Privacy Statement

With this privacy statement according to Art. 12 General Data Protection Regulation (GDPR), we would like to inform you about the type, scope and purpose of the personal data collected, used and processed by accSone and about your rights as a data subject according to the GDPR.

accSone has privacy regulations that are binding for our company to ensure the best possible protection for your personal data. Personal data is any information that can be used to determine your identity.

Controller according to Art. 4 No. 7 GDPR

accSone
Jörg Stelkens
Ebernburgstr. 1a
D-81375 Munich
Germany
++49 (0)89 23716605
email @ accsone.com

Information about data processing, duration of storage and the legal basis of the processing when using the accSone website

accSone Website (connection data)

You can access and retrieve information from accSone´s Website without entering personal data. When you visit our website only for informatin purposes, the device that you use to access the page automatically transmits log data (connection data) to our servers. Log data includes the IP address of the device that you use to access the website, the type of browser you are using, the website you have visited beforehand, your system configuration, and the date and time.

In this usecase only your IP address is considered as personal data because it is possible to determine your identity with this address. We store IP addresses only to the extent necessary to provide our services. Otherwise, the IP addresses are deleted or made anonymous. We store your IP address when visiting our website for a maximum of 7 days to detect and ward off attacks.

The legal basis for this data processing is Art. 6 para. I lit. f) GDPR, giving permission for the processing of personal data which is necessary for the protection of our legitimate interests or those of a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned (data subject) prevail. Our legitimate interest is conducting our business.

Furthermore we like to inform you, that accSone uses analysis systems only with anonymization functions. This truncates your IP address by two bytes, making it impossible to determine your identity or the internet connection you are using. It will include your abbreviated IP address, the website of our website you visit, the website from which you have switched to our website (referrer URL), your time spent on our website and the frequency of access to one of our websites processed.

accSone Contact us (contact data)

When contacting the specified e-mail address, the personal data provided (e-mail address, name, if applicable, other personal data) will be processed in order to process the request. The data resulting in this context are deleted after the storage is no longer required. The contact information service is aimed at adults of full age.

The legal basis for this data processing is Art. 6 para. I lit. f) GDPR, giving permission for the processing of personal data which is necessary for the protection of our legitimate interests or those of a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned (data subject) prevail. Our legitimate interest is conducting our business.

accSone Shop (contract data)

We collect certain types of personal data only to complete your order and to authorize payment. To process your order or the product registration and the product delivery, we ask for your name, e-mail address and your billing address. This allows us to process your order. In case of problems processing your order, we can contact you using this information. Of course, you can always correct possible data entry errors during the order process as often as necessary before submitting your order. In our order confirmation, which is send to you immediately after submitting your order, you will view all order data you have entered.

By selecting the payment method „paypal“, we link you to our payment service PayPal/Luxembourg for further processing. Personal data related to payment will only be entered and stored on the payment service provider's website. We do not receive any account or credit card information, but only information with confirmation or negative disclosure of the payment. All personal data processed by the payment service provider are governed by the terms and conditions and privacy notices of the payment service provider, which are available on the website www.paypal.com and to which we expressly refer.

We only process and store personal contract data for the period required to achieve the purpose of storage or where required by law. For contract data, processing will be restricted after the contract has been terminated; it will be deleted after expiry of the statutory retention period.

The legal basis of the processing is Art. 6 para. I lit. b) GDPR, giving permission to the processing of personal data, which is required to fulfil a contract. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in cases of enquiries regarding our products. If we are subject to a legal obligation which requires the processing of personal data, such as the fulfilment of tax obligations, the processing is based on Article 6 I lit. c) GDPR.

accSone Newsletter (consent based data)

We send out newsletters with information about our services and our company by e-mail only with the consent of the recipient or a legal permission according to the GDPR.

Registration for the newsletter takes place in a so-called double opt-in procedure. After registration, you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with external e-mail addresses. The registration for the newsletter will be logged in order to prove the registration process according to the legal requirements. This includes the storage of the login and the confirmation time, as well as the IP address.

To subscribe to the newsletter, it is sufficient to enter your e-mail address. Optionally, we ask you to give a name in the newsletter for personal address.

The legal basis for the dispatch of the newsletter and the associated performance measurement is a consent of the recipients acc. Art. 6 para. 1 lit. a) Art. 7 GDPR and § 7 Abs. 2 No. 3 UWG or if consent is not required, based on our legitimate interests in the direct marketing acc. Art. 6 para. 1 lt. f) GDPR, § 7 Abs. 3 UWG.

