Privacy Policy

Dear Customer,

We are pleased that you are interested in data protection. We would like to give you an easily understandable overview of our data protection process.

Our goal is to provide you with an amazing customer experience that also means that you can always trust us, that we are always transparent and honest to you. Your trust in our product is the reason why we can provide you with an amazing customer experience. We would like to thank you for this cooperation.

Who we are

We are the damejidlo.cz s.r.o., but usually we just use the name www.damejidlo.cz. You can always contact us via the following methods:
Můžete se na nás obracet s použitím následujících kontaktních údajů:
Address: Smrčkova 2485/4, 180 00, Praha 8
E-mail address: zakaznici@damejidlo.cz

While visiting our website, registering or placing orders, you agree to this privacy policy.

As data controller, we determine how we process your personal data, for what purposes and by what means. While we are required by law to provide you with all of the following information, we do so primarily out of the belief that a partnership should always be honest.

As data controller we are responsible that all our processing activities are in accordance with legal requirements but also you may reasonably expect these processing of your personal data (link to "legitimate interests").

If you have any questions about data protection at damejidlo.cz, you can also contact our data protection officer at any time by sending an email to DPO@damejidlo.cz.

We have a global Corporate Privacy Officer as we are also a member of the large and fascinating family of the Delivery Hero Group.

As a family, we make certain decisions together. Both our parent company, Delivery Hero SE, Oranienburger Straße 70, 10117 Berlin and we jointly decide which means we will use to process your personal data and which purposes we consider to be appropriate.

We will continue to be your point of contact if you have any questions about data protection.

Privacy is your right and you have the choice

As a customer you have the choice which information you would like to share with us. Of course, we need some information for the fulfillment of our contract. However, this does not always require all the data which you can make available to us.

You can take the following steps to disclose less information about yourself:

Cookies: You can install additional add-ons in your browser that block unnecessary cookies. By doing so, you will not see any interest-based advertisements.

Advertising: If you do not want to receive newsletters from us, you can unsubscribe at any time. In this case, we will not be able to send you any cool offers.

No data sharing: If you don't want to share any information with us at all, that's a shame. In this case we can't convince you how great our products are.

You can also make use of the following rights at any time:

Right to access
You have the right to be informed which data we store about you and how we process this data.

Right to rectification
If you notice that stored data is incorrect, you can always ask us to correct it.

Right to erasure
You can ask us at any time to delete the data we have stored about you. To erase your porsonal informations click here.

Right to restriction of processing
If you do not wish to delete your data, but do not want us to process it further, you can ask us to restrict the processing of your personal data. In this case, we will archive your data and only reintegrate it into our operative systems if you so wish. However, during this time you will not be able to use our services, otherwise we will process your data again.

Right to data portability
You can ask us to transmit the data stored about you in a machine-readable format to you or to another responsible person. In this context, we will make the data available to you in JSON format.

Right to object to the processing of your data
You can revoke your consent at any time or object to the further processing of your data. This also includes objecting to our processing, which we process without your consent but based on our legitimate interest. This applies, for example, to direct marketing. You can object to receiving further newsletters at any time.
If you do not agree with one of our processing purposes based on our legitimate interest or wish to object to it, you may object to the processing at any time on grounds relating to his or her particular situation. Please write an email to DPO@damejidlo.cz. In this case we will review the processing activity again and either stop processing your data for this purpose or explain to you our reasons worth protecting and why we will continue with the processing.

Automated decision making
We also process your personal data in the context of algorithms in order to simplify our processes. Of course, you have the right not to be subject to decisions based solely on automated processing. If you believe that we have denied your access in an unjustified way, you can always contact us at DPO@damejidlo.cz In this case, we will examine the case separately and decide on a case-by-case basis.

Right of complaint
If you believe that we have done something wrong with your personal data or your rights, you can complain to the appropriate supervisory authority at any time.

The supervisory authority responsible for us is:
Úřad pro ochranu osobních údajů
Pplk. Sochora 27
170 00 Praha 7
Email Address: posta@uoou.cz

To exercise your rights, you can contact DPO@damejidlo.cz at any time.

