This privacy policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the associated websites, functions and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terms used, such as “processing” or “controller”, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Data Controller

Selbstlagerbox GmbH
Zwickauer Str. 56b
DE-04103 Leipzig
Email address: datenschutz@selbstlagerbox.de
Managing Directors: Mathias Ihle, Janine Krakow
Link to legal notice: https://www.selbstlagerbox.de/impressum/

Data Protection Officer:

Sascha Kugler
Innovation Technology Management ITM GmbH
Wolfener Str. 32-34, Building 2B
12681 Berlin
Telephone: 030 / 439 720 340

Types of data processed:

– Personal details (e.g., names, addresses).
– Contact details (e.g. email, telephone numbers).
– Content data (e.g. text entries, photographs, videos).
– Usage data (e.g. websites visited, interest in content, access times).
– Meta/communication data (e.g. device information, IP addresses).

Categories of data subjects

Visitors and users of the online service (hereinafter, we also refer to data subjects collectively as “users”).

Purpose of processing

– Provision of the online service, its functions and content.
– Responding to contact enquiries and communicating with users.
– Security measures.
– Audience measurement/marketing

Terms used

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

"Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.

“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Relevant legal bases

In accordance with Article 13 of the GDPR, we inform you of the legal bases for our data processing. Where the legal basis is not specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and (b) and Article 7 of the GDPR; the legal basis for processing to fulfil our services, carry out contractual measures and respond to enquiries is Article 6(1)(b) of the GDPR; , the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.

Security measures

In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability and its segregation. Furthermore, we have established procedures to ensure the exercise of data subjects’ rights, the erasure of data and a response to data breaches. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

Cooperation with data processors and third parties

Where, in the course of our processing activities, we disclose data to other individuals or organisations (data processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

Where we engage third parties to process data on the basis of a so-called ‘data processing agreement’, this is done in accordance with Article 28 of the GDPR.

Transfers to third countries

Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or the disclosure or transfer of data to third parties, this takes place only where it is necessary for the fulfilment of our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process or have the data processed in a third country only if the specific conditions of Articles 44 et seq. of the GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards, such as the officially recognised determination of a level of data protection equivalent to that of the EU (e.g. for the USA through the ‘Privacy Shield’) or compliance with officially recognised specific contractual obligations (so-called ‘standard contractual clauses’).

Rights of data subjects

You have the right to request confirmation as to whether data concerning you is being processed, as well as access to this data, further information and a copy of the data in accordance with Article 15 of the GDPR.

In accordance with Article 16 of the GDPR, you have the right to request that data concerning you be completed or that inaccurate data concerning you be rectified.

In accordance with Article 17 of the GDPR, you have the right to request that the relevant data be erased without delay, or alternatively, in accordance with Article 18 of the GDPR, to request a restriction on the processing of the data.

You have the right to request that the data concerning you which you have provided to us be returned to you in accordance with Article 20 of the GDPR and to request that it be transferred to other controllers.

You also have the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.

Right to withdraw consent

You have the right to withdraw any consent given in accordance with Article 7(3) of the GDPR with effect for the future.

Right to object

You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to processing for the purposes of direct marketing.

Cookies and the right to object to direct marketing

‘Cookies’ are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Cookies that are deleted once a user leaves an online service and closes their browser are referred to as temporary cookies, or ‘session cookies’ or ‘transient cookies’. Such a cookie may, for example, store the contents of a shopping basket in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent”. For example, the login status may be stored if users return to the site after several days. Similarly, such a cookie may store the user’s interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by providers other than the controller operating the online service (otherwise, if only the controller’s own cookies are used, these are referred to as “first-party cookies”).

We may use temporary and permanent cookies and provide information about this in our privacy policy.

If users do not wish for cookies to be stored on their computer, they are asked to deactivate the relevant option in their browser’s settings. Stored cookies can be deleted via the browser’s settings. Disabling cookies may result in functional limitations of this online service.

A general objection to the use of cookies for online marketing purposes can be lodged for a wide range of services, particularly in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in your browser settings. Please note that, in such cases, you may not be able to use all the features of this website.

Deletion of data

The data we process is deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this privacy policy, the data stored by us is deleted as soon as it is no longer required for its intended purpose and there are no legal retention obligations preventing its deletion. If the data is not deleted because it is required for other, legally permissible purposes , its processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

In accordance with legal requirements in Germany, data is retained for a period of 10 years in particular, pursuant to Sections 147(1) AO, 257(1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting documents, trading ledgers, documents relevant for taxation, etc.) and for 6 years in accordance with Section 257(1) nos. 2 and 3, (4) HGB (commercial correspondence).

In accordance with statutory requirements in Austria, documents must be retained for 7 years in particular pursuant to Section 132(1) of the Austrian Federal Tax Code (BAO) (accounting records, receipts/invoices, accounts, supporting documents, business papers, statements of income and expenditure, etc.), for 22 years in connection with real estate, and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States for which the Mini One-Stop Shop (MOSS) is used.

Business-related processing

In addition, we process
– Contract data (e.g., subject matter of the contract, term, customer category).
– Payment data (e.g., bank details, payment history)
from our customers, prospective customers and business partners for the purpose of providing contractual services, customer service and support, marketing, advertising and market research.

