Privacy Policy
The provisions of the EU General Data Protection Regulation (hereinafter GDPR) apply throughout Europe. We would like to inform you about the processing of personal data carried out by our company in accordance with this regulation (see Articles 13 and 14 GDPR). If you have any questions or comments regarding this privacy policy, you can contact us at any time via the email addresses given in sections 2 and 3 below.
Table of Contents:
I. Overview
Scope of application
Data controller
Data protection officer
II. Details of data processing
General information about data processing
Website/application access
Customer support
Use of our contact form
Tracking
III. Rights of data subjects
Right to object
Right of access
Right to rectification
Right to deletion (“right to be forgotten”)
Right to restriction of processing
Right to data portability
Right to withdraw consent
Right to complain
IV. Glossary
I. Overview
This section of the privacy policy provides information about the scope, the data controller responsible for processing, their data protection officer, and data security.
Scope of application
Data processing can be essentially divided into two categories:
For the purpose of contract execution, all data necessary for the performance of a contract are processed. If external service providers are involved in the contract execution, your data will be shared with them to the extent necessary.
When accessing websites/applications, various information is exchanged between your device and our server. This may also include personal data. The information collected is used, among other things, to optimize our website or to display advertising in your browser.
This privacy policy applies to the following services:
Our online offering accessible at https://www.covercheck.de;
Whenever one of our other offerings (e.g., websites, subdomains, mobile applications, web services, or integrations on third-party sites) refers to this privacy policy, regardless of how you access or use it.
All these offerings are collectively referred to as “Services.”
Data controller
The data controller for data processing — that is, the party who decides on the purposes and means of processing personal data — in connection with the Services is:
CoverCheck
Versicherungskontor GmbH
Brunnenstraße 11
06493 Harzgerode
Tel.: +49 (0) 39484/7385-36
Fax: +49 (0) 39484/7385-37
Email: info@covercheck.de
Data protection officer
CoverCheck
Versicherungskontor GmbH
Data Protection Officer –
Brunnenstraße 11
06493 Harzgerode
II. Details of data processing
In this section, we provide detailed information about the processing of personal data within the scope of our Services. For better clarity, we categorize this information according to specific functionalities of our Services. During normal use, different functionalities and thus different processing activities may occur consecutively or simultaneously.
General information about data processing
For all processing described below, unless otherwise stated:
a. No obligation to provide data
There is neither a contractual nor a legal obligation to provide personal data. You are not obliged to provide data.
b. Consequences of non-provision
For required data (marked as mandatory when entering), failure to provide these data means the respective Service cannot be provided. Otherwise, failure to provide data may result in our services not being provided in the same form or quality.
c. Consent
In some cases, you have the option to give us your consent for further processing (possibly for some of the data). In such cases, we will inform you separately about all details and scope of consent and the purposes of these processing activities when you give your consent.
d. Transfer of personal data to third countries
If we transfer data to third countries (outside the European Union), this transfer only takes place in compliance with the legal requirements. The legal bases for this are regulated by Articles 44-49 GDPR.
e. Hosting by external service providers
Our data processing largely involves hosting service providers who provide storage and processing capacities in their data centers and process personal data on our behalf under our instructions. These providers either process data exclusively within the EU or we have ensured adequate data protection standards through the use of EU standard contractual clauses.
f. Transfer to governmental authorities
We transfer personal data to government authorities (including law enforcement) when required to comply with legal obligations (legal basis: Art. 6(1)(c) GDPR) or to assert, exercise, or defend legal claims (legal basis: Art. 6(1)(f) GDPR).
g. Storage duration
We do not store your data longer than necessary for the respective processing purposes. If the data is no longer required for contractual or legal obligations, it will be regularly deleted unless a temporary retention is still necessary. Reasons for this include:
Compliance with commercial and tax retention obligations
Preservation of evidence in legal disputes within statutory limitation periods
It is also possible to store your data further if you have explicitly consented to this.
h. Categories of data
Account data: login/user ID and password
Address data: street, house number, address additions, postal code, city, country
Contact data: phone number(s), fax number(s), email address(es)
Registration data: information about the service you registered for; times and technical information on registration, confirmation, and deregistration; data you provided at registration
Payment data: bank details, credit card data, data from other payment services such as PayPal
Access data: date and time of visit; referring page; pages visited; session ID; IP address; browser type and version; device type; operating system and similar technical info
Data under Art. 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, or data concerning sex life or sexual orientation
Website/Application Access
This section describes how we process your personal data when you access our Services. We particularly note that transmission of access data to external content providers (see below) is unavoidable due to the technical nature of data transmission on the Internet.
