DATA PRIVACY POLICY
CYBEX GmbH respects your privacy and understands that it is important to you, so we will strive to keep your personal information confidential and avoid unwanted contact. This Data Privacy Policy describes the type of information we collect and how we intend to use it. Please take a moment to read the following statement and understand how we process your data.
Table of contents:
General Provisions for data processing
1. The controller within the meaning of the EU General Data Protection Regulation ("GDPR")
2. Data Protection Officer
3. Personal data, purpose and legal basis
4. Minors
5. Disclosure of your data and transmission to third countries
6. Security notice
7. Duration of storage
8. Rights of the data subject
Special information on individual data processing
1. Provision of the website and creation of logfiles
2. Newsletter
3. Contacting us
• via the contact form
• by email
• by telephone
• via social media channels / instant messaging services
4. Online presence in social media
5. Cookies, web analytics, profiling and other third-party services
• Web Fonts
• Google Analytics
• Google AdSense
• Google Maps
• Plugins of social networks
6. Links to other websites
7. Data processing for the purpose of contract initiation and executions
8. Data collection at events
9. Online application process
General Provisions for data processing
1. The controller within the meaning of GDPR:
CYBEX GmbH („CYBEX“)
Managing Directors: Dr. Raoul Bader, Johannes Schlamminger, Kai Weisskopf
Address: Riedinger Str. 18, 95448 Bayreuth, Germany
Tel. +49 (0)92178511-0
E-Mail: info@cybex-online.com
2. Data protection officer:
E-Mail: dpo@goodbabyint.com
3. Personal data, Purpose and legal basis
Depending on the purpose, we collect and process different categories of personal data. The term personal data includes information such as first and last name, e-mail address, postal address, telephone number, date of birth, etc. We collect and process only the personal data necessary for the specific purpose.
The processing takes place, in particular, in accordance with Art. 6 para. 1 GDPR on the basis of the consent granted for particular purpose (Art. 6 para. 1 lit. a) GDPR), for the performance of contracts (Art. 6 para. 1 lit. b) GDPR) or to fulfill a legal obligation and protect vital interests (Art. 6 para. 1 lit. c) and d) GDPR). If necessary, we also process your data in order to safeguard our legitimate interests or legitimate interests of a third party (Art. 6 para. 1 lit. f) GDPR). A legitimate interest may be, for example, a necessary analysis for the purpose of direct customer or prospective customer approach, asserting legal claims and defense in legal disputes, optimizing and improving the user-friendliness of the services offered, market and opinion research, services or content, preventing misuse or criminal offences, guaranteeing IT security, implementing measures for business management and further development of products and services. For the further development of our services and products as well as for statistical purposes, we process your data in anonymous form.
Your personal data will be collected and processed for the following purposes on the following legal bases:
- Contract initiation and contract execution in accordance with Art. 6 para. 1 lit. b) GDPR
- Offering or performing our services in accordance with Art. 6 para. 1 lit. a), b) and f) GDPR
- Opening a customer in accordance with Art. 6 para. 1 lit. b) GDPR
- Registration of your product on our website in accordance with Art. 6 para. 1 lit. b) GDPR
- Obtaining information about our products, services, offers or other news resp. our newsletter in accordance with Art. 6 para. 1 lit. a)
- Customer management in accordance with Art. 6 para. 1 lit. b) and c), f) GDPR
- Establishing contact, communication and data exchange in accordance with Art. 6 para. 1 lit. a), b), f) GDPR
- PR and advertising in accordance with Art. 6 para. 1 lit. a), f) GDPR
- Application, recruitment and hiring (e-recruiting) in accordance with Art. 6 para. 1 lit. a), b) DSGVO
- Optimization of our customer service in accordance with Art. 6 para. 1 lit. f) GDPR
- Improvement of our products, research and development in accordance with Art. 6 para. 1 lit. a), c), d), e) and f) GDPR
- Guarantee of IT security according to Art. 6 para. 1 lit. c) and f) GDPR
4. Minors
Our website and services is not targeted to minors and, hence, we do not intentionally collect, store or process personal information of minors.
