to analyze and regularly improve the use of our website. With the statistics we can improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the US, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US Framework.

Legal basis for the Use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f GDPR.

For more information about Google Analytics and how it collects information, please visit https://support.google.com/analytics/answer/6004245. Google's privacy policy can be viewed at https://policies.google.com/privacy?hl=en

A separate e-commerce tag includes the following information:

• Transaction number
          o Number to identify a transaction
• Product name
          o Name of the product in the transaction
• Product Quantity
          o Quantity of the product purchased
• Transaction value
          o Amount of revenue (gross price in €)

The "browser add-on to deactivate Google Analytics" gives you the option to prevent the use of your data. Information and download options can be found on:
https://tools.google.com/dlpage/gaoptout?hl=de

Furthermore, by clicking on the "opt-out cookie" no further data is collected.

Third Party Content Integration
Within this online offer content, such as videos from YouTube or maps from Google Maps are included. This always presupposes that the providers of this content (hereinafter referred to as "third party provider") can see the IP address of the users. Without the IP address they could not send the contents to the browser of the respective user. The IP address is therefore required for the presentation of this content. We endeavor to use only content whose respective providers use the IP address solely for the delivery of the content. However, we do not have any influence on this if the third parties provide the IP address e.g. save for statistical purposes. Please refer to the respective privacy policy of the respective third-party providers.

Involvement of an external service provider in the realization or operation of a web site
We do not collect any personally identifiable information about visitors to our site except those required for a sales contract or contact us (see also section A and B). Depending on the access protocol used, our service provider stores the date and time of the request, the access method / function desired by the requesting computer, input values ​​(file name, ...) transmitted by the requesting computer, the access status of the web server (file transfer, file not found, command not executed, etc.) and name of the requested file. The IP address of the computer from which the request is being sent is not saved.

Cookie Policy
In order for this Internet portal to work properly, we sometimes store small files - called cookies - on your device. This is common on most major websites.

Cookies
A cookie is a small text file that a web portal leaves on your computer, tablet or smartphone when you visit it. This allows the portal to "remember" certain inputs and settings (eg, login, language, font size, and other display preferences) over a period of time, and you do not need to retake them each time you visit and navigate the portal. We use cookies to improve the user experience, such as: For example, in order to replace less relevant content with more relevant content in order to be able to switch more targeted online advertising in order to be able to adapt the content to other terminals and to make further optimization. The use of cookies helps us to improve the performance of our website (eg optimization of the click paths, highlighting of important elements (buttons) and more. We use permanent cookies (storage for up to 2 years) and first-party cookies (Google Analytics and Google AdWords). For the use of remarketing measures, Google Analytics also sets individual third-party cookies. The cookies are placed by Google with the services Google Analytics and Google AdWords and stored for up to two years. The cookies and the resulting information are used solely to improve the user experience and website performance. The cookies are anonymized and no personal user data is linked to the data from the cookies. By clicking on the tab "Prohibit cookies" you can withdraw your consent and no more cookies will be placed on your device.

Cookies:
This site uses cookies to optimize the presentation and to offer certain services. On and for our site, we use Google Analytics to analyze and improve the user experience. We use Google AdWords to create and evaluate online advertising campaigns. The following cookies are set for this purpose:

"_ga" purpose: distinction of visitors; Expiration date: 2 years

"_gid" purpose: distinction of visitors; Expiration Date: 24 hours

"_gat" Purpose: Limits clicks within a minute for which a cookie is set; Expiration Date: 1 minute

"ga-dissable- < property-id >" Purpose: To save the rejection of cookies (opt-out); Expiration date:> 50 years

"_gac_ < property-id >" Purpose: Assignation to an AdWords campaign; Expiration date: 90 days

"< Property-id >" is the number used to identify the Google Analytics registered site.

Personal data that are linked to the cookies are deleted in Google Analytics after 14 months. See also "Data transfer to third parties."