Processing of rentals in the online shop

We process our customers’ data as part of the ordering process (rentals) in our online shop to enable them to select and order the chosen products and services, as well as to facilitate payment, delivery and fulfilment.

The data processed includes inventory data, communication data, contract data and payment data, and the data subjects affected by the processing include our customers, prospective customers and other business partners. The processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer services. In doing so, we use session cookies to store the contents of the shopping basket.

Processing is carried out on the basis of Article 6(1)(b) (execution of order processes) and (c) (legally required archiving) of the GDPR. The information marked as necessary for the establishment and performance of the contract is required for this purpose. We only disclose the data to third parties in connection with delivery, payment or within the scope of legal permissions and obligations towards legal advisers and authorities. The data is only processed in third countries if this is necessary for the performance of the contract (e.g. at the customer’s request for delivery or payment).

When you register for or use our online services, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests, as well as the users’ interests in protection against misuse and other unauthorised use. This data is not disclosed to third parties as a matter of principle, unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Article 6(1)(c) of the GDPR.

The data is deleted once statutory warranty and similar obligations have expired; the necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion takes place once these have expired (end of commercial law (6 years) and tax law (10 years) retention obligations).

External payment service providers

We use external payment service providers via whose platforms users and we can carry out payment transactions: PayPal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full), Stripe (https://stripe.com/en-de/legal/consumer).

In the context of fulfilling contracts, we use payment service providers on the basis of Article 6(1)(b) of the GDPR. Furthermore, we use external payment service providers on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR in order to offer our users effective and secure payment options.

The data processed by the payment service providers includes master data, such as name and address; bank details, such as account numbers or credit card numbers; passwords, TANs and checksums; as well as details relating to the contract, amounts and recipients. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account or credit card-related information, but only information confirming or rejecting the payment. In some circumstances, the data may be transmitted by the payment service providers to credit reference agencies. The purpose of this transmission is to verify identity and creditworthiness. In this regard, we refer you to the terms and conditions and privacy policies of the payment service providers.

The terms and conditions and privacy policies of the respective payment service providers apply to payment transactions; these are available on the respective websites or within the transaction applications. We also refer you to these for further information and for exercising your rights of withdrawal, access and other data subject rights.

Administration, financial accounting, office organisation, contact management

We process data in connection with administrative tasks, the organisation of our operations, financial accounting and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in connection with the provision of our contractual services. The legal bases for processing are Article 6(1)(c) and Article 6(1)(f) of the GDPR. This processing affects customers, prospective customers, business partners and website visitors. The purpose and our interest in the processing lie in administration, financial accounting, office organisation and the archiving of data – in other words, tasks that serve to maintain our business activities, fulfil our duties and provide our services. The erasure of data relating to contractual services and contractual communication is in accordance with the information provided regarding these processing activities.

In this context, we disclose or transfer data to the tax authorities, advisers such as tax consultants or auditors, as well as other fee-charging bodies and payment service providers.

Furthermore, based on our business interests, we store information on suppliers, event organisers and other business partners, e.g. for the purpose of contacting them at a later date. We generally store this predominantly company-related data on a permanent basis.

Business analyses and market research

In order to operate our business efficiently and to identify market trends and the wishes of contractual partners and users, we analyse the data available to us regarding business transactions, contracts, enquiries, etc. In doing so, we process inventory data, communication data, contract data, payment data, usage data and metadata on the basis of Article 6(1)(f) of the GDPR, whereby the data subjects include contractual partners, prospective customers, customers, visitors and users of our online offering.

The analyses are carried out for the purposes of business evaluations, marketing and market research. In doing so, we may take into account the profiles of registered users, including details such as the services they have used. The analyses serve to improve user-friendliness, the optimisation of our offering and business efficiency. The analyses are used solely by us and are not disclosed externally, unless they are anonymous analyses with aggregated values.

Where these analyses or profiles are personal data, they will be deleted or anonymised upon the user’s termination of the contract, or otherwise after two years from the conclusion of the contract. Furthermore, overall business analyses and general trend assessments are compiled anonymously wherever possible.

Comments and posts

When users leave comments or other contributions, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. This is for our protection in the event that someone posts unlawful content in comments or contributions (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or contribution and are therefore interested in the author’s identity.

Furthermore, we reserve the right, on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR, to process users’ data for the purpose of spam detection.

On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.

The data provided in the context of comments and posts will be stored permanently by us until the user objects.

Contact

When contacting us (e.g. via the contact form, email, telephone or social media), the user’s details are processed for the purpose of handling the contact enquiry and its processing in accordance with Article 6(1)(b) of the GDPR. The user’s details may be stored in a Customer Relationship Management system (‘CRM system’) or a comparable enquiry management system.

We delete the enquiries once they are no longer required. We review the necessity of retention every two years; furthermore, statutory archiving obligations apply.

CRM system from Salesforce

We use the CRM system provided by salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 Munich, to process user enquiries more quickly and efficiently and to manage customers and contracts (legitimate interest pursuant to Article 6(1)(f) of the GDPR).

Salesforce is certified under the Privacy Shield Agreement and thereby offers an additional guarantee of compliance with European data protection law where data is processed in the USA (https://www.privacyshield.gov/participant?id=a2zt0000000KzLyAAK&status=Active).