The legal basis for the logging of the registration process is our legitimate interest in accordance with. Art. 6 para. 1 lit. f) DSGVO. Our interest lies in the use of a user-friendly and secure newsletter system, which serves both our business interests and the expectations of the users and also allows us to prove our consent.

Termination / Revocation - You may terminate the receipt of our newsletter at any time, ie. revoke your consent. A link to cancel the newsletter can be found at the end of each newsletter. We may save the submitted email addresses for up to three years based on our legitimate interests before we delete them to provide prior consent. The processing of this data is limited to the purpose of a possible defense against claims. An individual request for cancellation is possible at any time, provided that at the same time the former existence of a consent is confirmed.

accSone use of „YouTube“

In our website we use YouTube. This is a video portal of YouTube LLC., 901 Cherry Ave., 94066 San Bruno, CA, hereinafter referred to as "YouTube“. YouTube is a subsidiary of Google LLC., 1600 Amphitheater Parkway, Mountain View, CA 94043 USA, hereafter referred to as "Google".

We use YouTube in conjunction with the „Enhanced Privacy Mode feature“ to show you videos. The „Enhanced Privacy Mode feature“, according to YouTube, means that the data specified below will only be transmitted to the YouTube server when you actually start a video. A connection is required to display the video on our website via your internet browser. In the course of this, YouTube will at least collect and process your IP address, the date and time as well as the website you are visiting. It also connects to Google's DoubleClick ad network. If you're logged in to YouTube at the same time, YouTube will provide the connection information to your YouTube account. If you want to prevent this, you must either log out of YouTube before visiting our website or make the appropriate settings in your YouTube user account. For the purpose of functionality as well as for the analysis of user behavior, YouTube permanently stores cookies via your internet browser on your device. If you do not agree with this processing, you have the option to prevent the storage of cookies by a setting in your internet browser. For more information, see below "Cookies" in this privacy statement.

The legal basis for this data processing is Art. 6 para. I lit. f) GDPR, giving permission for the processing of personal data which is necessary for the protection of our legitimate interests or those of a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned (data subject) prevail. Our legitimate interest is user expercience improvement of our website.

For more information about the collection and use of data and your rights and protections, go to Google at https://policies.google.com/privacy available data protection information.

By signing up to the „EU-US Privacy Shield“ Google and its affiliate, YouTube, guarantees the EU privacy policy in processing data in the US (data transmission on the basis of Art. 49 para I lit. b) GDPR.)

accSone use of „Google reCAPTCHA“

In our website, we use Google reCAPTCHA to check and avoid interactions on our website through automated access, for example through so-called bots. This is a service of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google."

Through this service, Google can determine from which website a request is sent and from which IP address you use the so-called reCAPTCHA input box. In addition to your IP address, additional information may be collected by Google, which is necessary for the offer and the guarantee of this service.

The legal basis for this data processing is Art. 6 para. I lit. f) GDPR, giving permission for the processing of personal data which is necessary for the protection of our legitimate interests or those of a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned (data subject) prevail. Our legitimate interest is security of our website as well as the defense against unwanted, automated access in the form of spam or the like.

For more information about the collection and use of data and your rights and protections, go to Google at https://policies.google.com/privacy available data protection information.

By signing up to the „EU-US Privacy Shield“ Google guarantees the EU privacy policy in processing data in the US (data transmission on the basis of Art. 49 para I lit. b) GDPR.)

accSone use of „Google Fonts“

In our website we use Google fonts for displaying external fonts. This is a service of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA, hereafter referred to as "Google."

In order to enable the representation of certain writings in our internet appearance, a connection to the Google server in the USA is set up when calling our internet appearance.Google can determine from which website your request has been sent and to which IP address the presentation of the font is to be transmitted by the connection to Google established when our website is called up.

The legal basis for this data processing is Art. 6 para. I lit. f) GDPR, giving permission for the processing of personal data which is necessary for the protection of our legitimate interests or those of a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned (data subject) prevail. Our legitimate interest is optimization and economical operation of our website.

For more information about the collection and use of data and your rights and protections, go to Google at https://policies.google.com/privacy available data protection information.

By signing up to the „EU-US Privacy Shield“ Google guarantees the EU privacy policy in processing data in the US (data transmission on the basis of Art. 49 para I lit. b) GDPR.)

Information about Cookies

Using of Session Cookies

Our server works with cookies. "Cookies" are small data files that are temporarily stored in a designated file in your browser. You can decline cookies at any time if your browser allows you do this. Depending on your browser's settings, you will receive a notification that our server wants to place a cookie with a particular lifespan on your computer. Cookies allow you to experience faster and more convenient shopping processes during the lifespan of the cookie.