What data we process

In the following description of our processing activities, we refer in each case to categories of personal data. A category includes several personal data, which are usually processed together for the purposes.
Personal data is information that can identify you or even make you identifiable.
We generally process the following categories of personal data for the following reasons:

Contact Information:

Name, address, telephone number, email address, your ID from any social media

Reason:
If you contact us, we collect this data because we need to know who we are talking to and what we have been talking about so that we can help you with your reason for contacting us. This also applies if you leave comments on social media on our fan pages. We do not combine this data with your profile data on our platform, but we can still identify you by your social media ID.
The phone call may be monitored and recorded for quality assurance purposes and to ensure that our services work properly. Records are kept up to sixth months for internal needs only.

Location data:

Address, Postcode, City, Country, Longitude, Latitude

Reason:
We need these data to be able to deliver your orders. We create the longitude and latitude automatically in order to be able to process your delivery address in our other linked systems, such as our Rider app, and to display your address to our riders.

Profile data (master data):

Name, email address, password, telephone number, delivery addresses, interests, demographic data (age, delivery address)

Reason:
This data is your master data, which we absolutely need for our services. Without an email address / telephone number and a password, you cannot create a profile. Together with your name, this is your master data. We need your age to ensure that you are not a minor.

Order information:

Order history, selected restaurants, invoices, order ID, comments on orders, information on payment method, delivery address, successful orders and cancelled orders

Reason:
Each time you place an order, this information will be added to your profile. You can view all this information in your profile at any time. The information should give you an overview of your own interests and previous orders. We will also use the same information to improve our services. In addition, we will anonymize this information when you request a deletion or when your profile becomes inactive in order to continue to use this information in an anonymized form to optimize our services.

Communication data

Name, email address, telephone number, device ID

Reason:
If you would like to receive a newsletter, an SMS or an in-app push notification from us, we need certain information to send you the messages. Instead of addressing you with "Hey You", we find it more customer friendly to address you with your name. This category of personal information is also used by us to contact you, for example, if a product cannot be delivered and we want to offer you an alternative instead.

Payment information:

Payment method

Reason:
We need this information to track your payments and assign them to the orders you have placed. in some cases, depending on the payment method you choose in your order, we share your data with a provider of this payment method; for example when you choose to make a payment through Twisto (your personal data is transferred to Twisto payments a.s., ID no.: 016 15 165, with its registered office at Újezd 450/40, Malá Strana, 118 00 Praha 1); in case of a payment by a payment card, we do not process information regarding such payment and your interaction is only with the respective payment platform operator.

Delivery information:

Name, delivery address, phone number, order ID

Reason:
In accordance with the principle of data minimization, we only provide our riders and restaurants with the information that they need from you to prepare and deliver your order.

For which purposes we process data

We process your personal data only in accordance with the strict legal requirements. We pay particular attention to the fact that all principles for the processing of personal data are taken into account. The Delivery Hero Group pays great attention to transparency. Therefore, we only process your data if this is lawful and you can reasonably expect it to be processed. If, in the course of our evaluation, we come to the conclusion that the processing cannot reasonably be expected, we will only carry out the processing with your express consent.

Account creation, SSO registration, administration of your profile

In order to be able to offer you our services, the processing of your personal data is essential. Much of this data you transmit to us and other parts of the data we collect automatically when using our platforms. Nevertheless, we endeavor to keep the amount of data as small as possible. You can help us by only sharing necessary data with us that we need to fulfill our contractual obligations.

Account creation

When creating a customer account you will be asked to enter your master data. This is absolutely necessary, as we cannot create a customer profile without this data. Your email address and telephone number are particularly important, as we can use this information to identify you in our system the next time you want to log in again. Furthermore, we would like to ask you to choose your password carefully. Do not use the same password on multiple websites. Your password should also be at least 12 characters long, at least one lowercase letter, one uppercase letter, one special character (!?#,%& etc.) and one digit.

