Legal

Privacy Policy

Information on the processing of personal data

Introduction

With the following privacy policy we would like to inform you which types of your personal data (hereinafter also referred to as “data”) we process for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter jointly referred to as the “online offering”).

The terms used are not gender-specific.

Data Controller

Dr.Q GmbH
Emil-Figge-Straße 80
44227 Dortmund

Authorized representative:
Marian Harling

Email:
marian@askdrq.com

Overview of Processing

The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.

Types of data processed

  • Inventory data
  • Contact data
  • Content data
  • Usage data
  • Meta / communication data

Categories of data subjects

  • Communication partners
  • Users

Purposes of processing

  • Provision of contractual services and customer service
  • Contact requests and communication
  • Reach measurement
  • Feedback
  • Marketing
  • Profiles with user-related information
  • Provision of our online offering and usability

Relevant Legal Bases

Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection provisions may apply in your or our country of residence or domicile.

  • Consent (Art. 6 (1) sentence 1 lit. a GDPR) — the data subject has given consent to the processing of their personal data for one or more specified purposes.
  • Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at their request prior to entering into a contract.
  • Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

In addition to the data protection provisions of the GDPR, national data protection rules apply in Germany, in particular the Federal Data Protection Act (BDSG).

Security Measures

In accordance with legal requirements and taking into account the state of the art, the cost of implementation and the nature, scope, circumstances and purposes of processing, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

IP masking

To the extent that IP addresses are processed by us or by the service providers we use and the processing of a complete IP address is not necessary, the IP address will be shortened. In this case, the last two digits or the last part of the IP address after a dot are removed or replaced with a placeholder.

SSL encryption (https)

To protect the data you transmit via our online offering we use SSL encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.

Transmission of Personal Data

In the course of our processing of personal data it may happen that the data is transmitted to other bodies, companies, legally independent organisational units or persons, or is disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases we observe the legal requirements and in particular conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

Data Processing in Third Countries

To the extent that we process data in a third country (i.e. outside the European Union or the European Economic Area) or the processing takes place in connection with the use of third-party services, this is only done in accordance with the legal requirements.

Subject to explicit consent or contractually or legally required transmission, we only process or have processed data in third countries with a recognised level of data protection, contractual obligation through so-called standard protection clauses of the EU Commission, or on the basis of certifications (Art. 44 to 49 GDPR).

Deletion of Data

The data processed by us will be deleted in accordance with legal requirements as soon as the consents permitting the processing are revoked or other permissions cease to apply.

If the data is not deleted because it is required for other and legally permitted purposes, its processing will be limited to these purposes. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law.

Use of Cookies

Cookies are small text files or other storage markers that store information on end devices and read information from end devices. For example to save the login status of a user account, the contents of a shopping cart in an e-shop, the content accessed or the functions of an online offering that have been used.

We use cookies in accordance with the statutory provisions. We therefore obtain prior consent from users, unless this is not required by law.

Storage duration

  • Temporary cookies (session cookies): deleted at the latest after a user has left an online offering and closed their end device.
  • Permanent cookies: remain stored even after the end device has been closed. The storage duration can be up to two years.

Revocation and objection

Users can revoke any consent they have given at any time and also object to processing in accordance with the statutory provisions in Art. 21 GDPR. Users can also declare their objection via their browser settings.

Provision of the Online Offering and Web Hosting

In order to be able to provide our online offering securely and efficiently, we use the services of one or more web hosting providers from whose servers the online offering can be retrieved.

Data processed

  • Content data (e.g. entries in online forms)
  • Usage data (e.g. websites visited, access times)
  • Meta / communication data (e.g. device information, IP addresses)

Collection of access data and log files

We or our web hosting provider collect data on each access to the server (server log files). Log-file information is stored for a maximum of 30 days and then deleted or anonymised.

Webflow

We use Webflow services to build static websites, which may also include online forms. Service provider: Webflow, Inc., 208 Utah, Suite 210, San Francisco, CA 94103, USA. Privacy policy

Contact and Inquiry Management

When contacting us (e.g. via contact form, email, telephone or social media) as well as within the framework of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to answer the contact requests and any measures requested.

Data processed

  • Inventory data (e.g. names, addresses)
  • Contact data (e.g. email, telephone numbers)
  • Content data (e.g. entries in online forms)

Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR); Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR).

Web Analytics, Monitoring and Optimisation

Web analytics is used to evaluate the visitor flows of our online offering and can include behaviour, interests or demographic information about visitors as pseudonymous values. With the help of reach analysis we can identify at which times our online offering or its functions are used most frequently.

Users' IP addresses are stored. However, we use an IP masking procedure to protect users. In general, no clear-text data of the users (such as email addresses or names) is stored, only pseudonyms.

Google Analytics

Web analytics, reach measurement and measurement of user flows. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy · Opt-out

Presence on Social Networks

We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about ourselves.

Please note that user data may be processed outside the area of the European Union. This may result in risks for users because, for example, enforcement of user rights could be made more difficult.

LinkedIn

Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Privacy policy · Opt-out

YouTube

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy · Opt-out

Plugins and Embedded Functions and Content

We integrate function and content elements into our online offering that are obtained from the servers of their respective providers. This may include, for example, graphics, videos or city maps.

The integration always requires that the third-party providers of this content process the users' IP addresses because without the IP address they could not send the content to their browsers.

Google Fonts

Retrieval of fonts from the provider Google for the purpose of technically secure and maintenance-free use of fonts. The user's IP address is transmitted to Google so that Google can provide the fonts in the browser. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy

Rights of Data Subjects

As a data subject you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you.
  • Right to withdraw consent: you have the right to withdraw consent given at any time.
  • Right of access: you have the right to request confirmation as to whether relevant data is being processed and to obtain information about this data in accordance with the statutory provisions.
  • Right to rectification: you have the right to demand the completion of the data concerning you or the rectification of incorrect data concerning you.
  • Right to erasure and restriction of processing: you have the right, in accordance with the statutory provisions, to demand that data concerning you be deleted without delay, or alternatively to demand a restriction of processing.
  • Right to data portability: you have the right to receive data concerning you in a structured, commonly used and machine-readable format or to request its transmission to another controller.
  • Complaint to a supervisory authority: you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of the personal data concerning you infringes the GDPR.