Salesforce uses users’ data solely for the technical processing of enquiries and does not pass it on to third parties. To use Salesforce, users must at least provide a valid email address. Pseudonymous use is possible. During the processing of service enquiries, it may be necessary to collect further data (name, address).

Users can find further information in the Salesforce privacy policy: https://www.salesforce.com/de/company/privacy/.

Hosting and email dispatch

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we utilise for the purpose of operating this online service.

In doing so, we, or our hosting provider, process inventory data, contact details, content data, contractual data, usage data, metadata and communication data relating to customers, prospective customers and visitors to this online service on the basis of our legitimate interests in the efficient and secure provision of this online service in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).

Collection of access data and log files

We, or our hosting provider, collect data on every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. Access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address and the requesting provider.

Log file information is stored for a maximum of 7 days for security reasons (e.g. to investigate misuse or fraud) and is then deleted. Data that must be retained for further evidence purposes is exempt from deletion until the respective incident has been fully clarified.

Appointment booking via Calenso

We use the external provider Calenso to book appointments at our locations. This is a company based in Switzerland. To book an appointment, we store your name and email address, as well as the agreed appointment times. You do not need to create a user account to book an appointment. You may request the deletion of your data at any time. We have deliberately chosen a provider based in Switzerland that complies with the GDPR guidelines. You can find out more about Calenso’s privacy policy here: https://www.calenso.com/datenschutz/

Google Analytics

On the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is usually transmitted to a Google server in the USA and stored there.

Google is certified under the Privacy Shield Agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

Google will use this information on our behalf to evaluate how users use our website, to compile reports on activity within the website, and to provide us with further services relating to the use of the website and internet usage. In doing so, pseudonymous user profiles may be created from the processed data.

We only use Google Analytics with IP anonymisation enabled. This means that the IP address of users is truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.

The IP address transmitted by the user’s browser is not combined with other data held by Google. Users can prevent the storage of cookies by adjusting their browser software settings accordingly; users can also prevent the collection of data generated by the cookie and relating to their use of the online service by Google, as well as the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

Further information on Google’s use of data, as well as options for settings and objections, can be found in Google’s privacy policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).

Users’ personal data is deleted or anonymised after 14 months.

Google Universal Analytics

We use Google Analytics in its “Universal Analytics” form. “Universal Analytics” refers to a Google Analytics method in which user analysis is based on a pseudonymous user ID, thereby creating a pseudonymous user profile containing information from the use of various devices (so-called “cross-device tracking”).

Google AdWords and conversion tracking

We use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (“Google”) on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR).

Google is certified under the Privacy Shield Agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

We use the Google “AdWords” online marketing service to place adverts on the Google advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who are likely to be interested in the adverts. This allows us to display adverts for and within our online offering in a more targeted manner, so as to present users only with adverts that potentially match their interests. If, for example, a user is shown adverts for products in which they have expressed an interest on other online platforms, this is referred to as “remarketing”. For these purposes, when our website or other websites on which the Google advertising network is active are accessed, a Google code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are embedded in the website. With their help, an individual cookie, i.e. a small file, is stored on the user’s device (comparable technologies may also be used instead of cookies). This file records which websites the user has visited, what content they are interested in and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of the online service.

We also receive an individual ‘conversion cookie’. The information collected via the cookie is used by Google to generate conversion statistics for us. However, we only receive the anonymous total number of users who clicked on our advert and were redirected to a page tagged with a conversion tracking tag. We do not, however, receive any information that can be used to personally identify users.

User data is processed pseudonymously within the Google advertising network. This means that Google does not, for example, store or process the user’s name or email address, but instead processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. This means that, from Google’s perspective, the adverts are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected about users is transmitted to Google and stored on Google’s servers in the USA.

Further information on Google’s use of data, as well as options for settings and opting out, can be found in Google’s Privacy Policy (https://policies.google.com/technologies/ads and at https://policies.google.com/technologies/partner-sites) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).

Leadinfo

We use the lead generation service provided by Leadinfo B.V., Rotterdam, Netherlands. This service identifies visits to our website by businesses using IP addresses and displays publicly available information to us, such as company names or addresses. In addition, Leadinfo sets two first-party cookies to analyse user behaviour on our website and processes domains from form submissions (e.g. “leadinfo.com”) to correlate IP addresses with companies and improve its services. Further information can be found at www.leadinfo.com. On this page:www.leadinfo.com/en/opt-out , you have the option to opt out. If you opt out, your data will no longer be collected by Leadinfo.

Mailchimp

We use Mailchimp from The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE Suite 5000, Atlanta, GA 30308 USA (Mailchimp) to send our newsletter. This enables us to contact subscribers directly. In addition, we analyse your usage behaviour to optimise our offering.

To this end, we pass on the following personal data to Mailchimp:

[Email address]
[First name]
[Surname]

Mailchimp is the recipient of your personal data and acts as a data processor on our behalf in relation to the sending of our newsletter. The processing of the data specified in this section is not required by law or contract. Without your consent and the provision of your personal data, we cannot send you a newsletter.