Note: Google Analytics and Google AdWords do not store individually identifiable personal information about visitors to our site. For more information, see the privacy statement at https://support.google.com/analytics/answer/6004245. The data collected is anonymised by the function "anonymize_ip". In addition one can object to the collection of data by rejecting the cookies. You can limit or prevent the use of cookies by changing your browser settings. Please note that this might have an impact on the the functionality of the webpage.
For certain pages that require login, a function cookie is set so you do not have to sign in again. You can suppress this by removing the check mark. Please note that you can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance. The acceptance of cookies can be changed for specific cases or in general. Each browser differs in the way it manages the cookie settings. This is described in the Help menu of each browser, which explains how to change your cookie settings. These can be found for the respective browser under the following links:

Internet Explorer: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen

Chrome: http://support.google.com/chrome/bin/answer.py?hl=en&hlrm=en&answer=95647
Safari: https://support.apple.com/kb/ph21411?locale=de_DE
Opera: http://help.opera.com/Windows/10.20/de/cookies.html

Please note that if you do not accept cookies, the functionality of our website may be limited.

Personal data during the use of Facebook

We can currently use a social media plug-in from Facebook. We would be doing the so-called two-click-solution. This means that when you visit our site, initially no personal data is passed on to the providers of the plug-ins. The provider of the plug-in can be recognized by the first letter above the box or its logo. We give you the opportunity to communicate directly with the provider of the plug-in via the button. Only if you click on the highlighted field and activate it, the plug-in provider receives the information that you have accessed the corresponding website of our online service. In the case of Facebook, according to the provider in Germany, the IP address is anonymized immediately after collection. Activation of the plug-in means that personal data is transferred from you to the plug-in provider and stored in the USA. Since the plug-in provider carries out the data collection, in particular via cookies, we recommend that you delete all cookies before clicking on the tab "Facebook" via the security settings of your browser. We have no influence on the data collected and on data processing operations, nor do we know the full extent of data collection, the purpose of processing or the storage periods. We also have no information regarding the deletion of the data collected by the plug-in provider. The plug-in provider stores the data collection about you in the form of usage profiles and uses them for purposes of advertising, market research and / or tailor-made design of its website. Such an evaluation is carried out in particular (also for non-logged-in users) for the presentation of needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the formation of these user profiles, whereby you must contact the respective plug-in provider to exercise this. The plug-ins allow us to interact with social networks and other users so that we can improve our offer and make it more interesting for you as a user. The legal basis for the use of the plug-in is Art. 6 Abs. 1 S. 1 lit. f GDPR. The data transfer takes place regardless of whether you have an account with the plug-in providers and are logged in there. If you are logged into the plug-in provider, your data collected from us will be assigned directly to your existing account with the plug-in provider. If you press the activated button and if you link the page, the plug-in provider also stores this information in your user account and shares it publicly with your contacts. We recommend logging out regularly after using a social network, but especially before activating the button, as this will prevent you from being assigned to your profile with the plug-in provider. For further information on the purpose and scope of the data collection and their processing by the plug-in provider please refer to the privacy policy of the provider. There you will also find further information about your rights and settings options for the protection of your privacy. Addresses of the respective plug-in providers and URLs with their privacy policy: Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA; http://www.facebook.com/policy.php; For more information about data collection: http://www.facebook.com/help/186325668085084, http://www.facebook.com/about/privacy/your-info-on-other#applications and http: //www.facebook .com / about / privacy / your-info # everyoneinfo. Facebook has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US Framework

Your data - your rights

In the following, we would like to inform you about your rights concerning the handling your data: You have the right

• in accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can demand information on the processing purposes, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, the right to rectification, deletion, limitation of processing or opposition, the existence of request complaints and details about the content;
• in accordance with Art. 16 GDPR, immediately demand the correction or completion of incorrect personal data stored by us;
• in accordance with Art. 17 GDPR, request the deletion of your personal data stored by us. If the deletion is subject to statutory retention periods or the assertion or defense of legal claims, the data will be blocked.
• in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data, if the accuracy of the data is disputed by you, the or the processing is unlawful, if the you object to their deletion and we no longer need the data, but you require them to assert, exercise or defend legal claims or you have objected to the processing according to Art. 21 GDPR;
• in accordance with Art. 20 GDPR, to receive your personal data provided to us in a structured, common and machine-readable format or to request transmission to another person responsible;
• according to Art. 7 para. 3 GDPR, to revoke your once given consent to us at any time. As a result, we are no longer allowed to continue to process your data based.
• to complain to a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.

To implement the rights listed above, please send us your request in writen form or via e-mail to the contact address stated in the imprint.

Ullstein Concepts GmbH, May 2018