If young people under the age of 16 wish to use our services and provide their personal data to us, this is only allowed if a consent by the parent/ legal guardian is given. This may be reached if the contact details of the parent/ legal guardian, including the statement on the consent, are sent to us. These data as well as the data of the minor will then be processed in accordance with stipulations of this policy.
5. Disclosure of data and transfer to third countries
Within our organization, only those persons receive it who need your data to fulfil their contractual and legal obligations. The data may also be disclosed to third parties commissioned by us for further processing on the basis of an order processing contract. These are companies in the categories of IT services, logistics, printing services, telecommunications, debt collection, consulting, sales, PR and marketing, software providers, data maintenance and customer management.
We may also disclose your personal data to our affiliates based on legitimate interests for internal administrative purposes:
• gb GmbH (Riedingerstr. 18, 95448 Bayreuth, Germany; register number HRB6225)
• Columbus Trading-Partners GmbH & Co.KG (Riedingerstr. 18, 95448 Bayreuth, Germany; register number HRA4224)
• Goodbaby (Europe) GmbH & Co.KG (Riedingerstr. 18, 95448 Bayreuth, Germany; register number HRA4062)
• Goodbaby Czech Republic s.r.o. (Pobřežní 620/3, 186 00 Praha 8, Czech Republic; register number ID 04790316)
• Rollplay GmbH (Riedingerstr. 18, 95448 Bayreuth, Deutschland; register number HRB6725)
A transfer of data to institutions in countries outside the European Union (“EU”) or the European Economic Area (“EEA”) takes place insofar as:
• You have agreed to it,
• It is needed to execute your orders or perform services we offer,
• It is required by law,
• As part of the commissioned data processing,
• Within the Goodbaby/CYBEX group for internal administrative purposes.
In the case of order processing, the service providers are contractually bound to our instructions and obligated to guarantee the strict technical and organizational measures. The contract processors are located in both the countries that are subject to a European Commission adequacy decision, such as service providers in the United States that have been certified as EU-U.S. Privacy Shield, as well as in countries that do not protect personal data to the same extent as the EU. In these cases, we ensure that the level of data protection is comparable to that of the EU by means of contractual regulations and by agreeing the EU standard data protection clauses.
6. Security notice
In order to protect your data from manipulation, loss, destruction or unauthorized access, we use technical and organizational measures which are continuously improved in line with technical progress. Furthermore, all our employees and all individuals involved in information processing are under an obligation to observe data protection requirements and to ensure the confidential use of personal data.
7. Duration of storage
We adhere to the principles of data avoidance and data economy. We, therefore, store and process your personal data only for as long as this is necessary to achieve the purposes described herein or according to obligation to store data for a particular period defined by the legislator or we have a legitimate interest in the further storage. After the end of the respective purpose or the expiry of these deadlines, the corresponding data are routinely blocked or deleted in accordance with legal requirements.
Any further storage is only possible:
- if statutory retention and documentation obligations exist (for example, commercial and fiscal retention obligations),
- for the settlement of any warranty or liability claims,
- to assert, exercise or defend against legal claims,
- if there is another exception pursuant to Art. 17 Para. 3 GDPR.
8. Rights of the data subject
If your personal data is processed, you are the data subject within the meaning of the GDPR and you have the following rights:
• Right to information about your personal data stored with us, their origin and recipient and the purpose of data processing etc. (pursuant to Art. 15 GDPR),
• Right to rectification of incorrect or incomplete personal data stored by us (pursuant to Art. 16 GDPR),
• Right to restriction of processing of your personal data (pursuant to Art. 18 GDPR),
• Right to erasure of personal data concerning you (pursuant to Art. 17 GDPR),
• Right to notification (pursuant to Art. 19 GDPR),
• Right to data portability (pursuant to Art. 20 GDPR).
You also have the right, for reasons related to your particular situation, to object at any time to the processing of personal data concerning you carried out pursuant to Art. 6 para. 1 lit. e) or f) GDPR; this also applies to profiling based on this provision.