In addition, Mailchimp collects the following personal data using cookies and other tracking methods: information about your device (IP address, device information, operating system, browser ID, information about the application you use to read your emails, and further information about hardware and internet connection). Furthermore, usage data is collected, such as the date and time you opened the email/campaign and browser activity (e.g. which emails/webpages were opened). Mailchimp requires this data to ensure the security and reliability of its systems, compliance with the terms of use, and to prevent misuse. This corresponds to Mailchimp’s legitimate interest (pursuant to Article 6(1)(f) of the GDPR) and serves the purpose of contract performance (pursuant to Article 6(1)(b) of the GDPR). Furthermore, Mailchimp analyses performance data, such as email delivery statistics and other communication data. This information is used to compile usage and performance statistics for the services.

Mailchimp also collects information about you from other sources. Personal data is collected via social media and other third-party data providers over an unspecified period and to an unspecified extent. We have no influence over this process.

Further information on options to object to or have your data removed from Mailchimp can be found at: https://mailchimp.com/legal/privacy/#3._Privacy_for_Contacts

The legal basis for this processing is your consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent to the processing of your personal data at any time. A link to do so is included in all communications. You may also withdraw your consent via the contact details provided: Withdrawing your consent does not affect the lawfulness of any processing carried out prior to such withdrawal.

Your data will be processed for as long as the relevant consent remains in place. Apart from this, it will be deleted upon termination of the contract between us and Mailchimp, unless legal requirements necessitate further storage.

Mailchimp has implemented compliance measures for international data transfers. These apply to all global activities in which Mailchimp processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). For further information, please visit: https://mailchimp.com/legal/data-processing-addendum/

Facebook Pixel

With the help of the Facebook Pixel, Facebook is able to identify visitors to our website as a target group for the display of advertisements (so-called ‘Facebook Ads’). Accordingly, we use the Facebook Pixel to ensure that the Facebook Ads we place are shown only to those users on Facebook and within the services of Facebook’s partner networks (the so-called ‘Audience Network’

www.facebook.com/audiencenetwork/">https://www.facebook.com/audiencenetwork/ ) to those users who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interest in specific topics or products, as indicated by the websites visited) that we transmit to Facebook (so-called “Custom Audiences”). We also use the Facebook Pixel to ensure that our Facebook ads match users’ potential interests and do not appear intrusive. With the help of the Facebook Pixel, we can also track the effectiveness of Facebook adverts for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook advert (so-called “conversion tracking”).

Hotjar (analytics tool)

We use Hotjar to better understand our users’ needs and to optimise the user experience on this website. Hotjar is a service provided by Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141, Malta, Europe.

Hotjar enables us to better understand user behaviour (e.g. how much time visitors spend on which pages, which links they click, what they like or dislike, etc.) and thus helps us to improve our online offering. Hotjar uses cookies and other technologies to collect data about our visitors’ behaviour and their devices, in particular:

- the device’s IP address (recorded during the session and stored in anonymised form),

- screen size, device type, browser information,

- geographical location data (country only),

- preferred language setting.

Hotjar stores this information in a pseudonymised user profile. Processing is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in optimising our website.

Hotjar is contractually bound as a data processor under Article 28 of the GDPR and is not permitted to use or disclose the data collected on our behalf for its own purposes.

Further information can be found at https://www.hotjar.com/legal/policies/privacy/ and in the ‘About Hotjar’ section on the Hotjar support page.

Single Sign-On

The terms “single sign-on”, “single sign-on login” or “single sign-on authentication” refer to procedures that allow users to log in to our online service using a user account with a single sign-on provider (e.g. a social network). A prerequisite for single sign-on authentication is that users are registered with the relevant single sign-on provider and enter the required login details in the online form provided, or are already logged in with the single sign-on provider and confirm the single sign-on login via a button.

Authentication takes place directly with the respective single sign-on provider. As part of this authentication process, we receive a user ID indicating that the user is logged in to the respective single sign-on provider under this user ID, along with an ID that cannot be used by us for any other purposes (known as a ‘user handle’). Whether additional data is transmitted to us depends solely on the single sign-on procedure used, the data sharing options selected during authentication, and also on what data users have shared in the privacy or other settings of their user account with the single sign-on provider. Depending on the single sign-on provider and the user’s choices, this may involve various data; as a rule, it comprises the email address and the username. The password entered as part of the single sign-on procedure with the single sign-on provider is neither visible to us nor stored by us.

Users are asked to note that the details we hold about them may be automatically synchronised with their user account with the single sign-on provider; however, this is not always possible or does not always actually take place. If, for example, users’ email addresses change, they must update these manually in their user account with us.

We may use the single sign-on login, provided this has been agreed with users, as part of or prior to the performance of the contract, insofar as users have been asked to process this as part of their consent; otherwise, we use it on the basis of our legitimate interests and the users’ interests in an effective and secure login system.

Should users decide at any time that they no longer wish to use the link to their user account with the single sign-on provider for the single sign-on procedure, they must remove this link within their user account with the single sign-on provider. If users wish to have their data deleted by us, they must cancel their registration with us.

  • Types of data processed: Master data (e.g. names, addresses), contact details (e.g. email, telephone numbers)
  • Data subjects: Users (e.g. website visitors, users of online services)
  • Purposes of processing: Contractual services, registration procedures
  • Legal basis: Consent (Art. 6(1)(a) GDPR), performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR)

Services and service providers used:

Online Presence on Social Media

We maintain online presences on social networks and platforms in order to communicate with customers, prospective customers and users active there and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless otherwise stated in our privacy policy, we process users’ data if they communicate with us within the social networks and platforms, e.g. by posting on our online presences or sending us messages.

