Privacy Policy

Data Privacy Statement

As of: 27 November 2020

We take the protection of your data very seriously and attach the utmost importance to compliance with the EU General Data Protection Regulation (GDPR). By means of this data privacy policy, we would like to inform you, therefore, of which data we process for what purpose. This will enable you to decide yourself which data we are permitted to use for what purpose.

Table of Contents

1 Controller
2 Processing of Personal Data
3 Sharing with Third Parties
4 Storage
5 Newsletter
6 Registration for our Image Database
7 Right of Access to Your Personal Data / Right to Revoke
8 Data Security Measures
8.1 Technical measures
8.2 Organisational measures
7 Data Security on our Social Media Channels
9 Recording and Processing of Your Personal Data when You Visit our Website
9.1 Data recording via Google Analytics
9.2 Cookies
9.2.1 Functional cookie
9.2.2 Analysis cookies
9.3 Captchas
9.4 Links to third-party websites (external websites)
9.5 Information on data sharing with the USA
10 Use of Script Libraries (Google Web Fonts)
11 Amendments
12 Complaints

 

1 Controller

The following entity is responsible for the processing and storage of personal data:

Undercover GmbH
Nordostpark 74
90411 Nuremberg

Executive Directors: Michael Fortdran, Manfred Duschl, Uwe Weiler

Email:  office@undercover-germany.de

Telephone:  +49 911 / 956667-0

External data protection officer: Mario Heiß

MH IT-Services
Am Wagnersberg 7
91056 Erlangen

Email:  DS-Beauftragter@mh-it-services.de

Telephone:  +49 9131 / 9262739

 

2 Processing of Personal Data

Undercover GmbH processes personal data for the purpose of establishing, performing or terminating a contractual or similar obligation or using a service made available.
The following serve as examples:
•    orders placed verbally, over the telephone or in writing, the preparation of an offer beforehand and the stages of execution of the order, such as invoicing,
•    enquiries, complaints or notifications that we receive by email, by fax, via the contact form or by telephone.

Only the personal data needed for dealing with your concern shall be processed. The personal data shall include, among other information, your name, email address or telephone number or your postal address. In the case of a purchase contract, we shall obtain reports (see the table below) from third parties (e.g. credit reference agencies and public registers). Submission of your data shall take place only with your express consent. Use of your personal data for other purposes (in particular for advertising purposes) shall require your express consent.

 

Reports are issued by: Address:
Creditreform Nürnberg Aumüller KG Theodorstraße 11, 90489 Nuremberg
Euler Hermes Deutschland Gasstraße 29, 22761 Hamburg

 3 Sharing with Third Parties

Your personal data shall be passed on to the relevant employees within Undercover GmbH. Sharing with third parties shall take place only for the purpose of fulfilling your request.
Third parties may include, among others, appointed service providers, such as Undercover GmbH’s logistics service provider for the delivery of your order, or cooperation partners for the shipment of a prize in the case of participation in a prize competition.
On request, we shall send you a record of the processing activities. To make such request, please write to office@undercover-germany.de.
Your personal data shall not be shared with other third parties without your express consent, unless we are legally obliged to do so. Nor shall your personal data be marketed.

 4 Storage

The data that you provide shall be stored by us only as long as necessary for fulfilling your request or complying with statutory provisions.
In this respect, retention periods under fiscal law and commercial law shall be taken into account.
You may revoke your consent to storage at any time by writing an email to widerruf@undercover-germany.de.

Commercial or business contact

Personal data recorded in the course of commercial or business contact shall be stored by us within the period prescribed under fiscal law. In Germany, this period is 10 years according to Section 257 (4) HGB [German Commercial Code] and Section 147 (3) AO [Tax Code]. Details relating to the terms of trade and business can be found in our Terms of Delivery and Payment.

Applications

Owing to statutory obligations, your application documents and, therefore, your personal data shall be electronically stored with us for up to 6 months after the application procedure has ended. If we store your application beyond this period, we shall obtain your written consent thereto. You may revoke this consent at any time by writing an email to widerruf@undercover-germany.de.