You can revoke your declaration of consent for the collection and use of your personal data at any time with effect for the future. The revocation of your consent does not affect the legality of the processing carried out on the basis of your consent until you revoke your consent.
All requests for information or objections to data processing can be addressed in writing to the postal address stated above or sent by e-mail to dpo@goodbabyint.com.
Right to lodge a complaint with a supervisory authority
According to Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR.
In Bavaria, the competent supervisory authority is the Data Protection Authority of Bavaria for the Private Sector (BayLDA).
Special Information on individual data processing activities
1. Provision of the website and creation of logfiles
You can browse this website mostly without providing any detailed personal information.
For technical reasons, data such as the following, which your internet browser transmits to us or to our web service provider (so called server log files), is collected:
• Type and version of the browser
• Operating system
• Device type (desktop, tablet, smartphone, etc.), the device brand, and the associated model.
• Websites that linked you to our site (Referrer URL)
• Websites that you visit
• Date and time of your visit
• our internet protocol (IP) address
• Name of the retrieved website / file
• Transferred data volume
• Message of successful retrieval
• Click paths
For reasons of technical security, in particular for protection against cyber-attack attempts on our web server, this data is stored by us for a short time (up to 14 days) in accordance with Art. 6 Para. 1 lit. f) GDPR. We are not able to draw conclusions about individual persons based on these data.
In anonymous form, the data is also evaluated for statistical purposes in order to optimize our Internet presence and our offers.
3. Contacting us
We offer you various possibilities to get in touch with us. If you contact us in one of the ways listed below, the personal data that you have provided to us in the course of establishing contact will be used for processing and answering your enquiry. The data will be processed in accordance with Art. 6 Para. 1 lit. f) GDPR, namely in our legitimate interest to be able to respond to your request. If the purpose of the request is to conclude a contract, the legal basis for the processing is also Art. 6 para. 1 lit. b) GDPR. The data collected and stored for this purpose may be disclosed to the companies or persons commissioned by us for further processing. We may forward your data to our authorized dealers or other business partners for the purpose of eg. processing a complaint or other enquiry. The data is also disclosed to software providers for the provision of customer management systems and for the technical support of such systems. Further disclosure may be made to our affiliates for internal administrative purposes based on legitimate interests. The data will only be passed on for the processing of your enquiries.
The data will be stored for as long as is necessary to achieve the purpose for which it was collected. This is the case when the respective conversation with the user has ended or when it can be inferred from the circumstances that the matter concerned has been conclusively clarified and there is no legitimate reason for further storage.
Establishing contact:
• via the contact form
If a user makes use of this option, the data entered in the input mask will be transmitted to us and stored. The provision of your data depends on your request and could include the following information: Salutation, first name, surname, e-mail, address and telephone number, and if applicable product information, vehicle data, details of the purchased product.
The processing of the personal data from the input mask serves us solely for the processing of the establishment of contact regarding product information, vehicle compatibility, customer service or general inquiries. The other personal data processed during the sending process (IP address of the user, date and time) serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
• via e-mail
If you contact us via e-mail, the personal data (including e-mail address) of the user transmitted with the e-mail will be stored.
• by phone
If you use our telephone consultation, we collect the following data: name, telephone number, description of your enquiry or matter.
• via social media channels / instant messaging services
If you contact us through social media channels such as Facebook, Instagram, Twitter, or using instant messaging services such as WhatsApp, Facebook Messenger, your username, the description of matter, and other personal information submitted will be processed. If you make use of such contact possibilities, you are informed and agree that your data will also be processed in accordance with the privacy poliucy in the current version of the respective provider, e.g:
Facebook, Messenger: https://www.facebook.com/about/privacy/
Instagram (Instagram LLC): https://help.instagram.com/519522125107875
WhatsApp: https://www.whatsapp.com/legal/?lang=en#privacy-policy
LinkedIn (LinkedIn Ireland U.C.): https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
XING (XING SE): https://privacy.xing.com/en/privacy-policy
In particular, we expressly draw your attention to the fact that your personal data (communication metadata) will be collected by the respective provider through the use of the aforementioned and similar services and that the data may also be processed on servers in countries outside the EU (e.g. USA). Most of these services (WhatsApp, Facebook, Twitter etc.) are certified under the Privacy Shield Agreement (https://www.privacyshield.gov/list) and thus offer a guarantee of compliance with European data protection laws. However, due to the transmission of the data, there are still possible risks that cannot be completely excluded despite the existing data protection and data security measures. Your personal data could possibly be processed beyond the actual purpose and obtained by third parties. We have neither exact knowledge nor influence on such data processing. You may also not be able to assert your data subject rights sustainably.