Integration of third-party services and content

Within our online offering, we incorporate content and services from third-party providers on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) content or service offerings from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as “content”).

This always requires that the third-party providers of this content receive the user’s IP address, as they would not be able to send the content to the user’s browser without it. The IP address is therefore necessary for the display of this content. We endeavour to use only such content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags enable information, such as visitor traffic on the pages of this website, to be analysed. The pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of our online service, as well as being linked to such information from other sources.

YouTube

We embed videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated.

Google Maps

We embed maps from the “Google Maps” service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data processed may include, in particular, users’ IP addresses and location data; however, does not collect this data without the user’s consent (which is usually given via the settings on their mobile devices). The data may be processed in the USA. Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.

Use of Google My Business

Collection and sharing of information:
You can publish information worldwide using the Google My Business button. Via the Google My Business button, you and other users receive personalised content from Google and its partners.

Google stores both the fact that you have submitted a review via Google My Business and information about the page you were viewing when you clicked on Google My Business. Your Google My Business listing may appear as a reference alongside your profile name and photo in Google services, such as in search results or on your Google profile, or in other places on websites and in adverts across the internet.

Google records information about Google My Business activity to improve Google services for you and others. To use the Google My Business button, you need a publicly visible Google profile that is visible worldwide and must include at least the name chosen for the profile. This name is used across all Google services. In some cases, this name may also replace another name you have used when sharing content via your Google Account. The identity of your Google profile may be visible to users who know your email address or have other identifying information about you.

Use of the information collected:
In addition to the purposes explained above, the information you provide is used in accordance with Google’s applicable privacy policies. Google may publish aggregated statistics about users’ Google My Business activities or share them with users and partners, such as publishers, advertisers or affiliated websites.

LinkedIn

We have integrated LinkedIn into our website. LinkedIn is a website for social networking and career resources. LinkedIn supports both job seekers and employers with professional services and provides career-related information. By integrating LinkedIn into our website, our content is distributed via this service.

The controller responsible for the processing of your personal data is

  • LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

Further information about LinkedIn, LinkedIn’s privacy policy and how LinkedIn processes data can be found here:

If a button is embedded on our website, LinkedIn may automatically download IT content. In this case, the web pages accessed by the visitor automatically transmit the data to LinkedIn. Through this technical process, LinkedIn may receive personal data, such as your IP address and browsing habits, in order to optimise user-targeted advertising. The data is stored by LinkedIn in the USA and may be shared with third parties. A user who logs into LinkedIn with personal data is recognised by LinkedIn during every activity. Your personal data, e.g. your IP address, website clicks, when, where and how often you visit the page, source link, tracking link and time spent on the page, is transmitted. If a button is embedded in our website, LinkedIn can link any user activity to the user’s personal data and store and process this information.

The information is also published on the social network and displayed to your contacts. We use the information to safeguard our legitimate interests in accordance with legal requirements, so that we can promote our service in the best possible way.

Duration of storage

Once personal data is no longer required for the purposes of recording, it is deleted.

Right to object and erasure

Cookies are stored on the user’s computer, which transmits the cookies to our websites. As a user, you therefore have full control over the use of cookies. You can disable or restrict the transmission of cookies by changing your web browser settings. Stored cookies can be deleted at any time. This can also be done automatically. If you disable cookies for our website, you may not be able to use the site to its full extent.

You can prevent your personal data from being transmitted by logging out of your account.

Facebook

We operate this page as a communication and information channel to provide information about our services. Personal data is processed in accordance with Article 6(1)(f) of the General Data Protection Regulation on the basis of our legitimate interest in using this modern means of providing information and interacting with users and visitors to the page.

Please note that you use this Facebook page and its features at your own risk. This applies in particular to the use of interactive features (e.g. commenting, sharing, rating).

Processing of personal data by Facebook

When you visit our Facebook page, Facebook collects, among other things, your IP address and other information stored on your computer in the form of cookies. This information is used to provide us, as the operators of the Facebook pages, with statistical information regarding the use of the Facebook page. Facebook provides further information on this at the following link: http://dede.facebook.com/help/pages/insights.

The data collected about you in this context is processed by Facebook Ltd. and may be transferred to countries outside the European Union. Facebook describes in general terms what information it receives and how it is used in its Data Policy. There you will also find information on how to contact Facebook and on the settings options for advertisements. The Data Policy and the information required under Article 13(1)(a) and (b) of the GDPR are available via the following link: http://de-de.facebook.com/about/privacy.

Facebook does not conclusively and clearly specify how it uses data from visits to Facebook pages for its own purposes, to what extent activities on the Facebook page are attributed to individual users, how long Facebook stores this data, or whether data from a visit to the Facebook page is passed on to third parties; we are not aware of this.

When accessing a Facebook page, the IP address assigned to your device is transmitted to Facebook. According to Facebook, this IP address is anonymised (for ‘German’ IP addresses) and deleted after 90 days. Facebook also stores information about its users’ devices (e.g. as part of the ‘Login Notification’ feature); where applicable, this enables Facebook to link IP addresses to individual users.