Complaints

If you lodge a complaint with us, we shall store your personal data as well as the correspondence for the purpose of assertion, exercise or defence of legal claims for up to a maximum of 3 years, unless a longer retention period is stipulated by law.

Participation in a prize competition

If you take part in a prize competition, your personal data shall be stored and processed exclusively for the purpose of the prize competition. Your personal data shall be deleted following the prize draw. If you win, we shall store your personal data for up to a maximum of three years for the purpose of assertion, exercise or defence of legal claims. If we store your personal data beyond this period, we shall obtain your written consent thereto. You may revoke this consent at any time by writing an email to widerruf@undercover-germany.de.

General enquiries

In the case of general enquiries, your personal data shall be stored exclusively for the purpose of your enquiry. If we store your personal data for a longer period in order to get back to you at a later date, we shall obtain your written consent thereto. You may revoke this consent at any time by writing an email to widerruf@undercover-germany.de.

Image database

By registering to use the Undercover image database, you consent to the storage of your personal data. You may delete your account at any time.

Logging of log-ins to the image database

For reasons of technical security, in particular for averting attempts to attack our web server, the following data are stored by us for a short period by means of a session cookie: username, email address, date and time of the log-in.
After the user has logged out, the data are truncated and thus anonymised at domain level so that it is no longer possible to establish a link to the individual user (server log files). Additionally, the data are processed in anonymised form for statistical purposes; there is no cross-checking against other data stocks or sharing with third parties, even in part.

Logging of downloads of material

For reasons of technical security, in particular for averting attempts to attack our web server, the following data are stored by us:

  •  date and time of the request
  • name of the file requested
  • site from which the file was requested
  • access status (file transferred, file not found, etc.)
  • web browser used and operating system used
  • complete IP address of the requesting computer
  • data volume transferred

When our image database is logged into, personal data relating to the images downloaded are stored for preventing improper downloading of copyright-protected material, some in anonymised form for statistical purposes, e.g. for evaluating the popularity of products.

 5 Newsletter

If you have made a purchase with us for commercial purposes, we shall inform you of similar goods via our newsletter. The newsletter contains news relating to our product range as well as licence-related topics and information relating to Undercover GmbH. If you do not wish to receive any promotional information by email, you may opt out of receiving the newsletter at any time by writing to widerruf@undercover-germany.de.

6 Registration for our Image Database

If you register for use of our personalised services, some personal data, such as your name and address as well as your contact and communication details such as your telephone number and email address, shall be collected.

If you are registered with us, you will be able to access content and services that we only offer to registered users. Registered users also have the option of altering or deleting at any time, if necessary, the data provided during registration.

Moreover, we shall, of course, provide you at any time with information concerning your personal data stored by us. We shall also be happy to rectify or delete these data at your request, unless statutory retention obligations preclude this. To contact us in this connection, please write to widerruf@undercover-germany.de.

7 Right of Access to Your Personal Data / Right to Revoke

Under Section 15 GDPR, you have the right to receive on request at any time, free of charge, information concerning your personal data stored with us. If we have stored incorrect data relating to your person, you have the right to rectification of your data. If you wish to have your collected data deleted, or to object to our processing of these data, you may revoke at any time, without giving reasons, your consent to the processing and storage of your data. To request access to your personal data or to revoke your consent, please write to widerruf@undercover-germany.de. Insofar as your request for deletion is precluded by reasons under fiscal law or by other legal obligations, you have the right to obtain restriction of the processing of your data. Furthermore, you have the right to data portability insofar as you have consented to the processing of your data or have entered into a contract with us.

8 Data Security Measures

In order to protect your data against tampering by external parties, we take technical and organisational measures to bring about security in accordance with Article 28 (3) (c) and Article 32 GDPR, in particular in conjunction with Art. 5 (1) and (2) GDPR. Overall, the measures to be implemented constitute data security measures and measures for ensuring a level of protection that is appropriate to the risk in terms of the confidentiality, integrity, availability and resilience of the systems. The technical measures as well as the organisational measures are subject to technical progress and further development.

