PRIVACY POLICY
We are very happy about your interest in our company. Data protection is particularly important for the Board Members of Quality.One. In principle, it is possible to use Quality.One’s website without any personal data. However, if a person wants to use special services from our company via our website, personal data could be processed. If the processing of personal data is necessary and if there is no legal basis for such processing, we generally obtain consent from the person concerned.
The processing of personal data, such as the name, address, e-mail address or telephone number of an affected person, is always carried out in accordance with the General Data Protection Regulation and in accordance with the applicable to Quality.One nation-specific data protection regulations.
Through this Privacy Statement, our company wants to inform the public about the nature, scope and purpose of the personal data we collect, use and process. In addition, affected persons will be informed about the rights to which they are entitled by this privacy policy.
Quality.One, as accountable, has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, internet-based data transfers can generally have security vulnerabilities, so absolute protection cannot be guaranteed. For this reason, every person concerned is free to transmit personal data to us by alternative means, for example by telephone.
1. TERMS
PERSONAL DATA
Personal data is any information relating to an identified or identifiable natural person (‘ the person concerned ‘). Identifiable is a natural person who is directly or indirectly assigned, in particular by assigning it to an identifier such as a name, to a identification number, to location data, to an online identifier or to one or more special features that reflect The physical, physiological, genetic, psychological, economic, cultural or social identity of this natural person can be identified.
RESPONSIBLE OR CONTROLLER
The person responsible for the processing is the natural or legal person, authority, institution or other body that decides solely or jointly with others on the purposes and means of processing personal data. If the purposes and means of this processing are provided by EU law or the law of the member states, the person responsible may or provide for the specific criteria of his designation under EU law or the law of the member states.
PERSON CONCERNED
The person concerned is any identified or identifiable natural person whose personal data is processed by the controller.
ORDER PROCESSORS
Order processor is a natural or legal entity, authority, institution or other body that processes personal data on behalf of the person responsible.
PROCESSING
Processing is any operation performed with or without the help of automated procedures or any such sequence of operations related to personal data such as collecting, collecting, organizing, arranging, storing, adjusting or modifying, reading, retrieving, using, disclosing by transmission, distribution or other form of delivery, matching or linking, restricting, deleting or destroying.
RECIPIENT
The recipient is a natural or legal person, authority, entity or other body that is disclosed personal data, whether or not it is a third party. However, authorities that may receive personal data under EU law or Member States’ law may not be considered recipients.
RESTRICTION OF PROCESSING
Restriction of processing is the marking of stored personal data with the aim of limiting its future processing.
THIRD PARTY
Third party is a natural or legal person, authority, institution or other body other than the person concerned, the person responsible, the processor and persons who are responsible under the direct responsibility of the person responsible or the person responsible. Order processors have the power to process the personal data.
PROFILING
Profiling is any type of automated processing of personal data that consists in this personal data being used to evaluate certain personal aspects related to a natural person, in particular to address aspects To analyze or predict this natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, whereabouts or change of location.
CONSENT
Consent is any person voluntarily given by the person concerned for the particular case in an informed and unequivocal manner, in the form of a declaration or other clear corroborating act intended to enable the person concerned to Understanding that it agrees with the processing of the personal data relating to it.
PSEUDONYMIZATION
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be assigned to a specific affected person without the use of additional information, provided that this additional data Information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not assigned to an identified or identifiable natural person.
2. NAME AND ADDRESS OF THE CONTROLLER
Responsible within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions of data protection law are:
- Quality.One OÜ Sepapaja tn 6 15551 Tallinn, Estonia
- hello@Quality.One.ch
- + 372 71 21 500
- www.quality.one/
3. COOKIES
Quality.One’s websites use cookies. Cookies are text files that are stored and stored on a computer system via an Internet browser.
Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string through which websites and servers can be assigned to the specific Internet browser in which the cookie was stored. This allows the websites and servers visited to distinguish the individual browser of the person concerned from other internet browsers containing other cookies. A specific Internet browser can be recognized and identified using the unique cookie ID.
By using cookies, Quality.One can provide users of this website with more user-friendly services that would not be possible without the cookie setting.