4. Online presence in social media
We have established our presence on social networks and platforms to communicate with our customers, users and any interested person. For this purpose, we process personal data of users in accordance with Art. 6 para. 1 lit. b) GDPR or on the basis of our legitimate interests according to Art. 6 para. 1 lit. f) GDPR. In particular, to facilitate communication with users, to be able to inform users about our products and services, to receive feedback on our products and services, to establish new contacts, to ensure the general organization of the company's presence, to promote products or services, to improve customer loyalty and to increase brand awareness.
When you access any of such network or platform, the terms of use and privacy policies of the respective provider apply:
• Facebook: Facebook Ireland Limited, Hanover Reach, 5-7 Hanover Quay, 2 Dublin, Ireland. https://www.facebook.com/about/privacy/
• LinkedIn: LinkedIn Ireland, Gardner House, Wilton Place, Wilton Plaza, Dublin 2, Ireland: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
• Twitter: Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA: https://twitter.com/en/privacy
• Instagram: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA: https://help.instagram.com/519522125107875
• Pinterest: Pinterest Inc., 808 Brannan Street San Francisco, CA 94103-4904, USA: https://policy.pinterest.com/en/privacy-policy
• Snapchat: Snap Inc., 63 Market Street Venice, CA 90291, USA: https://www.snap.com/en-US/privacy/privacy-policy/
• Youtube/Google (Google LLC): https://policies.google.com/privacy
• XING: XING SE, Dammtorstraße 30, 20354 Hamburg, Deutschland: https://privacy.xing.com/en/privacy-policy
In particular, we expressly draw your attention to the fact that your personal data (communication metadata) will be collected by the respective provider through the use of the aforementioned and similar services and that the data may also be processed on servers in countries outside the EU (e.g. USA). Most of these services (WhatsApp, Facebook, Twitter etc.) are certified under the Privacy Shield Agreement (https://www.privacyshield.gov/list) and thus offer a guarantee of compliance with European data protection laws. However, due to the transmission of the data, there are still possible risks that cannot be completely excluded despite the existing data protection and data security measures. Your personal data could possibly be processed beyond the actual purpose and obtained by third parties. We have neither exact knowledge nor influence on such data processing. You may also not be able to assert your data subject rights sustainably.
In the case of requests for information and the assertion of data subject rights, these can be asserted most effectively with the providers of social networks or platforms. If you need further assistance, please contact us.
The data may be disclosed to third parties commissioned by us for further processing in accordance with the purpose for which it was collected (e.g. software providers for the provision of customer management systems and for the technical support of such systems).
Unless otherwise stated in our Privacy Policy, we will process your data for as long as is necessary to achieve our goal, in particular as long as you communicate with us on social networks and platforms, post or comment, or send us messages.
5. Cookies, web analytics, profiling and other third-party services
In order to offer you an optimal usage of our website and other services, we use so-called cookies. Cookies serve to make our offer more user-friendly, more effective and safer. Cookies are small text files which are stored on your computer or on another device you use and which are saved by your browser. We use technically necessary cookies and functionality cookies in accordance with Art. 6 Para. 1 f GDPR on the basis of legitimate interests. Our legitimate interests are in ensuring the functioning of our website and its best possible usability. We also use analysis cookies and advertising cookies as well as tracking tools in accordance with Art. 6 Para. 1 f GDPR and Recital 47 on the basis of legitimate interests. It is our legitimate interest to adapt our website optimally to the interests of our customers as well as to assess the number of visitors, posts, page views, reviews and followers in order to optimize future marketing campaigns.