8.1 Technical measures

Our website www.undercover-germany.de is encrypted with a 256-bit-encryption SSL certificate from the company Domains Priced Right, formerly Starfield Secure. If, therefore, you use the contact form to send us an enquiry or a complaint for example, your data shall be indecipherable for third parties. You can recognise SSL encryption by the prefix “https” in the website link.

Our hoster is
domainfactory GmbH
Oskar-Meester-Str. 33
85737 Ismaning

8.2 Organisational measures

Our employees and the service providers appointed by us are bound to confidentiality and data secrecy in accordance with Section 5 BDSG [German Federal Data Protection Act].

9 Recording and Processing of Your Personal Data when You Visit our Website

9.1 Data recording via Google Analytics

We use Google Analytics to optimise our Internet offering. Google Analytics is a web analysis service from Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses so-called “cookies”, text files that are stored on your computer and enable your use of the website to be analysed. Information such as, for example, the browser type, the time spent or the sites accessed is recorded. The information generated by such cookie concerning your use of this website will normally be transferred to a Google server in the USA and stored there. Google will use this information on our behalf in order to evaluate your use of the website, put together reports on the website activities and provide the website operator with other services relating to use of the website and the Internet.

IP anonymisation has been activated on this website by adding the code “_anonymizelp()” to Google Analytics. As a result, the users’ IP address is, within the Member States of the European Union or in other signatory states to the Agreement on the European Economic Area, truncated by Google beforehand. Only in exceptional cases is the full IP address transferred to a Google server in the US and truncated there.

The IP address transmitted by your browser within Google Analytics will not be combined with other Google data.

You can prevent the storage of these cookies by setting your browser software accordingly. Please note however that, if you do so, you may not be able to fully use all the features of this website. By downloading and installing the browser plugin available at the following link, users can, moreover, prevent data (including their IP address) generated by such cookie relating to their use of the website from being collected and transmitted to Google and being processed by Google.
The current link is: https://tools.google.com/dlpage/gaoptout?hl=de

Further information on terms of use and data privacy can be found at https://www.google.com/analytics/terms/de.html or at https://policies.google.com/terms?hl=en

9.2 Cookies

Undercover uses cookies on its website. Cookies are text files that are stored on your device and enable efficient functioning and analysis of your use of the website. There are two different types of cookies:

9.2.1 Functional cookie

Our functional cookies include cookies that enable optimum display and use of the website. We use the following cookies:

Name of the cookie Function Lifetime Responsible
Cookieconsent_dismissed Records whether the user has accepted the cookie notice. 1 year Undercover
Video Records whether the video has been displayed to the user. Until the browser session ends Undercover
PHPSESSID Allots, when the contact form is used, a session ID for defence against spam Until the browser session ends Undercover
uncodeAI.css
uncodeAI.images
uncodeAI.screen
Records the user’s resolution so that content is correctly scaled Until the browser session ends Undercover
Uncode_privacy[consent_types] Records which data privacy settings the user has consented to. 1 year Undercover

You can activate or oppose the storage of these cookies by setting your browser software accordingly. If you decline to accept the storage of the cookies, you will possibly only be able to use the website to a limited extent.

If you use the website www.undercover-germany.de from different devices, you will have to set your desired cookie settings, in the browsers used, on all devices concerned.

9.2.2 Analysis cookies

Undercover uses the analysis tool Google Analytics on its website. Cookies record data, for example the duration of your session, the search keywords via which you have arrived at our website, or which subsites you have accessed. Your IP address will be transmitted in anonymised form for this purpose. It is not possible to draw conclusions about the individual user. With the aid of these cookies, we can analysis the use of our website and make our website appealing to our users.
We use the following cookies:

Name of the cookie Function Lifetime Responsible
_ga Anonymously differentiates between individual users 2 years Google Analytics
_gat Anonymously differentiates between individual users 24 hours  Google Analytics
_gid Throttles the request rate 10 minutes Google Analytics

You can prevent the storage of the cookies by setting your browser software accordingly. Please note however that, if you do so, you may not be able to fully use all the features of this website. By downloading and installing the browser plugin available at the following link, users can, moreover, prevent data (including their IP address) generated by such cookie relating to their use of the website from being collected and transmitted to Google and being processed by Google.
The current link is: https://tools.google.com/dlpage/gaoptout?hl=de .