By means of a cookie, the information and offers on our website can be optimized in the sense of the user. Cookies allow us to recognize the users of our website, as mentioned above. The purpose of this recognition is to make it easier for users to use our website.
For example, the user of a website that uses cookies does not have to re-enter their access data every time they visit the website, because this is taken over by the website and the cookie stored on the user’s computer system. Another example is the cookie of a shopping basket in the online store. The online store remembers the items a customer has put in the virtual shopping cart via a cookie.
The person concerned can prevent the setting of cookies through our website at any time by means of a corresponding setting of the used internet browser and thus permanently object to the setting of cookies. Cookies that have already been set can also be deleted at any time via an internet browser or other software programs. This is possible in all popular internet browsers. If the person concerned deactivates the setting of cookies in the internet browser used, not all functions of our website can be fully used.
4. COLLECTION OF GENERAL DATA AND INFORMATION
The Quality.One website collects a range of general data and information with each visit to the website by an affected person or an automated system. This general data and information is stored in the server’s log files. The browser types and versions used can be summarized, the operating system used by the access system, the website from which a pull-ready system enters our website (so-called referrer), the subpages, Which are controlled by a pull-to-use system on our website, the date and time of access to the website, an Internet protocol address (IP address), the Internet service provider of the access system and Other similar data and information used to prevent security in the event of attacks on our information technology systems.
When using this general data and information, Quality.One does not draw any conclusions about the individual concerned. Rather, this information is needed in order to deliver the contents of our website correctly, to optimize the contents of our website as well as the advertising for it, the long-term functioning of our information technology systems and to ensure the technology of our website as well as to provide law enforcement authorities with the information necessary for law enforcement in the event of a cyberattack. This anonymously collected data and information is therefore evaluated by Quality.One, on the one hand, statistically and further, with the aim of increasing data protection and data security in our company, in order to ultimately achieve an optimal level of protection for those of us. Data processed. The anonymous data of the server log files is stored separately from all personal data provided by an affected person.
5. CONTACT OPPORTUNITY VIA THE WEBSITE
Due to legal regulations, the Quality.One website contains information that enables quick electronic contact with our company as well as direct communication with us, which is also a general address of the so-called electronic mail (e-mail address). If an affected person contacts the controller via email or via a contact form, the personal data transmitted by the person concerned will be automatically stored.
Such personal data, transmitted on a voluntary basis by an affected person to the controller, is stored for the purpose of processing or contacting the person concerned. This personal data will not be passed on to third parties.
6. COMMENTARY FUNCTION IN THE BLOG ON THE WEBSITE
Quality.One offers users on a blog, which is located on the website of the controller, the opportunity to leave individual comments on individual blog posts. A blog is a portal run on a website, usually open to the public, in which one or more people, called bloggers or web bloggers, can post articles or write down thoughts in so-called blog posts. The blog posts can usually be commented on by third parties. If an affected person leaves a comment in the blog published on this website, not only the comments left by the person concerned, but also information on the time of the commentary input and the username (pseudonym) chosen by the person concerned are stored and published.
Furthermore, the IP address assigned by the internet service provider (ISP) of the data subject is also logged. This storage of the IP address is made for security reasons and in the event that the data subject violates the rights of third parties or posts unlawful contents by submitting a comment. The storage of such personal data is therefore in the own interest of the controller, so that in the event of a breach of the law, it may be excusable. There is no disclosure of this personal data to third parties, unless such disclosure is not required by law or the legal defense of the controller.
7. SUBSCRIBE TO COMMENTS IN THE BLOG ON THE WEBSITE
The comments made in the blog of Quality.One can basically be subscribed to by third parties. In particular, there is the possibility that a commentator subscribes to the comments following a comment on a particular blog post.
If an affected person chooses to subscribe to comments, the controller will send an automatic confirmation email to double-check whether the owner of the specified email address for them Option has decided. The option to subscribe to comments can be ended at any time.
8. ROUTINE DELETION AND BLOCKING OF PERSONAL DATA
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of the storage or, if so required by the European directives and regulations or any other legislator in laws or regulations, that of the controller subject to was provided.
If the storage purpose is omitted or if a storage period prescribed by the European directives and regulations or any other relevant legislature expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.
9. RIGHTS OF AFFECTED PERSON
RIGHT TO CONFIRMATION
Each affected person has the right, as granted by the European di-rective and Regulatory Authority, to require the controller to confirm whether personal data relating to him / her are being processed. If an affected person wishes to exercise this right of confirmation, they can contact an employee of the controller at any time.
RIGHT TO RESTRICTION OF PROCESSING
Any person affected by the processing of personal data has the right granted by the European directive and regulatory authority to require the controller to restrict the processing if one of the following conditions applies:
- The accuracy of the personal data is contested by the data subject for a period of time that enables the person responsible to verify the accuracy of the personal data.
- The processing is unlawful, the data subject refuses to delete the personal data and instead requests the restriction of the use of personal data.
- The controller no longer needs the personal data for processing purposes, but the data subject needs them to assert, exercise or defend legal claims.
- The person concerned has objection to the processing acc. Art. 21 para. 1 DS-GVO and it is not yet clear whether the legitimate reasons of the person responsible outweigh those of the data subject.
If one of the above conditions is met and an affected person wishes to request the restriction of personal data stored by Quality.One, they may at any time contact an employee of the controller. The employee of Quality.One will cause the restriction of processing.
RIGHT TO INFORMATION
Any person affected by the processing of personal data shall have the right granted by the European legislature and the legislature at any time to obtain free information from the controller on the personal data stored about him and a copy of that information. In addition, the European legislator and regulator has provided the data subject with the following information:
- The processing purposes
- The categories of personal data being processed
- The recipients or categories of recipients to whom the personal data have been disclosed or are still being disclosed, in particular to recipients in third countries or to international organizations
- If possible, the planned duration for which the personal data will be stored or, if that is not possible, the criteria for determining that duration
- The existence of a right to rectification or erasure of the personal data concerning them, or to the limitation of the processing by the controller or a right to object to such processing
- The existence of a right of appeal to a supervisory authority
- If the personal data are not collected from the data subject: All available information about the origin of the data
- The existence of automated decision-making including profiling in accordance with Article 22 (1) and (4) of the GDPR and – at least in these cases – meaningful information on the logic involved, and the scope and intended impact of such processing on the data subject
Furthermore, the data subject has a right of access as to whether personal data has been transmitted to a third country or to an international organization. If this is the case, then the data subject has the right to obtain information about the appropriate guarantees in connection with the transfer. If a data subject wishes to avail himself of this right to information, he may, at any time, contact an employee of the controller.
DATA TRANSFERABILITY
Any person affected by the processing of personal data shall have the right granted by the European di-rective and Regulatory Authority to receive the personal data concerning him / her provided to a controller by the data subject in a structured, common and machine-readable format. It also has the right to transfer this data to another person without hindrance by the controller to whom the personal data has been provided, provided that the processing is carried out on the basis of the consent pursuant to Art. 6 para. 1 letter a DS-GVO or Art. 9 Abs. 2 letter a DS-BER or on a contract pursuant to Art. 6 para. 1 (b) of the GDPR and processing by automated means, unless the processing is necessary for the performance of a task of public interest or in the exercise of official authority delegated to the controller.
Furthermore, in exercising their right to data portability under Article 20 para. 1 DS-GVO the right to obtain that the personal data are transmitted directly from one person responsible to another person responsible, as far as this is technically feasible and if this does not affect the rights and freedoms of other persons.
To assert the right to data portability, the data subject may at any time contact a Quality.One employee.
RIGHT TO RECTIFICATION
Any person affected by the processing of personal data has the right granted by the European legislator to demand the immediate correction of inaccurate personal data concerning him. Furthermore, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary declaration, taking into account the purposes of the processing. If an affected person wishes to exercise this right of rectification, they may, at any time, contact an employee of the controller.
RIGHT TO OBJECT
Any person concerned by the processing of personal data shall have the right conferred by the European directive and regulatory authority at any time, for reasons arising from its particular situation, against the processing of personal data relating to it which, pursuant to Article 6 para. 1 letter e or f DS-GVO is filed to appeal. This also applies to profiling based on these provisions.
Quality.One will no longer process personal data in the event of an objection, unless we can prove compelling legitimate grounds for processing that outweigh the interests, rights and freedoms of the data subject, or the processing is for the purpose of asserting, exercising or defending legal claims.
If Quality.One processes personal data in order to operate direct mail, the data subject has the right to object at any time to the processing of personal data for the purpose of such advertising. This also applies to the profiling, as far as it is associated with such direct mail. If the data subject objects to Quality.One’s processing for direct marketing purposes, Quality.One will no longer process the personal data for these purposes.
In addition, the data subject has the right, for reasons arising from his / her particular situation, against the processing of personal data relating to him or her, which Quality.One uses for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 para. 1 DS-BER, objections shall be lodged unless such processing is necessary to fulfill a task of public interest.
In order to exercise the right of opposition, the data subject may directly contact any Quality.One employee or any other employee. The data subject is also free, in the context of the use of information society services, notwithstanding Directive 2002/58 / EC, to exercise his right of opposition by means of automated procedures using technical specifications.
RIGHT TO CANCELLATION (RIGHT TO BE FORGOTTEN)
Any person affected by the processing of personal data shall have the right granted by the European Directives and Regulators to require the controller to immediately delete the personal data concerning him, provided that one of the following reasons is satisfied and the processing is not required:
- The personal data has been collected for such purposes or otherwise processed for which they are no longer necessary.
- The data subject revokes their consent, to which the processing pursuant to Art. 6 para. 1 letter a DS-GVO or Art. 9 Abs. 2 (a) of the GDPR and that there is no other legal basis for processing.
- The data subject submits pursuant to Art. 21 para. 1 DS-GVO objection to the processing, and there are no legitimate reasons for the processing, or the data subject submits pursuant to Art. 21 para. 2 DS-GVO objection to the processing.
- The personal data was processed unlawfully.
- The deletion of personal data is necessary to fulfill a legal obligation under Union or national law, to which the controller is subject.
- The personal data were provided in relation to information society services offered in accordance with Art. 8 para. 1 DS-GMO levied.
If any of the above reasons are correct and a data subject wishes to arrange for the deletion of personal data held by Quality.One, they may, at any time, contact an employee of the controller. The employee of the Quality.One will arrange that the extinguishing request be fulfilled immediately.
If the personal data have been made public by Quality.One and our company is responsible in accordance with Art. 17 para. 1 DS-GVO committed to the deletion of personal data, the Quality.One takes appropriate measures, including technical means, to inform other data controllers who process the published personal data, taking into account the available technology and the implementation costs, the data subject has requested that these other data controllers delete all links to such personal data or copies or replications of such personal data, unless the processing is necessary. The employee of Quality.One will arrange the necessary in individual cases.
AUTOMATED DECISIONS IN INDIVIDUAL CASES INCLUDING PROFILING
Any person concerned with the processing of personal data shall have the right granted by the European directive and regulatory authority not to be subject to a decision based solely on automated processing, including profiling, which has a legal effect on it or, in a similar manner, significantly affects it; unless the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) permitted by Union or Member State legislation to which the controller is subject, and that legislation provides for appropriate measures to safeguard the rights and freedoms and the legitimate interests of the data subject; or (3) with the express consent of the data subject.
If the decision (1) is required for the conclusion or performance of a contract between the data subject and the controller or (2) is done with the express consent of the data subject, Quality.One shall take appropriate measures to safeguard the rights and freedoms and the legitimate interests the person concerned, including at least the right to obtain the intervention of a person by the controller, to express his / her own position and to challenge the decision.
If the data subject wishes to rely on automated decision-making rights, they may, at any time, contact an employee of the acountable.
RIGHT TO REVOKE A DATA PROTECTION CONSENT
Any person affected by the processing of personal data has the right, granted by the European directive and regulatory authority, to revoke consent to the processing of personal data at any time.