Categories of personal data:
Profile data (master data)
Device information and access data

Legal basis: Art. 6 para. 1 (b) GDPR, performance of contract

Login

If you already have an existing customer account, you will need to enter your email address and password to log in. If we detect irregularities during registration, such as entering the wrong password several times, we will take appropriate measures to prevent damage to you and us.

Categories of personal data:
Profile data (master data)

Legal basis:
Art. 6 para. 1 (b) GDPR, fulfilment of contract for registration;
Art. 6 para. 1 (f) GDPR, for the security measures

Single-Sign-On with Facebook

If you have a Facebook profile, you can register on our website to create a customer account or to register using the social plugin "Facebook Connect" of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"), within the framework of the so-called Single Sign On technology. You can recognize the social plugins of "Facebook Connect" on our website by the blue button with the Facebook logo and the inscription "Log in with Facebook" or "Connect with Facebook" or "Log in with Facebook" or "Sign in with Facebook".

If you call up a page of our website that contains such a plugin, your browser establishes a direct connection to the Facebook servers. The content of the plugin is transmitted directly from Facebook to your browser and integrated into the page. Through this integration, Facebook receives the information that your browser has called up the corresponding page of our website, even if you do not have a Facebook profile or are not logged on to Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there. These data processing operations are carried out in accordance with Art. 6 Para. 1 (f) GDPR on the basis of Facebook's legitimate interest in the display of personalised advertising on the basis of surfing behavior.

By using this "Facebook Connect" button on our website, you can also log in or register on our website using your Facebook user data. Only if you give your express consent in accordance with Art. 6 Para. 1 (a) GDPR prior to the registration process on the basis of a corresponding note on the exchange of data with Facebook, will we receive the general and publicly accessible information stored in your profile when using the Facebook "Facebook Connect" button on Facebook, depending on your personal data protection settings on Facebook. This information includes user ID, name, profile picture, age and gender.

We would like to point out that after changes have been made to Facebook's data protection conditions and terms of use, your profile pictures, the user IDs of your friends and the friends list may also be transferred if they have been marked as "public" in your Facebook privacy settings. The data transmitted by Facebook is stored and processed by us for the creation of a user account with the necessary data, if this has been released by you on Faceboo (title, first name, surname, address data, country, e-mail address, date of birth). Conversely, we can transfer data (e.g. information on your surfing behavior) to your Facebook profile on the basis of your consent.
The consent given can be revoked at any time by sending a message to us.
Facebook Inc., headquartered in the USA, is certified for the us European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

Categories of personal data:
Profile data (master data)
Contact Information
Facebook profile information

Legal basis:
Art. 6 para. 1 (a) GDPR, Consent

Managing your profile

You can log in to your profile at any time and change your personal data, such as name, email address or telephone number. You can also view your previous orders.

Categories of personal data
Profile data, location data
Order information
Device information and access data
Communication data
Payment information

Legal basis:
Art. 6 para. 1 (b) GDPR, performance of contract

Order processing

Once you have successfully registered and decided to place your order, we will store this information in your profile and process it in further processes so that you can submit your order to us. When you submit your order, your personal data is transferred to our backend where it is transferred to other systems for further processing.

Categories of personal data
Contact Information
Location data
Device information and access data

Legal basis:
Art. 6 para. 1 (b) GDPR, fulfilment of contract

Buffering

After you have logged in to your profile and made your selection, the products will be saved in your profile. If you accidentally close your browser or app, you can continue to the last point of your order. The last information is stored in a cookie.

Categories of personal data:
Profile data (master data)
Device information and access data
Order information

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest
The legitimate interest is to provide you with a better ordering experience where you can conveniently continue your order with browsers or apps that are accidentally closed.

Delivery

Once you have successfully placed your order, a number of processes are running in the background to ensure that your order is delivered quickly.
The following processing activities describe how and why your data is processed for the respective purposes.

Transfer to Riders and Restaurants

We use different riders for delivery. These can be permanent employees, freelancers or third parties who provide us with riders on the basis of a data processing agreement when we deliver our orders. In all these cases we send your personal data to the riders so that they can deliver your order quickly.

