
Privacy Policy
Our privacy policies
Below we would like to inform you about data protection in connection with our website.
You can find additional data protection information for further areas here:
Information for business partners (customers and suppliers)
Participation in video conferences or webinars via Microsoft Teams
Participation in video conferences or webinars via Zoom
Privacy policy for the website and social media profiles
Here you will find information about the processing of personal data when using our websites. We also provide information here about the processing of personal data in connection with our social media profiles (Xing, LinkedIn and YouTube). In doing so, we comply with the data protection law applicable in Germany. You can access this policy in its respective current version on our website at any time.
The controller pursuant to Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:
Thomas Rosin
Klaus-Groth-Str. 4
23611 Bad Schwartau
Tel.: 0451 305000-0
E-mail: info<ät>thomasrosin.de
You can find further information in our legal notice.
We expressly point out that data transmission over the internet (e.g. when communicating by e-mail) can have security gaps and cannot be completely protected against access by third parties. For a more secure transmission of data, we will be happy to provide you, upon informal request, with
- a PGP key. Information on encryption with PGP can be found in the German Wikipedia (Pretty Good Privacy). Free software for using this procedure can be found on the website of the Gpg4win project (www.gpg4win.de).
- a public S/MIME certificate. Information on encryption using S/MIME can be found here: S/MIME
The use of the contact details in the legal notice for commercial advertising is expressly undesired, unless we have previously given our written consent or a business relationship already exists. We hereby object to any commercial use and disclosure of this data.
Personal data
“Personal data are individual details about the personal or material circumstances of an identified or identifiable natural person (data subject).” Personal data include, among other things, name, address, date of birth, occupation, religion, but also details such as hobbies, possessions, purchases, behaviours, etc. The purpose of the Federal Data Protection Act and other special provisions is to protect the rights and freedoms of data subjects with regard to their data against misuse.
Insofar as personal data such as your name or your contact details are collected on our pages, this is done on a voluntary basis. You are neither legally nor contractually obliged to do so. However, without providing your data you cannot use the options for making contact or for online appointment booking offered here.
Collection of personal data when visiting our website
When using the website for information purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the data that is technically necessary for us to display the website to you (the legal basis is Art. 6(1)(1)(b) GDPR) and to ensure stability and security (the legal basis is Art. 6(1)(1)(c) GDPR in conjunction with Art. 32(1) GDPR and Section 19(1) TDDDG).
The logged data are neither used to create user profiles nor passed on to third parties, unless we are legally obliged to disclose the collected data. Log data with complete, personally identifiable IP addresses, which we store for reasons of technical security, in particular to ward off attempted attacks on our web server, are deleted or anonymised after no more than 7 days.
To improve our content offering and the compatibility of the website with users’ devices, we collect information about the web pages accessed and the device and browser types used in doing so, provided that you give us your consent for this. We store this information with anonymised (shortened) IP addresses for the purpose of statistical evaluation. The data are not passed on to third parties. (The legal basis is Art. 6(1)(1)(a) GDPR)
Contact form
You can send us an enquiry using our contact form. The personal data you provide to us in the context of this enquiry are used only to answer your enquiry. (The legal basis is Art. 6(1)(1)(b) GDPR)
The personal data from your enquiry are deleted once processing has been completed. However, depending on the content of your enquiry, tax-law and commercial-law retention periods, which can be up to 10 years, are taken into account here.
Online appointment booking
On our website we enable you to arrange appointments with us. For this we use the technical service etermin provided by eTermin GmbH, Mättivor 3, 6430 Schwyz, Switzerland, which we engage as a processor. The connection to the service is only established when you call up the online appointment function via a link on our website or in an e-mail sent by us. For the appointment booking, your entries in the appointment booking form are transmitted to us via cituro. You are not obliged to use this service to arrange an appointment with us. This is merely a supplementary offer. If you do not wish to use the service, please use one of the other contact options offered (contact form, telephone, e-mail) to arrange an appointment.
(The legal basis is Art. 6(1)(1)(b) GDPR)
We retain the personal data from appointment bookings for evidentiary purposes and the assertion of legal claims for up to 3 years (the legal basis is Art. 6(1)(1)(f) GDPR). Insofar as required beyond this, we retain the data for up to 10 years to comply with tax-law and commercial-law retention periods (the legal basis is Art. 6(1)(1)(c) GDPR).
Thomas Rosin as external data protection officer
Thomas Rosin has been appointed as external data protection officer for various companies. When we process personal data in our function as data protection officer and data protection office (auxiliary staff of the data protection officer), the company for which we are acting is the controller (Art. 4(7) GDPR).
If you contact us as a data subject, you will find information on the processing of your personal data in the data protection information of the controller that was provided to you upon the first processing of your data (e.g. data protection information for employees, for business partners, for website visitors). Where necessary, we will inform you in more detail in the context of your contact. We are also happy to be available to answer your questions.
Thomas Rosin Internal
“Thomas Rosin Internal” is a closed user area in which we offer additional free content for existing customers. In addition, chargeable services and content can also be purchased.
If you would like to use “Thomas Rosin Internal”, you must register by providing your first and last name, your company name, your e-mail address, a password of your choice and a username of your choice. There is no requirement to use your real name for the username; a pseudonym is possible here. For the purchase and use of chargeable content, a billing address is additionally required. Providing the aforementioned data is mandatory; you can provide all further information voluntarily in your user account.
As part of your registration we use the so-called double opt-in procedure, i. e. after your registration you will receive an e-mail in which you must confirm that you are the owner of the e-mail address provided and that you wish to receive necessary notifications (e. g. for sending purchase receipts or a link to reset your password).
In addition, you can subscribe to additional notifications, for example to be informed about new posts and content. You can unsubscribe from these additional notifications at any time, e. g. by clicking the unsubscribe link in the e-mail or by notifying us using the contact details provided above.
If you use the comment function provided in various places, your comment and your username are made accessible to other participants of “Thomas Rosin Internal”. Visitors to the website who are not logged in cannot view these. The other data in your user account can be viewed neither by other participants nor by visitors to the website.
If you use “Thomas Rosin Internal”, we store the data required to fulfil the contract, and, where necessary, also payment-related data. We also store the voluntary data you provide for the duration of your use of “Thomas Rosin Internal”, unless you delete it beforehand. You can manage and, where applicable, change your data in the protected customer area. (The legal basis is Art. 6(1)(1)(b) GDPR)
Data relating to your registration are retained for up to three years after the end of your participation in order to fulfil accountability obligations and to defend legal claims, and are then deleted insofar as they are not used for the stated purposes. Data required for the purchase and billing of chargeable services are retained for 10 years and deleted in the 11th year. (The legal basis is Art. 6(1)(1)(c) GDPR, in conjunction with Art. 5(2) GDPR, Section 147 AO, Section 257 HGB, as well as Art. 6(1)(1)(f) GDPR (the legitimate interest being the defence of legal claims))
Newsletter
With your consent, you can subscribe to various newsletters from us, with which we inform you about the topics listed in the description of the respective newsletter. These include, among others, our data protection newsletter or our internal customer information. In addition to specialist topics, our newsletters also regularly contain advertising for our products and services. (The legal basis is Art. 6(1)(a) GDPR.)
For registering for our newsletters we use the so-called double opt-in procedure. This means that, after your registration, we send you an e-mail to the e-mail address provided, in which we ask you to confirm that you wish the newsletter to be sent. If you do not confirm your registration within two weeks, your information will be blocked and automatically deleted. We also store the IP addresses you used and the times of registration and confirmation in each case. The purpose of the procedure is to be able to prove your registration and, if necessary, to clarify any possible misuse of your personal data.
The only mandatory detail for sending general newsletters is your e-mail address. Providing further data is voluntary and is used to be able to address you personally and to optimise the information offering. After your confirmation, we store your e-mail address for the purpose of sending the newsletter.
Certain newsletters are only for closed user groups. In order to regularly verify your membership, you must provide further information (including your employer who is a customer of ours and your business contact details).
You can withdraw your consent to the sending of a newsletter at any time and unsubscribe from the newsletter. You can declare the withdrawal by clicking the unsubscribe link provided in every newsletter e-mail. In the event of a withdrawal, we delete your data that is no longer required within 4 weeks.
We send our newsletters with the sender address newsletter (ät) thomasrosin (dot) de. It is possible that your e-mail system classifies our newsletters as spam. Most anti-spam solutions allow you to explicitly approve a particular sender e-mail address (“whitelist”). To do this, please enter the sender e-mail address from us mentioned above.
ProvenExpert review portal
We use the review portal ProvenExpert to manage the reviews for our company and to display the results on our website.
The provider is Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin
Website: https://www.provenexpert.com
Privacy policy: https://www.provenexpert.com/de-de/datenschutzbestimmungen/
When you visit our website, a connection to ProvenExpert is established so that ProvenExpert can display the current reviews in the footer of our website. To do this, ProvenExpert also records your browser settings, e.g. in order to display the review in a suitable language and size. The legal basis is Art. 6(1)(f) GDPR (legitimate interest: display of reviews)
Cookies
We use cookies and similar technologies on our website. Cookies are text files or information in a database that are stored on your device via your browser. The use of certain cookies is necessary and enables us to use certain content and functions of this website, to protect it against unauthorised access and to recognise authenticated users. In addition, we offer the use of optional content and functions for which you have given us your consent.
Cookies cannot run programs or transmit viruses to your computer.
Cookie “wp_lang” – valid for the current browser session – storage of the language setting for logged-in users.
Cookie “wordpress_test_cookie” – valid for the current browser session – check whether the browser supports cookies. This is only sent when you call up a login page.
Cookie “wordpress_logged_in_*” and “wordpress_sec_*” – valid for the current browser session – are required for the access protection of logged-in users.
Further detailed information about the cookies and functionalities we use can be found in the data protection settings. Here you can also view, withdraw or grant additional consents you have given so far. If we use certain functions on the basis of legitimate interests, you can also exercise a withdrawal there.
Further general information on the subject of cookies can be found, for example, in the German version of Wikipedia.
LinkedIn profile and joint controllership
On the social media platform LinkedIn (www.linkedIn.com) we operate both company-related and person-related social media profiles and publish there posts by and about Thomas Rosin (“our LinkedIn profiles and content”). For the processing of personal data on the LinkedIn platform, LinkedIn is generally the sole controller. You can obtain further information about the processing of personal data by LinkedIn in the LinkedIn privacy policy.
When you visit our LinkedIn profiles and content, LinkedIn processes personal data in order to provide us with statistics and insights (“LinkedIn Insights”). This gives us information about activities and interactions with our LinkedIn profiles and content. To do this, LinkedIn processes in particular the data that you have already provided to LinkedIn via the details in your profile, such as data on company affiliation, company size and employment status. This processing of personal data is carried out by LinkedIn and us as joint controllers. (The legal basis is Art. 6(1)(1)(f) GDPR, the legitimate interest being the improvement of our information offering).
We have entered into an agreement on processing as joint controllers with LinkedIn. In this context we have agreed with LinkedIn that LinkedIn is responsible for enabling you to exercise the rights to which you are entitled under data protection law (data subject rights). You can contact LinkedIn for this purpose via this link or the contact details in the LinkedIn privacy policy. Should you contact us regarding your rights and our LinkedIn profiles and content, we will forward your request to LinkedIn.
We have agreed with LinkedIn that the Irish data protection supervisory authority is responsible for this processing of your personal data under joint controllership. You have the right in this regard to lodge a complaint with the Irish data protection supervisory authority or another supervisory authority.
Important: When using the LinkedIn platform, personal data may also be processed by LinkedIn in third countries. You can obtain further information about this in the LinkedIn privacy policy.
YouTube profile and channel
On the social media platform YouTube (www.youtube.com) we operate a social media profile and a channel for publishing media posts by and about Thomas Rosin (“our YouTube profiles and content”). For the processing of personal data on the YouTube platform, YouTube is generally the sole controller. You can obtain further information about the processing of personal data by YouTube in the YouTube privacy policy.
If you contact us directly via YouTube, e.g. through platform-internal messages, comments or e-mails, and we process personal data from you as a result, we are the controller under data protection law. You can obtain information about this in these (our) privacy policies (see also the references to further topic-related privacy policies above this privacy policy)
Direct marketing
In individual cases we process your personal data in order to carry out direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to any profiling insofar as it is associated with such direct marketing.
If you object to processing for the purposes of direct marketing, we will no longer process your personal data for these purposes.
Your rights
You have the following rights vis-à-vis us with regard to the personal data concerning you:
- right of access (Art. 15 GDPR),
- right to rectification or erasure (Art. 16, 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing that we carry out on the basis of legitimate interests (Art. 21 GDPR); see the further information at the end of this policy in this regard.
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us.
Further information
The personal data processed in the context of providing this website are disclosed to the following categories of recipients:
Providers of technical services and services (e. g. data centre services, review portal, online appointment calendar), which are engaged by us without exception as processors.
Data are generally not passed on to third parties, unless this has been expressly requested by you or we are legally obliged to disclose data.
Automated decision-making that produces legal effects concerning you or similarly significantly affects you does not take place in connection with your use of this website.
Changes to this privacy policy
We reserve the right to adapt this privacy policy in accordance with the statutory data protection provisions. The respective current version applicable is available for you to view in the legal notice/data protection section of our website.
Information about your right to object under Art. 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which we carry out on the basis of Art. 6(1)(1)(f) GDPR (data processing on the basis of a legitimate interest).
If you object, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
The objection can be made without any particular form and should, where possible, be directed to the contact details listed in the privacy policy or in the legal notice.