Privacy policy

The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is: PepperPapers Limited.

Your rights as a data subject

You can exercise the following rights at any time using the contact details provided for our data protection officer:

  • Information about your data stored by us and its processing (Art. 15 GDPR),
  • Correction of incorrect personal data (Art. 16 GDPR),
  • Deletion of your data stored by us (Art. 17 GDPR),
  • Restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR),
  • Objection to the processing of your data by us (Art. 21 GDPR) and
  • Data portability, provided that you have consented to the data processing or have concluded a contract with us (Art. 20 GDPR).

If you have given us your consent, you can revoke it at any time with effect for the future.

You can contact a supervisory authority at any time with a complaint, e.g. the competent supervisory authority of the federal state of your residence or the authority responsible for us as the responsible body.

A list of supervisory authorities (for the non-public sector) with addresses can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.

Collection of general information when visiting our website

Nature and purpose of the processing:

When you access our website, i.e. if you do not register or otherwise transmit information, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider, your IP address and similar.

They are processed for the following purposes in particular:

  • Ensuring a smooth connection to the website,
  • Ensuring the smooth use of our website,
  • Evaluation of system security and stability and
  • to optimize our website.

We do not use your data to draw conclusions about your person. Information of this kind may be processed by us. anonymized and statistically evaluated in order to optimize our website and the technology behind it.

Legal basis and legitimate interest:

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.

Recipient:

Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.

Third country transfer:

The data collected may be transferred to the following third countries: no

The following data protection guarantees are in place:

Storage duration:

The data will be deleted as soon as it is no longer required for the purpose for which it was collected. This is generally the case for the data used to provide the website when the respective session has ended.

If the data is stored in log files, this is the case after 14 days at the latest. Storage beyond this is possible. In this case, the IP addresses of the users are anonymized so that it is no longer possible to identify the calling client.

Provision prescribed or required:

The provision of the aforementioned personal data is neither legally nor contractually required. Without the IP address, however, the service and functionality of our website cannot be guaranteed. In addition, individual services may be unavailable or restricted. For this reason, an objection is excluded.

Cookies

Like many other websites, we also use so-called “cookies”. Cookies are small text files that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website.

You can select the cookies that may be used on this website via the website’s cookie settings.

You can delete individual cookies or the entire cookie inventory via the browser. You will also receive information and instructions on how to delete these cookies or block their storage in advance. Depending on your browser provider, you will find the necessary information under the following links:

Storage duration and cookies used:

If you allow us to use cookies through your browser settings or consent, the following cookies may be used on our websites:

Technically necessary cookies

Nature and purpose of the processing:

We use cookies to make our website more user-friendly. Some elements of our website require that the accessing browser can be identified even after a page change.

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. This requires the browser to be recognized even after a page change.

We need cookies for the following applications:

  • Cart
  • User login

Legal basis and legitimate interest:

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in a user-friendly design of our website.

Recipient:

Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.

Provision prescribed or required:

The provision of the aforementioned personal data is neither legally nor contractually required. Without this data, however, the service and functionality of our website cannot be guaranteed. In addition, individual services may be unavailable or restricted.

Contradiction

Please read the information on your right to object under Art. 21 GDPR below.

Technically not necessary cookies

Furthermore, we use cookies to better tailor the offer on our website to the interests of our visitors or to generally improve it on the basis of statistical evaluations.

To find out which providers use cookies, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

  • Google Analytics

Legal basis:

The legal basis for this processing is your consent in each case, Art. 6 para. 1 lit. a GDPR.

Recipient:

Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.

For further recipients, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Third country transfer:

For information on this, please refer to the lists of the individual display, tracking, remarketing and web analysis providers and newsletters.

Provision prescribed or required:

Of course, you can also view our website without cookies. Web browsers are regularly set to accept cookies. In general, you can deactivate the use of cookies at any time via your browser settings (see Revocation of consent).

Please note that individual functions of our website may not work if you have deactivated the use of cookies.

Withdrawal of consent:

You can revoke your consent at any time via our cookie consent tool.

Profiling:

To what extent we analyze the behavior of website visitors with pseudonymized user profiles, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Registration on our website

Nature and purpose of the processing:

To register on our website, we require some personal data, which is transmitted to us via an input mask.