If you are currently logged in to Facebook as a user, there is a cookie on your device containing your Facebook ID. This enables Facebook to track, via , that you have visited this page and how you have used it. This also applies to all other Facebook pages. Facebook is able to track your visits to these websites and associate them with your Facebook profile via Facebook buttons embedded in websites. This data can be used to offer you content or advertising tailored to your interests. If you wish to prevent this, you should log out of Facebook or deactivate the ‘stay logged in’ function, delete the cookies stored on your device, and close and restart your browser. This will delete Facebook information that can be used to identify you directly. This allows you to use our Facebook page without your Facebook ID being revealed. If you access interactive features on the page (Like, Comment, Share, Messages, etc.), a Facebook login screen will appear. Once you have logged in, you will once again be recognisable to Facebook as a specific user.

Further information from the third-party provider regarding data protection, including the legal basis on which Facebook Ireland relies, as well as information on how you can manage or delete information held about you, can be found on the following Facebook website: https://de-de.facebook.com/about/privacy.

Processing of data by us

We can access statistical data in various categories via the so-called ‘Insights’ on the Facebook page. These statistics are generated and provided by Facebook. As the page operator, we have no influence over their generation or presentation. We cannot disable this function or prevent the generation and processing of the data. For a selectable period and for the categories of fans, subscribers, people reached and people interacting, Facebook provides us with the following data relating to our Facebook page:

  • Total number of page views and activities, post interactions (‘Likes’, comments, shared content, clicks on links, etc.), (post) reach, video views, replies,
  • Proportion of men and women,
  • Origin by country and city,
  • Language,
  • Views and clicks in the shop,
  • Clicks on route planners,
  • Clicks on telephone numbers.

Data relating to the Facebook groups linked to our Facebook page is also provided in this way. Due to the constant development of Facebook, the availability and presentation of the data is subject to change; therefore, for further details, please refer to Facebook’s privacy policy mentioned above. We use this data, which is available in aggregated form, to make our posts and activities on our Facebook page more appealing to users. For example, we use the breakdowns by age and gender to tailor our messaging and the users’ preferred visiting times to optimise the timing of our posts. Information about the types of devices used by visitors helps us to adapt the visual design of our posts accordingly. In accordance with Facebook’s Terms of Service, to which every user has agreed when creating a Facebook profile, we can identify the page’s subscribers and fans and view their profiles as well as other information they have shared.

Users’ rights

Under the joint responsibility agreement concluded between us and Facebook, Facebook Ireland assumes primary responsibility under the GDPR for the processing of Insights data and fulfils all obligations under the GDPR with regard to the processing of Insights data (including Articles 12 and 13 of the GDPR, Articles 15 to 22 of the GDPR and Articles 32 to 34 of the GDPR). Furthermore, Facebook Ireland will make the key points of this Page Insights Supplement available to data subjects.

Please feel free to contact us or Facebook if you have any questions. Under the agreement between us and Facebook, we will immediately forward your enquiry to Facebook where Facebook alone is responsible for fulfilling your data subject rights. Facebook Ireland will respond to enquiries in accordance with the obligations incumbent upon us under this Page Insights Supplement.

Instagram

We operate this page as a communication and information channel to provide information about our services. Personal data is processed in accordance with Article 6(1)(f) of the General Data Protection Regulation on the basis of our legitimate interest in using this modern means of providing information and interacting with the users and visitors of the page.

Please note that you use this Instagram page and its features at your own risk. This applies in particular to the use of interactive features (such as commenting or rating).

When you visit our Instagram page, Facebook collects, among other things, your IP address and other information stored on your device in the form of cookies. This information is used to provide us, as the operator of the Instagram page, with statistical information regarding the use of the Instagram page. The data collected about you in this context is processed by Facebook and may be transferred to countries outside the European Union. Facebook describes in general terms in its privacy policy what information it receives and how it is used. There you will also find information on how to contact Facebook and on the settings options for advertisements. The privacy policy is available at the following link: https://help.instagram.com/519522125107875

Facebook does not conclusively and clearly state how it uses data from visits to Instagram pages for its own purposes, to what extent activities on the Instagram page are attributed to individual users, how long Facebook stores this data, or whether data from a visit to the Instagram page is passed on to third parties, and we are not aware of this.

When you access an Instagram page, the IP address assigned to your device is transmitted to Facebook. According to Facebook, this IP address is anonymised (for ‘German’ IP addresses) and deleted after 90 days. Facebook also stores information about its users’ devices (for example, as part of the ‘login notification’ feature); where applicable, this enables Facebook to link IP addresses to individual users.

If you are currently logged in to Instagram as a user, there is a cookie on your device containing your Instagram ID. This enables Facebook to track that you have visited this page and how you have used it. This also applies to all other Instagram pages. Via Instagram buttons embedded in websites, Facebook is able to record your visits to these websites and associate them with your Instagram profile. Based on this data, content or advertising can be tailored to you. If you wish to avoid this, you should log out of Instagram or deactivate the ‘stay logged in’ function, delete the cookies stored on your device, and close and restart your browser. This will delete Instagram information that can be used to identify you directly. This allows you to use our Instagram page without your Instagram ID being revealed. When you access interactive features on the page ( , comments, messages and more), an Instagram login screen will appear. Once you have logged in, Instagram will recognise you again as a specific user.