Categories of personal data:
Delivery information

Legal basis:
Art. 6 para. 1 (b) GDPR, performance of contract

Calls from restaurants

If a product of your choice is not available for delivery, they can receive instructions from us to call you so that the problem can be solved easily.

Categories of personal data:
Delivery information

Legal basis:
Art. 6 para. 1 (b) GDPR, contract performance on call by the rider
Art. 6 para. 1 (f) GDPR, legitimate interest when called by the restaurant. The restaurants have no claim whatsoever to your personal data and under no circumstances may they use it for their own purposes. If you should nevertheless be contacted by a restaurant without your prior consent, we ask you to report this to us by e-mail to DPO@damejidlo.cz

Saved payment methods

We do not process information regarding such payment and your interaction is only with the respective payment platform operator. But in order to make the ordering process even more convenient for you, we offer to save your preferred payment method. This means that you don't have to enter your payment details again the next time you place an order. The storage of this data requires your prior consent. You can save your payment data by clicking on the consent field. You can revoke your consent for the future at any time by deactivating the consent field again or by informing us of this by e-mail to DPO@damejidlo.cz.

Categories of personal data:
Payment data

Legal basis:
Art. 6 para. 1 (a) GDPR, consent

Advertising and marketing

Direct marketing

Newsletter
If you have provided us with your email address when purchasing goods or services, we reserve the right to send you regular offers of similar goods or services to those already purchased from our range by email.
Not only do the contents of our newsletters vary, but so do the technologies and criteria we use to design our newsletters and segment customer groups. For example, a group of customers may receive a special newsletter promoting special deals from restaurants where customers have ordered. Other newsletters may refer to specific products that relate to a particular flavour, such as sushi, Indian delicacies or pizza.
We use different information from your order history and delivery addresses.
This is a profiling process in which we automatically process your data. The specific customer segmentation can have a legal effect on you or can have a significant effect on you in other ways if you receive certain newsletters and are not included in other campaigns.

If automated decision-making leads to a negative result for you and you do not agree with this, you can contact us at DPO@damejidlo.cz. In this case, we will individually assess the circumstances of your case.

Categories of personal data:
Contact Information
Location data
Order information

Legal basis:
Data processing in this respect takes place solely on the basis of our legitimate interest in personalised direct advertising pursuant to Art. 6 Para. 1 lit. f GDPR. If you have initially objected to the use of your email address for this purpose, we will not send you an email. You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time with effect for the future by notifying the person responsible named at the beginning. For this purpose you only incur transmission costs according to the basic tariffs. Upon receipt of your objection, the use of your email address for advertising purposes will be discontinued immediately.

NPS
We are constantly striving to improve our services. Your constructive feedback is very important to us. Therefore we will occasionally send you customer surveys and ask you to give us your opinion. If you do not wish to receive customer surveys, you can unsubscribe at any time. For any customer survey request you can click "unsubscribe" below and we will not contact you again.

Categories of personal data:
Communication data

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest.
Our legitimate interest is the purpose described above.

App
We have a strong interest in informing you about new restaurants or deals when using our app. We are always working to give you an amazing customer experience. To achieve this, we negotiate very good deals for you with our restaurant partners. To inform you about these deals, we send you in our Apps in-app-notification or push-notification. It is imperative that you have activated this in your end devices.

Categories of personal data:
Location data
Profile data (master data)
Order information

Legal basis:
If processing takes place with your consent, the legal basis is Art. 6 Para. 1 (a) GDPR, namely your consent. Otherwise, the processing is based on our legitimate interest pursuant to Art. 6 para. 1 (f) GDPR. Our legitimate interest lies in the aforementioned purpose.

SMS
Besides other means we continue to use SMS to inform you about new deals in your area. You will only receive an SMS from us if you have given your consent. You can revoke your consent at any time for the future. Please send us an e-mail to DPO@damejidlo.cz. The registration as well as the cancellation is free of charge for you.

