Privacy Policy
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to personally identify you. Detailed information on data protection can be found in the Privacy Policy set out below.
Data Collection on This Website
Who is responsible for data collection on this website?
The processing of data on this website is carried out by the website operator. The operator's contact details can be found in the section "Information on the Controller" of this Privacy Policy.
How do we collect your data?
Some data is collected when you provide it to us. This may include, for example, information that you enter into a contact form or send to us by email.
Other data is collected automatically or after your consent when you visit the website by our IT systems. This mainly includes technical data (e.g. internet browser, operating system or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the error-free operation of the website.
Other data may be used to analyse your user behaviour.
If contracts can be concluded or initiated via this website, the transmitted data will also be processed for contract offers, orders or other business inquiries.
What rights do you have regarding your data?
You have the right at any time to obtain, free of charge, information about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data.
If you have given your consent to data processing, you may revoke this consent at any time with effect for the future.
You also have the right, under certain circumstances, to request the restriction of the processing of your personal data.
Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
If you have any questions regarding data protection or your personal data, you may contact us at any time.
2. Hosting
The content of this website is hosted by the following provider:
Squarespace
The provider is Squarespace Ireland Ltd., Le Pole House, Ship Street Great, Dublin 8, Ireland (hereinafter "Squarespace").
Squarespace is a platform for creating and hosting websites. When you visit our website, your data is processed on Squarespace's servers. Personal data may also be transferred to Squarespace's parent company, Squarespace Inc., 8 Clarkson St, New York, NY 10014, USA.
Squarespace also stores cookies that are necessary for displaying the website and ensuring its security (essential cookies).
The use of Squarespace is based on Art. 6 (1) lit. f GDPR, as we have a legitimate interest in the most reliable presentation of our website. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g. device fingerprinting). Consent may be revoked at any time.
Data transfers to the United States are based on the Standard Contractual Clauses (SCCs) approved by the European Commission.
Further information is available at:
https://support.squarespace.com/hc/en-us/articles/360000851908
Squarespace is also certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when personal data is processed in the United States.
More information can be found at:
https://www.dataprivacyframework.gov/participant/4774
3. General Information and Mandatory Information
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection regulations and this Privacy Policy.
When you use this website, various personal data is collected. Personal data is any information that can be used to personally identify you. This Privacy Policy explains what data we collect, what we use it for, and how and for what purpose this is done.
Please note that data transmission over the Internet (e.g. communication by email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the Controller
The controller responsible for data processing on this website is:
Hanna Tkachenko
Martinstr. 6a
97828 Marktheidenfeld
Germany
Phone: +49 179 6048730
Email: info@hannatkachenko.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Storage Period
Unless a more specific storage period has been specified within this Privacy Policy, your personal data will remain with us until the purpose for processing no longer applies.
If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law). In the latter case, deletion will take place once these reasons no longer apply.
General Information on the Legal Basis for Data Processing
If you have given your consent to data processing, we process your personal data on the basis of Art. 6 (1) lit. a GDPR or, where special categories of personal data are processed, Art. 9 (2) lit. a GDPR.
In the event of explicit consent to the transfer of personal data to third countries, processing is also based on Art. 49 (1) lit. a GDPR.
If you have consented to the storage of cookies or access to information on your device (e.g. via device fingerprinting), processing is additionally based on Section 25 (1) TDDDG. Consent may be withdrawn at any time.
Where your data is required for the performance of a contract or for carrying out pre-contractual measures, we process your data on the basis of Art. 6 (1) lit. b GDPR.
Furthermore, we process your data where necessary to fulfil a legal obligation on the basis of Art. 6 (1) lit. c GDPR.
Data processing may also be based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
The specific legal basis applicable in each individual case is explained in the relevant sections of this Privacy Policy.
Recipients of Personal Data
As part of our business activities, we cooperate with various external service providers. In some cases, this requires the transfer of personal data to these external parties.
We only disclose personal data where this is necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest pursuant to Art. 6 (1) lit. f GDPR, or where another legal basis permits the disclosure.
When using processors, we only transfer personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint controller agreement is concluded.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent.
You may withdraw your consent at any time with future effect. The lawfulness of the data processing carried out before the withdrawal remains unaffected.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
Where data processing is based on Art. 6 (1) lit. e or lit. f GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data. This also applies to profiling based on these provisions.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves the establishment, exercise or defence of legal claims.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. This also applies to profiling insofar as it is related to such direct marketing.
If you object, your personal data will no longer be used for direct marketing purposes.
Right to Lodge a Complaint with the Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work or the place of the alleged infringement.
This right exists without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfilment of a contract in a commonly used, machine-readable format, or to have it transferred to another controller where technically feasible.
Right of Access, Rectification and Erasure
Within the framework of the applicable legal provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin, recipients and the purpose of the data processing.
You also have the right to request the correction or deletion of this data.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data.
This right exists in particular in the following cases:
if you contest the accuracy of your personal data while we verify its accuracy;
if the processing is unlawful and you request restriction instead of deletion;
if we no longer need your data but you require it for the establishment, exercise or defence of legal claims;
if you have objected pursuant to Art. 21 GDPR and it has not yet been determined whose interests prevail.
Where processing has been restricted, such data may only be processed with your consent or for the establishment, exercise or defence of legal claims or for reasons of important public interest.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries sent to us, this website uses SSL or TLS encryption.
You can recognize an encrypted connection by the change in the browser address line from "http://" to "https://" and by the lock symbol in your browser.
If SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to Promotional Emails
The use of contact data published as part of the legal notice obligation for sending unsolicited advertising or informational material is hereby prohibited.
The operators of this website expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, such as spam emails.