Further information from the third-party provider regarding data protection, as well as information on how you can manage or delete information held about you, can be found in the Instagram Help Centre at the following address: https://help.instagram.com/196883487377501.

Pinterest account

The account is operated by storemore – a brand of Selbstlagerbox GmbH. It is operated as a general information medium. For the service offered on Pinterest, we use both the technical platform and the services of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

Data processing by Pinterest

Pinterest’s detailed privacy policy, which informs you about data processing and your rights vis-à-vis Pinterest, can be found at the following link: https://policy.pinterest.com/de/privacy-policy We have no influence over the nature, scope and purposes of the data processing carried out by Pinterest. Nor do we have any influence over the use or disclosure of personal data by Pinterest. There are also no effective means of control in this regard.

When you use Pinterest, your personal data is collected, transmitted, stored, disclosed and used by Pinterest, and is transferred to, stored and used in the United States of America (USA), Ireland and any other country in which Pinterest operates. You can find out exactly which data is affected in Pinterest’s privacy policy. Users can also see which other users follow us or whom we follow.

Data processed by us via Pinterest

We process data via the Pinterest account when you interact with our pins or other posts (e.g. by ‘saving’, ‘sharing’ or commenting). In such cases, Pinterest informs us of the action taken, including the account name. We may use this data to compose a reply. Personal data is also collected and processed if you send us a message directly via Pinterest or by email. We will then also use this data to send you a reply.

If you request in a message that we contact you by other means outside of the Pinterest account and provide us with the relevant contact details (e.g. postal address, telephone number or email address), we will transfer this data to our company systems so that we can contact you accordingly as part of our business activities. Please note when sending a direct message that Pinterest may scan the content of the messages.

Your personal data will be stored until the stated purposes have been achieved or for as long as we have a legitimate interest in storing it. It will then be deleted, unless other agreements have been made with you or statutory archiving obligations (e.g. under commercial or tax law) apply. In the event of legally required archiving, the data will be blocked from further access. These documents will be deleted and destroyed in accordance with data protection regulations as part of regular procedures once the statutory retention periods have expired.

Measuring the success of our pins

Using tools provided by Pinterest, we can measure the reach of our pins within our target audience. To generate these reports, Pinterest processes various data and then makes it available to us in a processed form. We use this data to create pins tailored to our target audience, thereby enabling us to increase our relevant reach. The legal basis for this is Article 6(1)(f) of the GDPR. There are no overriding legitimate interests of the data subjects that would preclude this analysis.

Pinterest also uses cookies for this purpose and analyses your behaviour on Pinterest. The information generated by cookies regarding your use of Pinterest (including your IP address) is transmitted to Pinterest’s servers and stored there. It cannot be ruled out that data processing may take place outside the scope of EU law. Through identification, for example when logging in to Pinterest, the data listed above may also be collected and used across devices. This allows, for example, the tracking of a visit that you begin on a PC and continue on a mobile device, with the data from both devices being linked.

Pinterest will use this information to evaluate your use of the website on our behalf, to compile reports on activities for us, to form interest-based target groups, and to provide us with further services related to the use of Pinterest. Pinterest may also transfer this information to third parties where required by law or where such third parties process the data on Pinterest’s behalf. You can prevent the installation of cookies by adjusting your browser settings accordingly – however, this may mean that you will no longer be able to use Pinterest.

Calendly

Calendly is an online scheduling tool that collects users’ personal data to enable appointment booking.

Use of Calendly

To simplify and optimise our appointment scheduling, we use the “Calendly” service provided by Calendly, LLC, 271 17th St NW, Ste 10, Atlanta, GA 30363, USA. When using Calendly, data such as name, email address and the appointments selected by the user are processed.

Data processed

The following personal data is collected and processed when using Calendly:

  • First name and surname
  • Email address
  • Telephone number (if provided by the user)
  • Date and time of booked appointments

This data is used exclusively for the purpose of scheduling appointments and is not passed on to third parties.

Legal basis

The processing of data is based on Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(f) of the GDPR (legitimate interest in effective appointment organisation).

Data transfer to third countries

Calendly stores the collected data in the USA. Processing is carried out on the basis of the EU Standard Contractual Clauses to ensure an adequate level of data protection.

Further information

For further information on data processing by Calendly, please refer to Calendly’s privacy policy: https://calendly.com/de/pages/privacy.

WhatsApp contact (Click-to-Chat & QR code)

Contact via WhatsApp

Visitors to our website have the option of contacting us via the WhatsApp messaging service. For this purpose, we use WhatsApp Business, a service provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. When you contact us via WhatsApp, you automatically provide us with your mobile phone number and, where applicable, further personal data (e.g. profile picture, communication content). Communication takes place solely for the purpose of dealing with your enquiry.

Processing is carried out on the basis of Article 6(1)(a) of the GDPR (consent) or Article 6(1)(f) of the GDPR (legitimate interest in a simple and modern form of communication). Please note that WhatsApp may also transfer personal data to the USA. Meta is certified under the EU-US Data Privacy Framework. Further information on data processing by WhatsApp can be found in their privacy policy.

The use of WhatsApp is voluntary. Alternatively, other contact methods (telephone, email, contact form) are available to you.

Trustpilot widget (review display)

We use a widget from the provider Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark (“Trustpilot”) on our website to display our Trustpilot score and reviews.