Categories of personal data:
Contact Information
Order information

Legal basis:
Art. 6 para. 1 (a) GDPR, consent

Online marketing
Our service is based to a large extent on convincing potential customers that we offer an amazing customer experience and that every visit to our platform is worthwhile. In order to reach as many potential customers as possible, we are very active in the field of online marketing. It is just as important to win the trust of potential customers and to strengthen the trust of our existing customers. Therefore, we would like to present you our processes as transparent as possible.

Targeting
n principle, targeting means the switching and fading in of advertising banners on websites that are tailored to specific target groups. The aim is to display the most attractive banners as individually as possible for the user and potential customer. Firstly, we define a target group and secondly, we commission our service providers to show our advertising to the defined target group. We do not process any personal data, as these are initially made anonymous. To better define the target group, we segment customer types and place different ads on different portals.

Retargeting
As soon as you have visited our website and, for example, have already placed an order in your shopping cart, we store this information in cookies. If you continue to surf other websites, our advertising partners will remind you on our behalf that you have not yet completed your order. We don't want you to miss out on our amazing customer experience.
You can disable retargeting by installing appropriate add-ons for your browser. Furthermore, you can and should also regularly delete the cookies stored in the browser you are using.

Categories of personal data:
Contact Information

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest.
Our legitimate interest is the purpose described above.

Cookies
In order to make the visit of our website/app attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our affiliate to recognize your browser on your next visit (persistent cookies). You can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for specific cases or in general. Failure to accept cookies may limit the functionality of our website/app.

What categories of cookies exist?
Strictly necessary scookies are needed so that you can move around a website/app and use its features. Without these cookies, functionality cannot be guaranteed, such as actions taken during a visit (e.g. text entry), even when navigating between pages on the site.
Functionality cookies allow a website/app to save information already provided (such as user name, language selection, or the location you are in) and improve the user's ability to offer personal features. These cookies collect anonymised information and cannot track your movements on other websites.
Performance cookies collect information about the use of a website/app - for example, which pages a visitor visits most often and whether he receives error messages from a page. These cookies do not store information that allows identification of the user. The collected information is aggregated and anonymous. These cookies are used exclusively to improve the performance of a website/app and thus the user experience.
Cookies for marketing purposes are used to play more targeted advertising relevant to the user and adapted to his interests. They are also used to limit the frequency of an ad and measure the effectiveness of advertising campaigns. They register whether you have visited a website/app or not. This information may be shared with third parties (e.g. Advertisers). To improve targeting and advertising cookies are often linked to third party site functionalities.

Objection to the use of cookies
If you do not want us to collect and analyse information about your visit, you can object to this at any time for the future (opt-out). If you want to object, please contact us under the contact information mentioned above.

For technical implementation of this objection, an opt-out cookie will be set in your browser. This cookie is solely for the purpose of mapping your objection. Please note that for technical reasons an opt-out cookie can only be used for the browser from which it was set. If you delete cookies or use a different browser or device, you will need to re-opt-out.

You can find our cookie policy with all the cookies we use here.

Sweet Treat

We want to reward our customers' loyalty with option to win some credits for next order. For this reason, we offer our registered customers the opportunity to able to win credits by selecting one of the items shown after order. In order to be able to check the frequency of use of credits, but also to avoid misuse of these credits, we collect various personal data.

Categories of personal data:
Profile data (master data)

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest
Our legitimate interest is the purpose described above.

User Experience Surveys:

We always develop new products and try to adapt our services to the wishes of our customers. In order to measure the effectiveness of these changes, we regularly offer interviews with our User Experience team. In these interviews we record your usage behaviour and ask you for possible optimisation possibilities.
Participation in the interviews requires your consent. If you have already given your consent and would like to revoke it for the future, you can do so at any time by sending an email to DPO@damejidlo.cz. In this case we will exclude you from participating in our interviews and you will not receive any further invitations for them.

Categories of personal data:
Contact Information
Order information

Legal basis:
Art. 6 Para. 1 (a) GDPR, Consent

Fraud prevention and security of our platform

In order to protect our customers and our platform from possible attacks, we continuously monitor the activities on our website. To this end, we use various technical measures to ensure that suspicious behavior patterns are detected at an early stage and prevented in good time. To achieve this goal, several monitoring mechanisms run in parallel and prevent potential attackers from accessing our website at all.

The decision-making process is automated and can have a legal effect on the person concerned or affect them in a similar way. If automated decision-making leads to a negative result for you and you do not agree with this, you can contact us at DPO@damejidlo.cz. In this case, we will individually assess the circumstances of your case.

Categories of personal data:
Device information and access data
Contact information
Payment information
Order information
Voucher information

Legal basis:
Art. 6 Para. 1 (a) GDPR, Consent

Merger & acquisitions, change of ownership

We would also like to inform you that in the event of a merger with or acquisition by another company, we will disclose information to that company. Of course, we will require the company to comply with the legal data protection regulations.

Categories of personal data:
Contact Information
Delivery information
Location data
Profile data (master data)
Device information and access data
Order information
Communication data
Payment information
Voucher information

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest
Our legitimate interest is the purpose described above.

Vouchers

We often offer vouchers for our platforms. The reasons can vary. The purpose of these vouchers is to reward our loyal customers and to encourage them to continue to lead our loyal customers.
In order to be able to check the number, the value and the frequency of use of the vouchers, but also to avoid misuse of these vouchers, we collect various personal data.

Categories of personal data:
Profile data (master data)
Voucher information

Legal basis:
Art. 6 para. 1 (f) GDPR, legitimate interest
Our legitimate interest is the purpose described above.

Who we work with and where we process your data

We never give your data to unauthorized third parties. However, as part of our work we obtain the services of selected service providers and give them limited and strictly monitored access to some of our data. However, before we forwarding personal data to these partner companies for processing on our behalf, each individual company undergoes an audit. All data recipients must meet the legal data protection requirements and prove their data protection level with appropriate proofs.

Delivery Hero Gruppe

Within a group it is sometimes necessary to use resources effectively. In this context, we support each other within our Group in optimizing our processes. In addition, we provide joint content and services. This includes, for example, the technical support of systems.
This is a joint responsibility within the meaning of Art. 26 GDPR. We are fully responsible for fulfilling the data protection requirements together with Delivery Hero SE, Oranienburger Straße 70, 10117 Berlin, dpo@deliveryhero.com. Within the framework of joint controllership, both we and Delivery Hero SE have agreed that both will guarantee your rights equally.
For practical reasons we have decided that we are to you for all data protection-legal questions at the disposal and in particular your rights in accordance with Art. 15 to 22 GDPR will guarantee we will guarantee.
Please contact us for this under DPO@damejidlo.cz.

Service providers

We use different data processors in our daily processing. These process your personal data in accordance with the requirements of Art. 28 GDPR only according to our instructions and have no claims whatsoever on these data. We also monitor our processors and include only those who meet our high standards.
Because we use different data processors and change them from time to time, it is not appropriate to identify specific recipients of personal information. However, if you are interested, we will be happy to disclose the name of the processor(s) in use at that time upon request.

Third parties

In addition to data processors, we also work with third parties, to whom we also transmit your personal data, but who are not bound by our instructions. These are, for example, our consultants, lawyers or tax consultants who receive your data from us on the basis of a contract and process your personal data for legal reasons or to protect our own interests.
We do not sell or rent your personal data to third parties under any circumstances. This will never take place without your explicit consent.

Prosecuting authorities and legal proceedings

Unfortunately, it can happen that a few of our customers and service providers do not behave fairly and want to harm us. In these cases, we are not only obliged to hand over personal data due to legal obligations, it is also in our interest to prevent damage and to enforce our claims and to reject unjustified claims.

Social Media Fanpages

We have profiles on various social media platforms on which we advertise our products and interact with customers. Since we operate these profiles on third-party platforms, each time you visit these social media channels the operators collect different personal data from you.

Responsibilities
We and the respective operators of the social media platforms act as joint controllers. Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.

The social media platforms Facebook and Instagram are operated by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.