The following additional data is collected at the time of registration:

Your registration is required for the provision of certain content and services on our website.

Legal basis:

The data entered during registration is processed on the basis of the user’s consent (Art. 6 para. 1 lit. a GDPR).

Recipient:

Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.

Storage duration

Data will only be processed in this context as long as the corresponding consent has been given.

Provision prescribed or required:

The provision of your personal data is voluntary, solely on the basis of your consent. Without the provision of your personal data, we cannot grant you access to the content we offer.

Provision of chargeable services

Nature and purpose of the processing:

For the provision of chargeable services, we request additional data, such as payment details, in order to process your order.

Legal basis:

The processing of the data required for the conclusion of the contract is based on Art. 6 para. 1 lit. b GDPR.

Recipient:

Recipients of the data may be processors.

Storage duration:

We store this data in our systems until the statutory retention periods have expired. These are generally 6 or 10 years for reasons of proper accounting and tax law requirements.

Provision prescribed or required:

The provision of your personal data is voluntary. Without the provision of your personal data, we cannot grant you access to the content and services we offer.

Brevo

We use the services of Brevo, Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin on our website.

Brevo is a provider of hosting services and customer relationship management systems. Brevo provides the necessary product infrastructure for this.

Brevo uses the services of the Google Cloud Platform (GCP). The data processed by GPC is processed and stored on servers in Germany (Frankfurt a. M.) and Belgium.
Exceptions to the German server location exist for the back-ups that are stored in GCP in Belgium. The back-ups are encrypted by Brevo before being transmitted to GCP. Sendinblue SAS, the parent company of Sendinblue GmbH based in France, is responsible for key management. Back-ups are overwritten every 100 days.

Google may transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf.
Brevo enables us to integrate various codes and services into our website in an organized and simplified way. We link the following services with Brevo:

  • Email marketing
  • Newsletter
  • Automation
  • Server protocols
  • User accounts
  • Contact form
  • Blog/comment function
  • Google Analytics
  • Contact us

We use Brevo to sort and coordinate your inquiries and orders that originate from our website and partner sites. The following personal data is transmitted to Brevo and stored there:

  • First and last name
  • Address
  • E-mail address
  • Phone number
  • IP address
  • Browser
  • Terminal device
  • Order details: Products and purchase value

Brevo uses the Google Cloud Platform (GCP) infrastructure in the EU (Frankfurt a. M., Germany) to support the processing of local customer data.
The personal data processed by the GCP is stored on Google’s servers within the EU. By hosting these services at GCP, Brevo can increase the performance and reliability of the services. The purpose is to ensure that the data can be retrieved and to guarantee data security.

The purpose of processing by Brevo is to respond to your inquiries. The legal basis for the processing of personal data is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest is to offer a standardized and sorted system that allows us to process your contact requests quickly and in a sorted manner.
The data collected by Brevo is transmitted to Google for analysis. The legal basis for the transfer is Article 6 para. 1 lit f) GDPR. The purpose of the transfer is analysis for marketing purposes.
Brevo has a legitimate interest in the transmission to improve and optimize its services.

We have concluded a data processing agreement with Brevo for the use of Brevo (Article 28 GDPR). Brevo processes the data on our behalf in order to display the services on our website.
Brevo may pass this information on to third parties if this is required by law or if third parties process this data on behalf of Brevo.
If you have deactivated individual tracking services (e.g. by setting an opt-out cookie), the deactivation will continue for all affected tracking tags integrated by Brevo.

The legal basis for the processing of personal data described here is Article 6 para. 1 lit f) GDPR. Our legitimate interest lies in the benefits of integrating various services via Brevo. By integrating Brevo, we reduce the required maintenance effort as well as the loading effort of the website and the server and traffic load. Brevo has a legitimate interest in the (personal) data collected in order to improve its own services.

Your rights

1. right of withdrawal

You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Furthermore, you can prevent the installation of cookies by making the appropriate settings in your browser; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.

2. right of objection

You have the right to object if the processing of your data is not covered by your consent (proof of consent).
The objection should be addressed to PepperPapers Limited, 77 Camden Street Lower, Dublin, Dublin 2, D02 XE80, Ireland.

The processed information is only stored for as long as necessary for the intended purpose or as required by law.
The provision of personal data is neither legally nor contractually required and is also not necessary for the conclusion of a contract. You are also not obliged to provide the personal data. However, failure to do so may result in you not being able to use our website or not being able to use it to its full extent.

