Privacy policy

Information on data protection

The use of this website may involve the processing of personal data. In order to make this processing comprehensible for you, we would like to provide you with an overview of this processing with the following information. In order to ensure fair processing, we would also like to inform you about your rights under the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Responsible for data processing is

VARTAN.AERO GmbH
Neßpriel 2, 21129 Hamburg 
Germany

(hereinafter referred to as "we" or "us").

  1. General information
  2. Contact

If you have any questions or suggestions regarding this information or would like to contact us to assert your rights, please send your enquiry to

VARTAN.AERO GmbH
Boschstraße 1, 22761 Hamburg
Germany

+49 40 468 96 10 10
info(at)vartan.aero

 b. General information on data processing


 When using this website, personal data may be processed. The data protection term "personal data" refers to all information that relates to an identified or identifiable person. The IP address can also be personal data. An IP address is assigned to every device connected to the internet by the internet provider so that it can
send and receive data. When you visit the website, we collect information that you provide yourself. We also automatically collect certain information about your use of the website during your visit to the website.
 We process personal data in compliance with the relevant data protection regulations, in particular the GDPR and the BDSG. Data processing by us only takes place on a legal basis. When visiting this website, we only process personal data with your consent (Art. 6 para. 1 sentence 1 a) GDPR), for the fulfilment of a contract to which you are a party to or at your request for the implementation of pre-contractual measures (Art. 6 para. 1 sentence 1 b) GDPR), for the fulfilment of a legal obligation (Art. 6 para. 1 sentence 1 c) GDPR) or if the processing is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require the protection of personal data (Art. 6 para. 1 sentence 1 f) GDPR). If you apply for an open position in our company, we will also process your personal data to decide on the establishment of an employment relationship (§26 para. 1 sentence 1 BDSG).

  1. Duration of storage

Unless otherwise stated in the following, we only store the data for as long as is necessary to achieve the purpose of processing or to fulfil our contractual or legal obligations. Such statutory retention obligations may arise in particular from commercial or tax law regulations.

  1. Technical service providers

Unless otherwise stated in the following information, the data is processed on the servers of technical service providers commissioned by us for this purpose. These service providers only process the data in accordance with our documented instructions and are contractually obliged to guarantee adequate technical and organizational measures for the protection of personal data.

  1. Processing of server log files

When using our website for purely informational purposes, general information that your browser transmits to our server is initially stored automatically (so not via registration). By default, this includes: browser type/version, operating system used, page accessed, the previously visited page (referrer URL), IP address, date and time of the server request and HTTP status code.
The processing is carried out to protect our legitimate interests and is based on the legal basis of Art. 6 para. 1 sentence 1 f) GDPR. This processing serves the technical administration and security of the website. The stored data is deleted after seven days unless there is a justified suspicion of unlawful use based on concrete indication and further examination and processing of the information is necessary for this reason.

  1. Contact options and requests

Our website contains a contact form which you can use to send us messages. The transfer of your data is encrypted. All data fields marked as mandatory are required to process your request. If you do not provide this data, we will not be able to process your request. The provision of further data is voluntary. Alternatively, you can also send us a message via the contact e-mail. We process the data for the purpose of answering your request. The legal basis for data processing is Art. 6 para. 1 sentence 1 b) GDPR.

  1. Application via our website (Jobs)

If you apply to our company, we will process your application data exclusively for purposes related to your interest in current or future employment with us and the processing of your application. Your application will only be processed and acknowledged by the relevant contact persons at our company. All employees entrusted with data processing are obliged to maintain the confidentiality of your data.
 If we are unable to offer you employment, we will retain the data you have submitted for up to six months after rejection for the purpose of answering questions in connection with your application and the rejection. This does not apply if statutory provisions prevent deletion, if further storage is necessary for the purpose of providing evidence or if you have expressly consented to longer storage.
The legal basis for this data processing is 26 para. 1 sentence 1 BDSG. If we store your applicant data for longer than six months and you have expressly consented to this, we would like to point out that this consent can be freely revoked at any time in accordance with Art. 7 para. 3 GDPR. Such a revocation does not affect the legality of the processing that was carried out on the basis of the consent until the revocation.