If the data subject wishes to assert their right to withdraw consent, they may, at any time, contact an employee of the accountable.
10. DATA PROTECTION IN APPLICATIONS AND IN THE APPLICATION PROCESS
The accountable collects and processes the personal data of applicants for the purpose of processing the application process. The processing can also be done electronically. This is particularly the case if an applicant submits corresponding application documents to the controller by electronic means, for example by email or via a web form available on the website. If the controller concludes a contract of employment with an applicant, the data transmitted will be stored for the purposes of the employment relationship in accordance with the law.
If no employment contract is concluded with the candidate by the controller, the application documents will be automatically deleted two months after the announcement of the rejection decision, unless deletion precludes other legitimate interests of the controller. Other legitimate interest in this sense, for example, a burden of proof in a procedure under the General Equal Treatment Act (AGG).
11. LEGAL BASIS OF PROCESSING
Art. 6 I lit. A DS-GMO serves our company as the legal basis for processing operations in which we obtain consent for a particular processing purpose. If the processing of personal data is necessary to fulfill a contract of which the data subject is a party, as is the case, for example, in processing operations necessary for the supply of goods or the provision of any other service or consideration, processing shall be based on Art. 6 I lit. b DS-GVO. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in the case of inquiries about our products or services. If our company is subject to a legal obligation which requires the processing of personal data, such as the fulfillment of tax obligations, the processing is based on Art. 6 I lit. c DS-GVO. In rare cases, the processing of personal data may be required to protect the vital interests of the data subject or another natural person.
This would be the case, for example, if a visitor to our premises were injured and his or her name, age, health insurance or other vital information would have to be passed on to a doctor, hospital or other third party. Then the processing would be based on Art. 6 I lit. d DS GMOs are based. Ultimately, processing operations could be based on Art. 6 I lit. f DS GMOs are based. Processing operations that are not covered by any of the above legal bases are based on this legal basis if processing is necessary to safeguard the legitimate interests of our company or a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned prevail. Such processing operations are particularly permitted because they have been specifically mentioned by the European legislator. In that regard, it considered that a legitimate interest could be assumed if the data subject is a customer of the controller (recital 47, second sentence, DS-BER).
12. BENEFICIAL INTERESTS IN THE PROCESSING THAT ARE BEING PURSUED BY THE CONTROLLER OR A THIRD PARTY
Is the processing of personal data based on Article 6 I lit. f DS-GMO is our legitimate interest in conducting our business for the benefit of all of our employees and our shareholders.
13. DURATION FOR WHICH THE PERSONAL DATA IS STORED
The criterion for the duration of the storage of personal data is the respective statutory retention period. After the deadline, the corresponding data will be routinely deleted, if they are no longer required to fulfill the contract or to initiate a contract.
14. LEGAL OR CONTRACTUAL PROVISIONS FOR THE PROVISION OF PERSONAL DATA; NECESSITY FOR THE CONCLUSION OF THE CONTRACT; OBLIGATION OF THE DATA SUBJECT TO PROVIDE THE PERSONAL DATA; POSSIBLE CONSEQUENCES OF NON-PROVISION
We clarify that the provision of personal information is in part required by law (such as tax regulations) or may result from contractual arrangements (such as details of the contractor). Occasionally it may be necessary for a contract to be concluded that an affected person provides us with personal data that must subsequently be processed by us. For example, the data subject is required to provide us with personal information when our company concludes a contract with her. Failure to provide the personal data would mean that the contract with the person concerned could not be closed. Prior to any personal data being provided by the person concerned, the person concerned must contact one of our employees. Our employee will inform the individual on a case-by-case basis whether the provision of the personal data is required by law or contract or required for the conclusion of the contract, whether there is an obligation to provide the personal data, and what would have resulted from the failure to provide the personal data.
15. EXISTENCE OF AUTOMATED DECISION-MAKING
As a responsible company, we refrain from automatic decision-making or profiling.
This Privacy Policy was created by the privacy statement generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which acts as External Data Protection Officer Munich, in cooperation with the lawyer for data protection law Christian Solmecke.
As of: May 23, 2018