Data Privacy Policy
Responsible body in the sense of data protection law
Sarah Hatzold Fashion Consulting & Styling
Pickelstrasse 10
80637 Munich
privacy@sarahhatzold.com
+49 15753345501
With my Website I collect Personal Data from you when you submit web forms or interact with it, for example by subscribing to a blog, a newsletter, signing up for a webinar, subscribing to one of my services or requesting customer support. This Information is collected in order to improve the website performance, to ensure technical integrity and in order to follow up requests made by website visitors e.g. sending a Newsletter or the coordination for providing Services offered through this website. I may ask for first and last name and contact information as your email address or phone number. In some cases I may request job title, and other similar business information.
Data Privacy DeclarationDefinitions
Introduction and general information
Thank you for your interest in our website. The protection of your personal data is very important to us. In the following, you will find information on how we handle your data that is collected through your use of our website. Your data will be processed in accordance with the legal regulations on data protection.
Definitions
Our data protection declaration is intended to be simple and understandable for everyone. As a rule, the official terms of the General Data Protection Regulation (DSGVO) are used in this data protection declaration. The official definitions are explained in Art. 4 DSGVO.
Data processing by visiting our website
When you visit our website, it is technically necessary for data to be transmitted to our web server via your internet browser. The following data is recorded during an ongoing connection for communication between your internet browser and our web server:
- Date and time of the request
- Name of the requested file
- Page from which the file was requested
- Access status
- Web browser and operating system used
- (Complete) IP address of the requesting computer
Amount of data transferred
We collect the listed data to ensure a smooth connection setup of the website and to enable a comfortable use of our website by the users. In addition, the log file is used to evaluate system security and stability as well as for administrative purposes. The legal basis for the temporary storage of the data or the log files is Art. 6 para. 1 lit. f DSGVO. This data is stored and processed by Hubspot and its subprocessors.
Data Subjects Categories, Processed Data Types and Processing Purposes
We do not process sensitive personal information.
We do not receive any information from third parties.
Website Visitors
Processed Data Types:
- Meta Data
- Usage Data
Purposes of Processing:
- Website Performance
- Security measures
- Range measurement
- Click Tracking
- Marketing Analytics
- Conversion measurement
- A/B testing
- Marketing Activities
- Target group creation and Targeting
Contact form and contact by e-mail
If you send us enquiries via the contact form or by e-mail, your details from the enquiry form or your e-mail, including your first and last name, title, will be stored by us for the purpose of processing the enquiry and in the event of follow-up enquiries. The specification of an e-mail address is required to contact you, the specification of your name and telephone number is voluntary. Under no circumstances will we pass on this data without your consent. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f DSGVO and, if applicable, Art. 6 (1) lit. b DSGVO if your request is aimed at concluding a contract. Your data will be deleted after your request has been processed, provided that there are no legal obligations to retain data. You can object to the processing of your personal data at any time in the case of Art. 6 para. 1 lit. f DSGVO.
Interested Parties (Signup Newsletter, & Forms, Chat, and Similar forms of Interaction)
Processed Data Types:
- Meta Data (e.g. IP address)
- Usage Data (e.g. visited pages)
- Personal Data (e.g. name, email address, phone number, position, company)
Purposes of processing
- Website Performance
- Security measures
- Range measurement
- Click Tracking
- Marketing Analytics
- Conversion measurement
- A/B testing
- Marketing Activities
- Target group creation and Targeting
- Direct Marketing
- Interaction with visitors, prospects and customers
- Contact requests, queries and communication
- Surveys and questionnaires.
Customers, Suppliers and Business Partners
Processed Data Types:
- Meta Data (e.g. IP address)
- Usage Data (e.g. visited pages)
- Personal Data (e.g. name, email address, phone number, position, company, postal address)
- Payment Data (e.g. Bank account)
- Company Data (e.g. VAT or TaxID, company address)
- Contract Data ( e.g Signed Legal Documents, Offers, Invoices)
Purposes of processing
- Feedback
- Website Performance
- Security measures
- Range measurement
- Click Tracking
- Marketing Analytics
- Conversion measurement
- A/B testing
- Marketing Activities
- Target group creation and Targeting
- Direct Marketing
- Interaction with visitors, prospects and customers
- Contact requests, queries and communication
- Surveys and questionnaires.
- Provision of contractual services and customer service
- Creating and Maintaining Profiles
- Office and organizational procedures.
List of Data Processors (for Website Visitors, Interested Parties & Customers)
Hubspot
- Hubspot (CMS & CRM Platform hosted on a European Server) Data Privacy Declaration
- Manages Meta Data, Usage Data, as CMS System and Personal Data, Payment Data, Company Data and Contract Data as CRM System.