Some of these cookies are temporarily stored and automatically deleted when the browser is closed (session cookies). Other cookies (persistent cookies) are stored permanently and are only removed from your browser cache when you manually delete them. These cookies allow us to recognize your browser the next time you visit.
If you do not agree with the use of cookies, you can or must actively delete and/or deactivate them yourself. This must be configured via the respective browser settings. If cookies are deactivated, the functionality of this website may be restricted.
Third party cookies and tracking tools used:
5.1 Fonts
We use Web Font Services: Typography and Adobe Typekit (Adobe Fonts) (Privacy Policy: https://www.adobe.com/de/privacy/policies/adobe-fonts.html) on this Website to ensure that the content is displayed accurately and graphically appealing across browsers. In order to provide the Adobe Fonts service, Adobe (Adobe Systems Software Ireland Limited) may collect information about the fonts that are provided for this website. Adobe uses the collected information to provide their services, to diagnose delivery or download problems, and to pay for and fulfill Adobe's contracts with font manufacturers whose fonts are used.
5.2 Google Analytics
Our website uses Google Analytics, a web analysis service from Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as “Google“. Google Analytics uses so-called “cookies“, text files that are stored to your computer in order to facilitate an analysis of your use of the site.
The information generated by these cookies, such as time, place and frequency of your visits to our site, including your IP address, is transmitted to Google’s location in the US and stored there.
We use Google Analytics with an IP anonymization feature on our website. In doing so, Google abbreviates and thereby anonymizes your IP address before transferring it from member states of the European Union or signatory states to the Agreement on the European Economic Area.
Google will use this information to evaluate your usage of our site, to compile reports on website activity for us, and to provide other services related to website- and internet usage. Google may also transfer this information to third parties if this is required by law or to the extent this data is processed by third parties on Google´s behalf.
Google states that it will in never associate your IP address with other data held by Google. You can prevent cookies from being installed by adjusting the settings on your browser software accordingly. You should be aware, however, that by doing so you may not be able to make full use of all the functions of our website.
Google also offers a disabling option for the most common browsers, thus providing you with greater control over the data which is collected and processed by Google. If you enable this option, no information regarding your website visit is transmitted to Google Analytics. However, the activation does not prevent the transmission of information to us or to any other web analytics services we may use. For more information about the disabling option provided by Google, and how to enable this option, visit https://tools.google.com/dlpage/gaoptout?hl=en
5.3 Google AdSense
We use Google AdSense on our website which is a service of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, for incorporating advertisements. Google-AdSense uses so-called “cookies“, text files, that are stored to your computer and which provide analysis of the use of our website. Furthermore, Google AdSense uses so-called “web beacons“, which allow Google to analyze information, such as visitor traffic to our website. This information, along with your IP address and the ad format displayed, is transmitted to Google in the US where it is stored and may be transferred by Google to contracting partners. However, Google does not merge your IP-address with other stored data on you. You can prevent cookies from being installed by adjusting the settings on your browser software accordingly. You should be aware, however, that by doing so you may not be able to make full use of all the functions of our website. By using our website, you declare that you agree to the processing of data collected about you by Google in the manner previously described and for the purposes there specified.
5.4 Google Maps
We use the service Google Maps to help you find a nearby retailer or to plan a route. Google Maps is a service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. This service is governed by Google's Privacy Policy:
https://www.google.com/intl/de_en/policies/privacy/), as amended by the separate Google Maps Privacy Policy (https://www.google.com/intl/de_en/help/terms_maps.html.
When you visit our website or access other services that include Google Maps, your browser establishes a direct connection with Google's servers. The map content is transmitted by Google directly to your browser and integrated into the page. We therefore have no influence on the extent of the data collected by Google. Through the use of Google Maps, information including your user settings, IP address and your current location or the (start) address entered as part of the route planner function may be transmitted to Google in the USA.
We expressly draw your attention to the fact that we have no influence on the further processing and use of the data by Google. If you do not want Google to collect the data about you, you can prevent Google Maps from executing by selectively blocking the execution of the Java script code used by using a Java script blocker; alternatively, you can also completely deactivate Java script execution in your browser settings. In this case, however, you cannot use the map display.