If you use the website www.undercover-germany.de from different devices, you will have to set your desired cookie settings, in the browsers used, on all devices concerned.
Further information on terms of use and data privacy can be found at
https://policies.google.com/privacy?hl=de

https://www.google.com/analytics/terms/?hl=de

 

9.3 Captchas

In certain cases, this website uses Google reCAPTCHA v2 to prevent automatic programmes / bots from using text fields. This increases the security of our website and averts SPAM for the user. This is also in our legitimate interest and fulfils our legal obligation.
The data collected comprise hardware and software information, e.g. device and application data as well as the results of the security queries. These data are transmitted to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The data are not used for personalised advertising.
Further information can be viewed in Google’s Data Privacy Statement: https://policies.google.com/privacy .

Further documentation is available here:
https://developers.google.com/recaptcha/
https://www.google.com/recaptcha/admin/create

Legal bases:
Art. 6 (1) (c) GDPR (in the case of processing of data in connection with a legal obligation)
Art. 6 (1) (f) GDPR (in the case of processing activities in keeping with the aforementioned legitimate interest)

9.4 Links to third-party websites (external websites)

The website www.undercover-germany.de links to third-party websites, e.g. the websites of our distributors in the distributor search or on social media channels. Our data privacy policy applies merely to the website scooli.com or undercover-germany.de. We accept no liability for the data privacy policies of the third-party websites linked to. Moreover, we shall have no control over the recording, use and storage of your personal data when you use third-party websites. For information on data privacy relating to such website, please read the data privacy policy of the website linked to. Whenever we link to third-party websites, we shall point this out to you on our website. The website will be displayed via a new browser window.

9.5 Information on data sharing with the USA

Tools from companies based in the USA are, among others, integrated into our website. When these tools are active, your personal data can be passed on to the US servers of the respective companies. Please note that the USA is not a safe third country within the meaning of EU data protection law. US companies are obliged to provide personal data to security authorities without you as the data subject being able to take legal action against this. Therefore, it cannot be ruled out that your data contained on US servers will be processed, evaluated and permanently stored by US authorities (e.g. secret services) for monitoring purposes. We have no influence over these processing activities.
10 Use of Script Libraries (Google Web Fonts)
In order to show our content correctly and in a graphically appealing manner across all browsers, this website uses script libraries and font libraries, e.g. Google Web Fonts https://www.google.com/webfonts.

Google Web Fonts will be transferred to your browser’s cache in order to prevent multiple loading. If the browser does not support Google Web Fonts or prohibits these from being accessed, content will be displayed in a standard font.

Accessing of script libraries or font libraries automatically triggers a connection to the operator of the library. It is theoretically possible – but currently also unclear whether and if so for what purposes – that operators of such libraries collect data.

The data privacy policy of the library operator Google can be found here: https://www.google.com/policies/privacy/.

11 Amendments

The Data Privacy Statement is regularly updated or amended. You will not be notified thereof. Therefore, we recommend that you check the Data Privacy Statement before you use the website www.undercover-germany.de.

12 Complaints

We take the protection of your data very seriously therefore and attach utmost importance to compliance with the data protection laws. If you nevertheless feel that we are not treating your data in conformity with the data protection laws, please do not hesitate to contact us. Together with you, we shall deal with your concern in a speedy and fair manner. Our contact details can be found in Section 1.
You also have the option of lodging a complaint with the aforementioned data protection officer or with a data protection supervisory authority. You can find our data protection officer’s contact details in Section 1.

Our relevant data protection supervisory authority is:

Bayerisches Landesamt für Datenschutzaufsicht [Bavarian State Office for Data Protection Supervision]
Promenade 27
91522 Ansbach
Telephone: 0981 53 1300