You can prevent the creation of cookies at any time by means of an appropriate setting of your internet browser used and thus permanently object the creation of cookies. Furthermore, cookies that have already been created can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If you deactivate the creation of cookies in the internet browser you are using not all functions of our website may be fully usable.

Links to our Social Media Sites

We maintain online presence within social networks and platforms in order to communicate with customers, prospects and users active there and to inform them about our services. On our website we give you information about an accSone online presence there by using social icons from these companies as follows:

KVR Audio, Twitter, Facebook, Soundcloud and Google+.

These services are offered by the companies mentioned. When calling the respective networks and platforms, the terms and conditions and the data processing guidelines apply to their respective operators. In order to increase the protection of your data when visiting our website, the redirects are static links. This will prevent your data from being sent to social networks when you visit our website. Contact between you and the social network will not be established until you actively click on the button.

Processors

We pass on various personal data to our processors as the controller within the scope of the processing. We have ensured the security of your data by concluding data processing agreements according to Art. 28 GDPR. Our processors can be divided into the following categories:

Provision of services: These include office service providers, payment service providers, social media and advertising service providers

Operation of services, maintenance and upkeep of hardware and software, hostingservices

We only release data to authorities and third parties in accordance with statutory provisions or a legal title. Information may be provided to authorities on the basis of a legal regulation on security or for prosecution purposes. Third parties will only receive information if required by law. This may be the case, for example, in the case of a copyright infringement.

Data security

We have established technologies and security regulations and procedures to protect your personal information that is under our control. We protect this information from unauthorized access, usage, modification and illegal or accidental loss. Our servers employ a variety of security mechanisms and authorization processes to hamper unauthorized access. We save your information on specifically protected servers.

Your rights as a data subject according to the GDPR

Right to information and confirmation
You have the right to receive free information from us at any time, as well as confirmation of your personal data stored and a copy of this information.

Right to rectification
You have the right to demand the immediate correction of incorrect personal data concerning you. You also have the right to request the completion of incomplete personal data, including by means of a supplementary statement, taking into account the purposes of processing.

Rights to erasure
You have the right to have your personal data erased without delay if any of the following is true and if processing is not required:
• The personal data has been collected for such purposes or processed in a way for which it is no longer necessary.
• You revoke your consent, on which the processing was based, and any other legal basis for processing is lacking.
• You object to the processing in accordance with Art. 21 para.I GDPR and there are no legitimate reasons for the processing, or you object to the processing in accordance with Art. 21 para.II GDPR.
• The personal data has been processed unlawfully.
• The erasure of personal data is required to fulfil a legal obligation under European Union law or a national law to which we are subject.
• The personal data was collected in relation to information society services offered pursuant to Art.8 para. I GDPR.

Right to restriction of processing
You have the right to request the restriction of processing if one of the following conditions is met:
• The accuracy of your personal information is contested by you for a period of time that allows us to verify the accuracy of your personal information.
• The processing is unlawful, you refuse the deletion of the personal data and instead require the restriction of the use of personal data.
• We no longer need your personal information for processing purposes, but you need it to assert, exercise or defend your rights.
• You have objected to the processing in accordance with Art. 21 para.I GDPR and it is not yet clear whether our legitimate interests prevail over yours.

Rights to object
You have the right to object at any time to the processing of personal data concerning you, which takes place on the basis of Art. 6 para. I lit. e) or f) GDPR.
In the event of an objection, we will no longer process personal data unless we can demonstrate compelling legitimate reasons for processing that outweigh your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims.
You have the right to object at any time to the processing of your personal data for the purpose of direct advertising.

Right to data portability
You have the right to receive personal data relating to you that has been provided to us in a structured, common and machine-readable format. You also have the right to transfer this data to another controller without hindrance by us if the processing is based on the consent pursuant to Art. 6 para.I lit. a) GDPR or Art. 9 para.II lit. a) GDPR or is based on a contract pursuant to Art. 6 para.I lit. b) GDPR and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, in exercising your right to data transferability under Art. 20 para. I GDPR, you have the right to arrange that your personal data is transmitted directly from one controller to another, where this is technically feasible and as long as this does not affect the rights and freedoms of others.

Right to withdraw consent under data protection law
You have the right to withdraw the consent to the processing of personal data at any time.

Right of appeal to the supervisory authority
You have the right to contact a supervisory authority in the Member State of your place of residence or place of work or the location of the alleged violation at any time if you believe that the processing of personal data concerning you is contrary to the EU-GDPR.