5.5 Plugins of social networks
Our website uses plugins of social networks. When you visit our pages, the plug-in will provide a direct connection between your browser and the social network provider. We have no influence on the data collected by the plugin. If you are logged into the social network, a link between your user account and the use of our website can be established. If you are interacting with the plugins, such as by clicking on "Like", "Follow" or "Share" or write a comment, this information may automatically appear in your profile on the social network. If you are a member of one or more of the following social networks and do not want the provider to merge the use of our website with data stored on the social network, please log out of the social network before using our website.
Provider of the plugins used on our website:
• Facebook: Facebook Ireland Limited, Hanover Reach, 5-7 Hanover Quay, 2 Dublin, Ireland. https://www.facebook.com/about/privacy/
• Google+: Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA: http://www.google.de/intl/de/policies/privacy/
• LinkedIn: LinkedIn Ireland, Gardner House, Wilton Place, Wilton Plaza, Dublin 2, Ireland: http://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
• Twitter: Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA: https://twitter.com/privacy.
• Instagram: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA: http://instagram.com/about/legal/privacy/
• Pinterest: Pinterest Inc., 808 Brannan Street San Francisco, CA 94103-4904, USA: https://policy.pinterest.com/en/privacy-policy
• Snapchat: Snap Inc., 63 Market Street Venice, CA 90291, USA: https://www.snap.com/en-US/privacy/privacy-policy/
6. Links to other websites
Our site contains links to third-party websites. Please note that by clicking on these links you leave our website and we have no influence on the contents of the linked pages. We are, therefore, not responsible for the protection of your data on websites linked by us and for these pages our Data Privacy Policy is not valid.
7. Data processing for the purpose of contract initiation and execution
We collect, store and use personal data (e.g. name, last name, address, telephone number, e-mail address) of the interested persons, customers, or business partners for the purpose of establishing, executing and terminating a contract. The personal data processed for this purpose, the scope and purpose, are determined by the underlying contractual relationship or the pre-contractual services. Before the conclusion of a contract - i.e. in the contract initiation phase - the personal data is processed for the preparation of offers, contracts or for the fulfilment of other enquires of the interested persons with regard to the conclusion of a contract. Interested persons may be contacted during the preparation of the contract using the data they have provided. The legal basis for this processing is Art. 6 para. 1 lit. b) GDPR.
8. Data collection at events
As part of our business activities, we regularly orginize events such as trade fairs, marketing events, etc. primarily in the B2B area. In this context, we collect, use and store personal data of participants in accordance with Art. 6 para. 1 lit. a), b) or f) GDPR. Insofar as we process the data based on our legitimate interests, this is done in particular to establish and maintain the company’s presence and corporate communication, to increase brand awareness, and to promote commercial objectives.
During our events, image, sound or video recordings are made by persons and service providers commissioned or accredited by us. The recordings document both the event itself and the participation of individuals.
In the case of image or video recordings focusing on individuals, the participants have the right at any time to inform the photographer or videographer that they do not wish to be depicted. We assume that the persons participating in the event agree through their conduct e.g. through willing actions such as "posing" or "looking directly into the camera" to the creation and publication of recordings for the purposes of corporate communication, including online and social media.
9. Online application process
We offer you the opportunity to apply for a job in our company through over E-Recruiting portal. In the registration process, please note our data privacy statement for e-recruiting.
However, if you prefer to apply for a job by e-mail, we point out that your data and the file attachments sent with it will be transferred via an unsecured connection.
The collection and processing of your personal data is carried out exclusively for the purpose of filling positions within our group of companies. The legal basis for this processing is Art. 6 Para. 1 lit. b) GDPR. Your data will only be forwarded to the internal positions and departments of our company responsible for the particular application procedure.
Your personal data will be deleted automatically six months after completion of the application process, unless we have concluded an employment contract with you. This does not apply if statutory provisions preclude deletion, if further storage is necessary for the purpose of providing evidence or if you have expressly agreed to longer storage. Should we wish to include your application in our talent pool, we will contact you.
.
.
.
.
.