Data Category | Purpose | Legal Basis | If applicable, Legitimate Interest | Storage Duration |
---|---|---|---|---|
Access Data |
Connection establishment, Display of service content, Detection of attacks on our site through unusual activities, Error diagnosis |
Art. 6(1)(f) GDPR |
Proper functioning of the services, Security of data and business processes, Prevention of misuse, Prevention of damage caused by interference with information systems |
7 days |
Recipient Category | Affected Data | Legal Basis for Transfer | If Applicable, Legitimate Interest |
---|---|---|---|
External content providers, who provide content (e.g. images, videos, embedded posts from social networks, advertising banners, fonts, update information) necessary for displaying the service |
Access data | Contract processing (Art. 28 GDPR) |
Proper functioning of the services, (accelerated) display of content |
IT security service providers | Access data | Contract processing (Art. 28 GDPR) | Prevention of attacks by |
---|
Recipient Category | Affected Data | Legal Basis for Transfer | If Applicable, Legitimate Interest |
---|---|---|---|
External content providers, who provide content (e.g. images, videos, embedded posts from social networks, advertising banners, fonts, update information) necessary for displaying the service |
Access data | Contract processing (Art. 28 GDPR) |
Proper functioning of the services, (accelerated) display of content |
How we process your personal data when you contact our customer service can be found here:
Information on Processing
Data Category | Purpose | Legal Basis | Legitimate Interest (if applicable) | Storage Duration |
---|---|---|---|---|
Basic personal data, Contact data, Content of inquiries / complaints |
Handling of customer inquiries and user complaints |
Art. 6 (1) b), f) GDPR |
Customer retention, Service improvement |
Until request is processed |
Below we describe how your personal data is processed using tracking technologies for the purpose of analyzing and optimizing our services, as well as for advertising purposes. The description of the tracking methods also includes information on how you can prevent or object to the processing of your data.
Please note that opting out of such processing is usually stored via cookies. If you use our services on a new device, in a different browser, or if you have deleted cookies set by your browser, you will need to opt out again.
The tracking methods described process personal data only in pseudonymized form.
There is no connection made with a specific, identified natural person, i.e., the data is not merged with information about the person behind the pseudonym.
(1) Purposes of Processing
The analysis of user behavior through tracking helps us assess the effectiveness of our services, optimize them, adapt them to users’ needs, and fix errors.
It also allows us to statistically determine key metrics about how our services are used (reach, usage intensity, user browsing behavior) – based on standardized procedures – in order to obtain market-wide comparable values.
Tracking for measuring the success of advertising campaigns helps us optimize our future ads and enables marketers and advertisers to improve their campaigns as well.
Tracking for ad delivery optimization aims to show users interest-based advertising, measure the success of ads, and thereby increase advertising revenue.
(2) Legal Basis for Processing
For services that monitor the online behavior of data subjects and create user profiles, an informed consent in accordance with the GDPR is required.
(3) The individual tracking methods used
(Note: This part will typically list tools like Google Analytics, Meta Pixel, etc. If you provide that part, I can translate it as well.)
Name of the Service | Functionality | Opt-out Option | Data Transfer | Adequacy Decision | Appropriate Safeguards |
---|
You will still receive advertising, but it will no longer be based on your interests.
If we process your personal data for direct marketing purposes, you have the right to object at any time, with effect for the future, to the processing of personal data concerning you for such advertising purposes. This also applies to profiling, to the extent it is related to such direct marketing.
You also have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.
The right to object can be exercised free of charge. You can contact us via the contact details mentioned in section I.2.
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed by us. If this is the case, you also have the right to access this data and receive further information pursuant to Art. 15 GDPR.
You have the right to request the immediate correction of inaccurate personal data concerning you (Art. 16 GDPR). Taking into account the purposes of the processing, you also have the right to request the completion of incomplete personal data, including by means of a supplementary statement.
You have the right to request the immediate deletion of your personal data where one of the reasons listed in Art. 17(1) GDPR applies and where processing is not required for any of the exceptions defined in Art. 17(3) GDPR.
You have the right to request the restriction of processing of your personal data where one of the conditions outlined in Art. 18(1)(a)–(d) GDPR applies.
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format.
You also have the right to transmit those data to another controller without hindrance from us, or to request direct transmission, where technically feasible.
This applies only if the processing is based on your consent or a contract and is carried out by automated means. It does not apply to paper-based data.
If the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time. The lawfulness of processing based on consent before its withdrawal remains unaffected.
In the event of data protection violations, you have the right to lodge a complaint with a supervisory authority. The competent authority is the data protection officer of the federal state in which our company is located.
You can find a list of data protection officers and their contact details here:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
Processor:
A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Browser:
A software program used to display websites (e.g., Chrome, Firefox, Safari).
Cookies:
Small text files stored locally on a user’s device when visiting a website. These store user preferences and behavior for later retrieval by the server. Cookies can be controlled or deleted via browser settings.
Third Countries:
Countries outside the EEA that are not bound by EU data protection laws.
Personal Data:
Any information relating to an identified or identifiable natural person. This includes names, identification numbers, location data, online identifiers, or factors specific to the identity of that person.
Pixels (Tracking Pixels / Web Beacons):
Tiny, invisible graphics used to track user activity on websites or in emails. They inform the server when a page or email has been viewed and may capture browser data, time, cookies, and other device information.
Profiling:
Any automated processing of personal data to evaluate certain personal aspects, especially to analyze or predict behavior, interests, location, reliability, or preferences.
Services:
All our offerings to which this privacy policy applies (see scope).
Tracking:
The collection and analysis of data regarding the behavior of visitors to our services.
Tracking Technologies:
Tracking via log files on web servers or via pixels, cookies, and similar technologies on users’ devices.
Processing:
Any operation on personal data—automated or manual—including collection, storage, use, disclosure, or deletion.
©Alrights reserved by CoverChek