  1. Cookies

We use cookies on our website. Cookies are small text files that are stored by your browser when you visit a website. This identifies the browser used and can be recognised by our web server.
In particular, we use persistent cookies to analyse our website. These cookies are automatically deleted after a specified period, which may vary depending on the cookie.
If this use of cookies results in the processing of personal data, this is based on the legal basis of Art. 6 para. 1 sentence 1 f) GDPR. This processing serves our legitimate interest in making our website more user-friendly, effective and secure. You can delete cookies in the security settings of your browser at any time. You can generally object to the use of cookies through your browser settings. Further information on this can be found at the Federal Office for Information Security at https://www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/EinrichtungSoftware/EinrichtungBrowser/Sicherheitsmassnahmen/Cookies/cookies_node.html.

 

  1. Cloudflare

We use the Cloudflare service from Cloudflare Inc. (USA) on our Shopify website to detect malicious visitors to our websites and to minimise the blocking of legitimate users. For such integration, it is technically necessary to process your IP address so that the content can be sent to your browser. Your IP address is therefore transmitted to Cloudflare. You can object to this data processing at any time via the settings of the browser used or certain browser extensions. Please note that this may result in functional restrictions on the website.

Your data is processed on the basis of Art. 6 para 1 sentence 1 (f) GDPR and is based on our legitimate interest in the optimisation and economic operation of our website.

When using the service, a transfer of your data to the USA cannot be ruled out. Please note the information in the section "Data transfer to third countries". Further information on data protection at Cloudflare can be found in Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/.

  1. Online shop

If you order a product via our website, we process personal data exclusively for contract fulfilment or respectively to be able to provide you with the ordered product. As part of the booking or ordering process, we only process the data that you yourself have entered in the entry form and, if applicable, payment information if you pay by bank transfer in advance. In order to be able to deliver the ordered products to you, we transmit your data required for the delivery to one of our shipping service providers as specified in the order. The legal basis for the processing is Art. 6 para. sentence 1 b) GDPR. All data fields marked as mandatory are required to process your booking or order. Failure to provide this data means that we will not be able to process your booking or order.

The provision of further data is voluntary. We process such voluntarily provided data on the basis of Art. 6 para. 1 sentence f) GDPR.

  1. Revocation of consent

If you have given us separate consent to process your data, you can withdraw this consent at any time in accordance with Art. 7 para. 3 GDPR. Such a revocation does not affect the legality of the processing that was carried out on the basis of the consent until the revocation.

  1. Your rights

As a data subject, you have the right to assert your data subject rights towards us. In particular, you have the following rights:

  • In accordance with Art. 15 GDPR and § 34 BDSG, you have the right to request information as to whether or not we process personal data relating to you and, if so, to what extent.
  • You have the right to demand that we rectify your data in accordance with Art. 16 GDPR.
  • You have the right to demand that we erase your personal data in accordance with Art. 17 GDPR and § 35 BDSG.
  • You have the right to restrict the processing of your personal data in accordance with Art. 18 GDPR.
  • In accordance with Art. 20 GDPR, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller.
  1. Right of objection

In accordance with Art. 21 GDPR, you have the right to object to any processing based on the legal basis of Art. 6 para. 1 sentence 1 e) or f) GDPR. If we process personal data about you for the purpose of direct marketing, you can object to this processing in accordance with Art. 21 (2) and (3) GDPR.

  1. Data protection officer

    You can reach our data protection officer using the following contact details:

Herting Oberbeck Datenschutz GmbH,
Hallerstr. 76, 20146 Hamburg ,
https://www.datenschutzkanzlei.de
E-mail: datenschutz@vartan.aero

  1. Complaint to a supervisory authority

If you believe that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR.

  1. Data processing on our social media pages

We have a company page on several social media platforms. In this way, we would like to offer further opportunities for information about our company and for dialogue. Our company has company pages on the following social media platforms: Facebook, LinkedIn


When you visit or interact with a profile on a social media platform, personal data about you may be processed. The information associated with a social media profile used also regularly constitutes personal data. This also includes messages and statements made using the profile. In addition, certain information is often automatically collected during your visit to a social media profile, which may also constitute personal data.