We are responsible for all interactions on our own platforms. The operators of the social media platforms themselves are data controllers for general interactions and interactions outside our profiles.
An exception applies to the data processing described below for the usage analysis (page insights); we are jointly responsible with Facebook for this.
The following links will show you exactly which data is collected by the respective social media operators:
Privacy Policy Facebook
Privacy Policy Instagram

Data processing
For pages, Facebook provides page administrators with statistics and insights that help them understand the types of actions people take on their pages ("Page Insights").
When you visit or interact with a Page or its content, information such as the following may be collected and used to create Page Insights:

  • Viewing a Page, or a post or video from a Page
  • Following or unfollowing a Page
  • Liking or unliking a Page or post
  • Recommending a Page in a post or comment
  • Commenting on, sharing or reacting to a Page post (including the type of reaction)
  • Hiding a Page's post or reporting it as spam
  • Clicking a link to a Page from another Page on Facebook or from a website off Facebook
  • Hovering over a Page's name or profile picture to see a preview of the Page's content
  • Clicking on the website, phone number, Get Directions button or other button on a Page
  • Whether you're on a computer or mobile device while visiting or interacting with a Page or its content
We and Facebook are jointly responsible for the processing of your data for the provision of page insights. For this purpose, we and Facebook have agreed in an agreement which and a division of our data protection obligations according to Art. 26 GDPR shall be agreed.

Your data subject rights
As part of our agreement with Facebook, we have determined that Facebook is primarily responsible for fulfilling its information obligations in connection with the Page Insight data and for ensuring that you exercise your rights under the GDPR. For more information about your data subject rights on Facebook, please see Facebook's Page-Inside Privacy Policy.

Data processing outside the EU

We process your data mainly within the European Union (EU) and the European Economic Area (EEA). However, some of our service providers mentioned above are based outside the EU and the EEA.
The GDPR has high requirements for the transfer of personal data to third countries. All our data receivers have to measure up to these requirements. Before we transfer your data to a service provider in third countries, every service provider is first assessed with regard to its data protection level. Only if they can demonstrate an adequate level of data protection will they be shortlisted for service providers.

Regardless of whether our service providers are located within the EU/EEA or in third countries, each service provider must sign a data processing agreement with us. Service providers outside the EU/EEA must meet additional requirements. According to Art. 44 ff. GDPR personal data may be transferred to service providers that meet at least one of the following requirements:

  • Commission has decided that the third country ensures an adequate level of protection (e.g. Israel and Canada)
  • Standard data protection clauses adopted:
    These are contractual clauses which cannot be modified by the contracting parties and in which they undertake to ensure an adequate level of data protection.
  • Approved certification mechanism:
    Under international agreements, companies can be certified according to defined criteria. One of these certifications is the EU-US Privacy Shield Agreement.
    On the following link you can see certified companies: https://www.privacyshield.gov/welcome

We will only transfer your data to service providers who meet at least one of these requirements. If we transfer data to third countries, these are mainly companies based in the USA or Israel.

How long we store your data

We generally delete your data after the purpose has been fulfilled. The exact deletion rules are defined in our regional deletion concepts. Different deletion rules apply depending on the purpose of the processing. Within our deletion concepts we have defined various data classes and assigned rule deletion periods to them. The data collected is marked with a deletion rule. When the retention period is met, the stored data will be deleted accordingly.

We will delete your personal data either if you wish and let us know or if your account is inactive for three years, we will also delete your account. Before this happens, you will receive a separate notification from us to the email address registered in your user account.

In addition to the deletion rules defined by us, there are other legal retention periods which we must also observe. For example, tax data must be kept for a period of between six and ten years or even longer in some cases. These special retention periods vary according to local legal requirements.

Therefore, despite your request for deletion of your data, we may still have to store some of the stored data due to legal regulations. In this case, however, we will restrict data from further processing.

Furthermore, we will continue to store your data if we have a right to do so in accordance with Art. 17 para. 3 GDPR. This applies in particular if we need your personal data for the establishment, exercise or defence of legal claims.

About our cookie policy

You can find our cookie policy with all the cookies we use here.

Right of modification

We reserve the right to change this data protection declaration in compliance with the statutory provisions. We will inform you of any significant changes, such as changes of purpose or new purposes of processing.

Last update: October 2019