- Hubspot Dataprocessing Agreement
- List of necessary Hubspot Cookies
- List of analytical Cookies
- List fo advertisement Cookies
- List of functional Hubspot Cookies
- List of Data-Sub Processors of Hubspot
Google Analytics
- Google Analytics code is executed only after an opt-in through the Hubspot cookie banner
- This instance of Analytics works with anonymized IP-Adresses
- If agreed by Opt-in, Google Analytics might send data to third countries outside the EU
Our website uses Google Analytics, an internet analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses so-called "cookies".
Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, and to compile reports on website activity. Google will also use this information to provide the website operator with other services related to the use of the website and the internet. The IP address sent by your browser as part of Google Analytics will not be combined with any other data held by Google. The processing is carried out in accordance with Art. 6 para. 1 lit. a DSGVO on the basis of the consent you have given.
We only use Google Analytics with IP anonymisation activated. This means that your IP address is only processed by Google in a shortened form. We have concluded an order processing agreement with the service provider in which we oblige them to protect our customers' data and not to pass it on to third parties. As a transfer of personal data to the USA takes place, further protection mechanisms are required to ensure the level of data protection of the GDPR. To ensure this, we have agreed standard data protection clauses with the provider in accordance with Art. 46 (2) lit. c DSGVO. These oblige the recipient of the data in the USA to process the data in accordance with the level of protection in Europe. In cases where this cannot be ensured even through this contractual extension, we endeavour to obtain additional regulations and commitments from the recipient in the USA. The terms of use of Google Analytics and information on data protection can be accessed via the following links: http://www.google.com/analytics/terms/de.html https://www.google.de/intl/de/policies/.
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. Deletion of user and event level data associated with cookies, user identifiers (e.g. User ID) and advertising IDs (e.g. DoubleClick cookies, Android advertising ID, IDFA [Apple identifier for advertisers]) will occur no later than 14 months after collection.
You can prevent cookies from being stored by adjusting the settings of your browser software accordingly. However, we would like to point out that in this case you may not be able to use all functions of this website without restrictions. You may also prevent Google from collecting data generated by the cookie and from analysing your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at https://tools.google.com/dlpage/gaoptout?hl=de.
Google Ads
Our website uses Google Ads, an internet analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Ads uses so-called "cookies".
Cookies
Our website uses cookies, which are stored by the browser on your device and which contain certain settings for the use of the website (e.g. for the current session). Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser. Most of the cookies we use are so-called session cookies, which are automatically deleted after you close your browser. Other cookies remain stored on your end device until you delete them or the storage period expires. These cookies enable us to recognise your browser on your next visit.
In part, the cookies serve to simplify website processes by storing settings (e.g. providing already selected options). If personal data is also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6 para. 1 lit. b DSGVO either for the execution of the contract or in accordance with Art. 6 para. 1 lit. f DSGVO to protect our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the page visit. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally and activate the automatic deletion of cookies when closing the browser. The cookie settings can be managed under the following links for the respective browsers.
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Internet Explorer: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
Chrome: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647
Safari: https://support.apple.com/kb/ph21411?locale=de_DE
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
You can also individually manage the cookies of many companies and functions that are used for advertising. To do this, use the corresponding user tools, available at https://www.aboutads.info/choices/ or http://www.youronlinechoices.com/uk/your-ad-choices. Most browsers also offer a so-called "Do-Not-Track function", with which you can indicate that you do not wish to be "tracked" by websites. When this feature is enabled, the browser tells ad networks, websites and applications that you do not want to be tracked for behavioural advertising and the like. For information and instructions on how to edit this feature, please see the links below, depending on your browser provider:
Google Chrome: https://support.google.com/chrome/answer/2790761?co=GENIE.Platform%3DDesktop&hl=de
Mozilla Firefox: https://www.mozilla.org/de/firefox/dnt/
Internet Explorer: https://support.microsoft.com/de-de/help/17288/windows-internet-explorer-11-use-do-not-track
Opera: http://help.opera.com/Windows/12.10/de/notrack.html
Safari: https://support.apple.com/kb/PH21416?locale=de_DE
In addition, you can prevent the loading of so-called scripts by default. NoScript allows JavaScripts, Java and other plug-ins to run only on trusted domains of your choice. Information and instructions on how to edit this function can be obtained from the provider of your browser (e.g. for Mozilla Firefox at: https://addons.mozilla.org/de/firefox/addon/noscript/). Please note that if you deactivate cookies, the functionality of this website may be limited.