  1. Visiting a social media page
  2. Facebook page

When you visit our Facebook page, which we use to present our company or individual products from our range, certain information about you is processed. The sole controller for this processing of personal data is Meta Platforms Ireland Limited (Ireland/EU - "Meta"). Further information on the processing of personal data by Meta can be found at https://www.facebook.com/privacy/explanation. Meta offers the possibility to object to certain data processing; information and opt-out options in this regard can be found at https://www.facebook.com/settings?tab=ads.


Meta provides us with statistics and insights for our Facebook page in anonymised form, which helps us to gain knowledge about the types of actions people take on our page (so-called "page insights"). These Page Insights are created on the basis of certain information about people who have visited our page. This processing of personal data is carried out by Meta and us as joint controllers. The processing serves our legitimate interest in analyzing the types of actions taken on our site and improving our site based on these findings. The legal basis for this processing is Article 6 para. 1 sentence 1 (f) GDPR. We cannot assign the information obtained via Page Insights to individual user profiles that interact with our Facebook page. We have entered into a joint controllership agreement with Meta, which sets out the distribution of data protection obligations between us and Meta. Details of the processing of personal data for the creation of Page Insights and the agreement concluded between us and Meta can be found at https://www.facebook.com/legal/terms/information_about_page_insights_data. With regard to this data processing, you have the option of asserting your data subject rights (see "Your rights") towards Meta. Further information on this can be found in Meta's privacy policy at https://www.facebook.com/privacy/explanation.


Please note that user data is also processed in the USA or other third countries in accordance with the Meta Privacy Policy. Meta only transfers user data to countries for which the European Commission has issued an adequacy decision in accordance with Art. 45 GDPR or on the basis of suitable guarantees in accordance with Art. 46 GDPR.

  1. LinkedIn company page

In principle, LinkedIn Ireland Unlimited Company (Ireland/EU - "LinkedIn") is the sole controller for the processing of personal data when you visit our LinkedIn page. Further information on the processing of personal data by LinkedIn can be found at https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy.


When you visit our LinkedIn company page, follow this page or engage with the page, LinkedIn processes personal data to provide us with statistics and insights in anonymised form. This gives us insights into the types of actions that people take on our site (so-called page insights). In particular, LinkedIn processes data that you have already provided to LinkedIn via the information in your profile, such as data on function, country, industry, seniority, company size and employment status. In addition, LinkedIn will process information about how you interact with our LinkedIn company page, e.g. whether you are a follower of our LinkedIn company page. With the Page Insights, LinkedIn does not provide us with any personal data about you. We only have access to the summarised Page Insights. It is also not possible for us to draw conclusions about individual members from the information in the Page Insights. This processing of personal data in the context of Page Insights is carried out by LinkedIn and us as joint controllers. The processing serves our legitimate interest in analysing the types of actions taken on our LinkedIn company page and improving our company page based on these findings. The legal basis for this processing is Article 6 para. 1 sentence 1 f) GDPR. We have entered into an agreement with LinkedIn on processing as joint controllers, which sets out the distribution of data protection obligations between us and LinkedIn. The agreement is available at: https://legal.linkedin.com/pages-joint-controller-addendum. The following applies:

  • LinkedIn and we have agreed that LinkedIn is responsible for enabling you to exercise your rights under the GDPR. You can contact LinkedIn online via the following link (https://www.linkedin.com/help/linkedin/ask/PPQ?lang=de) or reach LinkedIn via the contact details in the Privacy Policy. You can contact the Data Protection Officer at LinkedIn Ireland via the following link: https://www.linkedin.com/help/linkedin/ask/TSO-DPO. You can also contact us using the contact details provided to exercise your rights in connection with the processing of personal data in the context of Page Insights. In such a case, we will forward your enquiry to LinkedIn.
  • LinkedIn and we have agreed that the Irish Data Protection Commission is the lead supervisory authority overseeing processing for Page Insights. You always have the right to lodge a complaint with the Irish Data Protection Commission (see www.dataprotection.ie) or any other supervisory authority.

Please note that in accordance with the LinkedIn privacy policy, personal data is also processed by LinkedIn in the USA or other third countries. LinkedIn only transfers personal data to countries for which the European Commission has issued an adequacy decision in accordance with Art. 45 GDPR or on the basis of suitable guarantees in accordance with Art. 46 GDPR.

Status: 10/2022