When you visit the pages on which the widget is embedded, your browser may establish a connection to Trustpilot’s servers. In particular, the following data may be processed:

- IP address

- Date and time of access

- Page accessed/referrer URL

- Device and browser information (e.g. user agent)

The purpose of the processing is to display customer reviews and our Trustpilot score, as well as to optimise the display.

The legal basis is Article 6(1)(f) of the GDPR (legitimate interest) to present our offering transparently and to enable prospective customers to make informed decisions based on customer reviews.

Where Trustpilot uses cookies or similar technologies in this context, this is done – where necessary – on the basis of your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG; technically necessary processes are based on Section 25(2) of the TDDDG.

Further information on data processing by Trustpilot can be found in Trustpilot’s privacy policy.

Automated review invitation via Trustpilot (AFS)

We use the Trustpilot Automated Feedback Service (AFS) to automatically invite customers via email to submit a review on Trustpilot following a booking.

Process: When you book with us, you will receive a booking/confirmation email from us. In this context, an automated invitation to submit a review via Trustpilot is triggered. To this end, we transmit the data required for sending the email to Trustpilot. Trustpilot then sends an invitation email to you on our behalf.

Categories of data processed (where transmitted by us):

- Name

- Email address

- Reference/booking number generated by us

The purpose is to gather customer feedback, improve our services and present authentic customer experiences.

The legal basis is Article 6(1)(f) of the GDPR (legitimate interest in collecting and evaluating customer feedback and in improving quality).
Where invitations are classified as direct marketing in individual cases, they are sent in accordance with legal requirements; you may object to receiving them at any time (see below).

The recipient of the data is Trustpilot A/S (see above). Data is transferred within the EU/EEA (Denmark). Where Trustpilot uses sub-processors, this is done on the basis of appropriate safeguards.

Retention period: The data transmitted to Trustpilot will only be processed for as long as is necessary for the dispatch and allocation of the invitation/review; otherwise, Trustpilot’s retention periods and deletion policies apply.

Objection: You may object to the sending of review invitations at any time with future effect, e.g. via the unsubscribe link in the invitation email or by sending us a message (see above for contact details). In this case, we will no longer use your data to send further invitations via Trustpilot.

Image recognition for box recommendations via OpenAI

Image-based box size recommendation using AI

To make it easier for our customers to select a suitable storage box, we offer the option to upload images of the items to be stored. The uploaded images are automatically analysed to provide a recommendation on box size. This analysis is carried out using an AI model from OpenAI (OpenAI Inc., San Francisco, USA). The images are temporarily transmitted to and processed by OpenAI for this purpose.

Processing is carried out on the basis of your explicit consent in accordance with Article 6(1)(a) of the GDPR. Use of this service is voluntary. The images transmitted may allow conclusions to be drawn about personal belongings, living conditions or other personal data. No automated decision-making within the meaning of Article 22 of the GDPR takes place.

OpenAI operates as a provider outside the EU. Data processing is carried out on the basis of the EU Commission’s standard contractual clauses. Further information can be found in OpenAI’s privacy policy.

The images are not stored permanently once the analysis has been completed.

Stripe

Stripe is a payment service provider that handles payments for services and products.

Use of Stripe

We use the payment service provider Stripe Payments Europe, Ltd., Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland, to process payments.

Data processed

As part of the payment process, Stripe collects the following data:

  • Payment information (e.g. credit card details, bank account details)
  • Name and address of the payee
  • Email address
  • IP address

This data is used exclusively for the purpose of processing payments.

Legal basis

The processing of data is based on Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(f) of the GDPR (legitimate interest in the secure processing of payments).

Data transfer to third countries

Stripe may transfer data to countries outside the EU/EEA, in particular to the USA. To protect your data, Stripe has implemented the EU Standard Contractual Clauses.

Further information

For further information on data processing by Stripe, please refer to Stripe’s privacy policy: https://stripe.com/de/privacy.

SEPA Mandate

Purposes and legal basis for the processing of personal data

Your data is processed for the purpose of carrying out the SEPA direct debit procedure for rent payments. The legal basis is the consent you have given us in accordance with Article 6(1)(a) of the GDPR for the direct debit.

Type of personal data and its processing

The personal data that Selbstlagerbox GmbH collects from you for the above-mentioned purpose is set out in the “SEPA Direct Debit Mandate”. Once Selbstlagerbox GmbH has received the SEPA Direct Debit Mandate signed by you, the data you have provided therein will be stored for the purpose of debiting the rental payments. The data will be transmitted via data transfer to the relevant banking institutions (Selbstlagerbox GmbH’s principal bank and the banking institution you have specified) as part of the direct debit procedure.

Duration of storage

We must store personal data for as long as it is necessary to fulfil our obligations and as required by statutory retention periods or limitation periods.

Your data protection rights

Under the GDPR, you have the right to access, rectification, erasure, restriction of processing and to object (Articles 15 to 18, 21 GDPR). A restriction on these rights may arise from the GDPR itself. If you believe that the processing of your personal data is not lawful, you may lodge a complaint with the State Data Protection Commissioner in accordance with Article 77(1) of the GDPR.

Note: In the event of any inconsistencies or disputes regarding the interpretation, the German version shall prevail. The English translation is provided for communication purposes only.