Data transfer and recipients
Your personal data will not be transferred to third parties unless
if we have explicitly pointed this out in the description of the respective data processing.
if you have given your express consent in accordance with Art. 6 Para. 1 S. 1 lit. a DSGVO,
the disclosure is necessary for the assertion, exercise or defence of legal claims pursuant to Art. 6 (1) sentence 1 lit. f DSGVO and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
in the event that a legal obligation exists for the disclosure pursuant to Art. 6 para. 1 sentence 1 lit. c DSGVO and
insofar as this is necessary for the processing of contractual relationships with you in accordance with Art. 6 Para. 1 Sentence 1 lit. b DSGVO.
We also use external service providers for the processing of our services, which we have carefully selected and commissioned in writing. They are bound by our instructions and are regularly monitored by us. If necessary, we have concluded order processing contracts with them in accordance with Art. 28 DSGVO. These are service providers for web hosting, sending e-mails as well as maintenance and care of our IT systems, etc. The service providers will not pass this data on to third parties.
Legal Basis for Collecting and Processing Data
- Access to the legal document: https://gdpr.eu/
- Legal basis for collecting an processing personal data:
- Consent (Art. 6 para. 1 p. 1 lit. a. DSGVO) - The data subject has given his/her consent to the processing of personal data relating to him/her for a specific purpose or purposes.
- Performance of a contract and pre-contractual requests (Art. 6 para. 1 p. 1 lit. b. DSGVO) - Processing is necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures carried out at the data subject's request.
- Legal obligation (Art. 6 (1) p. 1 lit. c. DSGVO) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 (1) p. 1 lit. f. DSGVO) - Processing is necessary for the purposes of the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data
Data security
We take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons. This website uses SSL encryption for security reasons and to protect the transmission of confidential content.
Duration of storage of personal data
The duration of the storage of personal data is determined by the relevant statutory retention periods (e.g. from commercial law and tax law). After expiry of the respective period, the corresponding data is routinely deleted. If data is required to fulfil or initiate a contract or if we have a legitimate interest in continuing to store it, the data will be deleted when it is no longer required for these purposes or you have exercised your right of revocation or objection.
Your rights
In the following, you will find information on which data subject rights the applicable data protection law grants you vis-à-vis the controller with regard to the processing of your personal data:
- The right to request information about your personal data processed by us in accordance with Article 15 of the GDPR.
In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information about its details. - The right to request the correction of incorrect or incomplete personal data stored by us without delay in accordance with Art. 16 DSGVO.
- The right to request the erasure of your personal data stored by us in accordance with Article 17 of the GDPR, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims.
- The right to request the restriction of the processing of your personal data in accordance with Art. 18 DSGVO, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you object to its erasure and we no longer require the data, but you need it for the assertion, exercise or defence of legal claims or you have objected to the processing in accordance with Art. 21 DSGVO.
- The right, pursuant to Art. 20 DSGVO, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transferred to another controller.
- Right to revoke consent given in accordance with Art. 7 (3) DSGVO: You have the right to revoke consent to the processing of data once given at any time with effect for the future. In the event of revocation, we will immediately delete the data concerned unless further processing can be based on a legal basis for processing without consent. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.
- To exercise any of these rights for this website please use this form to contact me about data privacy. I will respond to your request to change, correct, or delete your data within a reasonable time frame and notify you of the action I have taken.
- The right to complain to a supervisory authority in accordance with Art. 77 DSGVO. As a rule, you can contact the supervisory authority of the federal state of our registered office stated above or, if applicable, that of your usual place of residence or workplace. Contact details for data protection authorities in the EEA are available here).
Right of objection
If your personal data is processed by us on the basis of legitimate interests pursuant to Art. 6 (1) p. 1 lit. f DSGVO, you have the right to object to the processing of your personal data pursuant to Art. 21 DSGVO, insofar as this is done for reasons arising from your particular situation. Insofar as the objection is directed against the processing of personal data for the purpose of direct marketing, you have a general right of objection without the requirement to specify a particular situation. If you wish to exercise your right of withdrawal or objection, simply send an e-mail to privacy@sarahhatzold.com .
External links
Social networks (Facebook, Twitter, Xing etc.) are only integrated on our website as links to the corresponding services. After clicking on the integrated text/image link, you will be redirected to the page of the respective provider. User information is only transferred to the respective provider after the forwarding. For information on the handling of your personal data when using these websites, please refer to the respective data protection regulations of the providers you use.
Subject to change
We reserve the right to adapt or update this data protection declaration if necessary in compliance with the applicable data protection regulations. In this way, we can adapt it to the current legal requirements and take into account changes to our services, e.g. when introducing new services. The most current version applies to your visit.
This data protection declaration was created by www.datenschutzexperte.de
Status of this data protection declaration: 23.1.2023