Tidio

We use Tidio (hereinafter: “Tidio”) to process user inquiries via our customer support channels or via live chat systems. The provider is Tidio LLC, 180 Steuart St, CA 94119, San Francisco, California, USA.

E-mails and chat messages that you send to us can be saved in the Tidio ticket system and answered by our employees in live chat. When you communicate with us via Tidio, all the data you entered before starting the chat (e.g. name or chat ID, address and telephone number) as well as your IP address, country of origin, browser and device used, website accessed and the messages exchanged are summarized in a profile and stored on Tidio’s servers.

The messages sent to us will remain with us until you ask us to delete them or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.

The use of Tidio is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in processing your requests as quickly, reliably and efficiently as possible. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.

Further information can be found in Tidio’s privacy policy: https://www.tidio.com/privacy-policy/.

Contract for order processing
We have concluded an order processing contract with the provider of Tidio. This is a contract required by data protection law, which ensures that the provider of Tidio processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Contact form

Nature and purpose of the processing:

The data you enter will be stored for the purpose of individual communication with you. For this purpose, a valid e-mail address and your name are required. This is used to assign the request and then answer it. The specification of further data is optional.

Legal basis:

The data entered in the contact form is processed on the basis of a legitimate interest (Art. 6 para. 1 lit. f GDPR).

By providing the contact form, we would like to make it easy for you to contact us. The information you provide will be stored for the purpose of processing your request and for possible follow-up questions.

If you contact us to request a quote, the data entered in the contact form will be processed to carry out pre-contractual measures (Art. 6 para. 1 lit. b GDPR).

Recipient:

Recipients of the data may be processors.

Storage duration:

Data will be deleted no later than 6 months after the request has been processed.

If there is a contractual relationship, we are subject to the statutory retention periods according to the German Commercial Code (HGB) and delete your data after these periods have expired

Provision prescribed or required:

The provision of your personal data is voluntary. However, we can only process your request if you provide us with your name, e-mail address and the reason for the request.

Use of Google Analytics

If you have given your consent, this website uses Google Analytics, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter: “Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymization on these websites, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html and at https://policies.google.com/?hl=de.

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.

The data sent by us and linked to cookies, user identifiers (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data that has reached the end of its retention period is automatically deleted once a month.

Withdrawal of consent:

You can prevent tracking by Google Analytics on our website by deactivating the marketing cookies via the website’s cookie settings. You can also prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: Browser Add On to deactivate Google Analytics.

Embedded YouTube videos

We embed YouTube videos on our website. The operator of the corresponding plugins is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA (hereinafter referred to as “YouTube”). YouTube, LLC is a subsidiary of Google LLC, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA (hereinafter “Google”). When you visit a page with the YouTube plugin, a connection to YouTube servers is established. YouTube is informed which pages you visit. If you are logged into your YouTube account, YouTube can assign your surfing behavior to you personally. You can prevent this by logging out of your YouTube account beforehand.

When a YouTube video is started, the provider uses cookies that collect information about user behavior.

Further information on the purpose and scope of data collection and its processing by YouTube can be found in the provider’s privacy policy, where you will also find further information on your rights in this regard and setting options to protect your privacy(https://policies.google.com/privacy).

Withdrawal of consent:

The provider does not currently offer the option of simply opting out or blocking data transmission. If you wish to prevent your activities on our website from being tracked, please revoke your consent for the corresponding cookie category or all technically unnecessary cookies and data transfers in the cookie consent tool. In this case, however, you may be able to use our website. or only to a limited extent.

SSL encryption

To protect the security of your data during transmission, we use state-of-the-art encryption methods (e.g. SSL) via HTTPS.

Information about your right to object in accordance with Art. 21 GDPR

Individual right of objection

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6 para. 1 lit. f GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.

Recipient of an objection

PepperPapers Limited


Changes to our privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.

Questions for the data protection officer

If you have any questions about data protection, please send us an e-mail or contact the person responsible for data protection in our organization directly: datenschutz (AT) pepperpapers.de

The privacy policy was created with the help of activeMind AG, the experts for external data protection officers (version #2020-09-30).

Last updated on: 04.07.2024

EN