4. Data Collection on This Website
Cookies
Our website uses so-called "cookies." Cookies are small data files that do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies may originate from us (first-party cookies) or from third-party providers (third-party cookies). Third-party cookies enable the integration of certain services provided by third parties within websites (e.g. cookies for processing payment services).
Cookies serve various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies may be used to analyze user behavior or for marketing purposes.
Cookies that are necessary for carrying out electronic communication, for providing certain functions requested by you (e.g. shopping cart functionality), or for optimizing the website (e.g. audience measurement) (necessary cookies) are stored on the basis of Art. 6 (1) lit. f GDPR, unless another legal basis applies.
The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services.
Where consent has been requested for the storage of cookies and similar technologies, processing is carried out exclusively on the basis of your consent (Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG). Consent may be withdrawn at any time.
You can configure your browser to inform you about the use of cookies, allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing your browser. Disabling cookies may limit the functionality of this website.
Where additional cookies or third-party services are used on this website, these are explained separately in this Privacy Policy.
Server Log Files
The provider of this website automatically collects and stores information in server log files, which your browser automatically transmits to us.
This information includes:
Browser type and browser version
Operating system used
Referrer URL
Host name of the accessing computer
Time of the server request
IP address
This data is not merged with other data sources.
The collection of this data is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website. For this purpose, server log files must be collected.
Contact by Email or Telephone
If you contact us by email or telephone, your inquiry, including all resulting personal data (such as your name and message), will be stored and processed by us for the purpose of handling your request.
We will not pass this data on without your consent.
The processing of this data is based on Art. 6 (1) lit. b GDPR, provided your inquiry is related to the performance of a contract or necessary for pre-contractual measures.
In all other cases, processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6 (1) lit. f GDPR) or on your consent (Art. 6 (1) lit. a GDPR), where such consent has been requested. Consent may be withdrawn at any time.
The data you send us through contact inquiries will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for storing the data no longer applies (for example, after your inquiry has been fully processed). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
5. Social Media
This website includes functions of the Instagram service. These functions are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
If the social media element is active, a direct connection is established between your device and the Instagram server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This enables Instagram to associate your visit to this website with your user account.
Please note that, as the provider of this website, we have no knowledge of the content of the transmitted data or how Instagram uses it.
The use of this service is based on your consent pursuant to Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG. You may withdraw your consent at any time.
Where personal data is collected on our website with the help of this tool and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, are jointly responsible for this data processing pursuant to Art. 26 GDPR.
This joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook or Instagram. Any processing carried out by Facebook or Instagram after the transfer is not part of this joint responsibility.
The obligations jointly incumbent upon us have been set out in a joint processing agreement. The wording of this agreement can be found at:
https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tools and for implementing these tools on our website in a data protection-compliant manner. Facebook is responsible for the security of Facebook and Instagram products.
You may exercise your data subject rights (e.g. requests for information) regarding data processed by Facebook or Instagram directly with Facebook. If you exercise your rights with us, we are obliged to forward your request to Facebook.
Data transfers to the United States are based on the Standard Contractual Clauses (SCCs) of the European Commission.
Further information can be found at:
https://www.facebook.com/legal/EU_data_transfer_addendum
https://privacycenter.instagram.com/policy/
https://www.facebook.com/help/566994660333381
Further information on Instagram's privacy practices can be found in Instagram's Privacy Policy:
https://privacycenter.instagram.com/policy/
The company is certified under the EU-US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States.
Every company certified under the DPF commits to complying with these data protection standards.
Further information is available at:
https://www.dataprivacyframework.gov/participant/4452
6. Newsletter and MailerLite
If you subscribe to the newsletter offered on this website, the data you provide (in particular your email address) will be processed for the purpose of sending the newsletter.
We use MailerLite as our email marketing service provider. The data you enter is stored on MailerLite's servers and processed exclusively for sending newsletters and analyzing newsletter performance.
The processing of your data is carried out solely on the basis of your consent pursuant to Art. 6 (1) lit. a GDPR.
You may withdraw your consent at any time with future effect by clicking the unsubscribe link included in every newsletter or by contacting us directly.
The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
The data you provide for the purpose of subscribing to the newsletter will be stored until you unsubscribe from the newsletter and will be deleted from the mailing list after you unsubscribe, unless statutory retention obligations require otherwise.
We reserve the right to remove or block email addresses from our mailing list at our own discretion within the scope of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
Data stored by us for other purposes remains unaffected.
After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist by us or by MailerLite if this is necessary to prevent future mailings. The data in the blacklist is used exclusively for this purpose and is not combined with other data.
This serves both your interest and our interest in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 (1) lit. f GDPR).
Storage in the blacklist is not limited in time.
Further information on MailerLite's privacy practices can be found at:
https://www.mailerlite.com/legal/privacy-policy
7. Plugins and Tools
Google Fonts
This website uses Google Fonts, which are provided by Google, to ensure the consistent display of fonts.
When you access a page, your browser loads the required fonts into its browser cache in order to display texts and fonts correctly.
For this purpose, the browser you use must establish a connection to Google's servers. As a result, Google becomes aware that this website has been accessed via your IP address.
The use of Google Fonts is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the consistent presentation of the website's typography.
Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g. device fingerprinting). Consent may be withdrawn at any time.
If your browser does not support Google Fonts, a standard font from your computer will be used instead.
Further information about Google Fonts can be found at:
https://developers.google.com/fonts/faq
Google's Privacy Policy is available at:
https://policies.google.com/privacy
Google is certified under the EU-US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States.
Every company certified under the DPF commits to complying with these data protection standards.
Further information is available at:
https://www.dataprivacyframework.gov/participant/5780
Source: