Privacy Policy

In this privacy policy you will learn how IntegaDesign GmbH collects, processes and protects personal data in order to comply with the legal requirements of the General Data Protection Regulation (GDPR). We explain the underlying terminology, your rights as a data subject as well as the specific data processing operations of our online services.

1. Definitions

Our privacy policy is based on the terms used by the European legislator for the adoption of directives and regulations (GDPR). Among others, we use the following terms:

  • Personal data: Any information relating to an identified or identifiable natural person.
  • Data subject: Any natural person whose data is processed.
  • Processing: Any operation in connection with personal data (e.g. collection, storage, deletion).
  • Restriction of processing: Marking stored data to limit its future processing.
  • Profiling: Automated processing to evaluate personal aspects.
  • Pseudonymisation: Processing in which data can no longer be attributed without additional information.
  • Controller: The entity that decides on the purposes and means of processing.
  • Processor: Processes data on behalf of the controller.
  • Recipient: Person or entity to which data is disclosed.
  • Third party: Entities other than the data subject or the controller.
  • Consent: A freely given, informed and unambiguous indication of will.

2. Name and address of the controller responsible for processing

The controller within the meaning of the data protection laws is:

Publisher: IntegaDesign GmbH, Managing Director Markus Rufflar
Address: Otto-Hahn-Straße 36, 63303 Dreieich
Tel.: + 49 (0)6103-7329244
E-mail: info@integadesign.de
Website: https://www.integadesign.de

3. Cookies

We use cookies (text files) to make our services user-friendly and to analyse browsing behaviour. This includes the frequency of page views, search terms and the use of functions. The legal basis for analysis cookies is Art. 6 (1) lit. a GDPR. You can prevent or delete the setting of cookies at any time via your browser settings.

4. Collection of general data and information

With every access we collect general data (log files) such as browser type, operating system, IP address and access time. This serves to optimise the content, the functionality of the systems as well as the prosecution of cyberattacks. With your permission we additionally collect names, e-mail addresses and place-of-residence data.

5. SSL encryption

To protect your data we use current encryption methods (e.g. SSL) via HTTPS.

6. Subscription to our newsletter

You can subscribe to our newsletter by providing your e-mail address via the input mask. We use the double opt-in procedure for confirmation. A revocation is possible at any time via the link in the newsletter or by notification.

7. Newsletter tracking

Our newsletters contain tracking pixels for statistical evaluation (open rates, clicks). This data is evaluated anonymously and not passed on to third parties.

8. Registration on our website

During registration, personal data is collected for internal use. The IP address as well as time stamps are stored to prevent misuse.

9. Contact option via the website

Enquiries via e-mail or contact form are automatically stored for processing and not passed on to third parties without consent.

10. Comment function in the blog

In our blog, the time of entry, your user name (pseudonym) and the IP address are stored when comments are made.

11. Subscription to comments in the blog

Third parties can subscribe to comments. Here too we use the double opt-in procedure to verify the e-mail address.

12. Routine deletion and blocking of personal data

We store data only as long as the purpose requires or statutory retention periods prescribe.

13. Rights of the data subject

You have the following rights vis-à-vis the controller:

  • Right to confirmation and information about processed data.
  • Right to rectification of incorrect data.
  • Right to erasure ("to be forgotten").
  • Right to restriction of processing.
  • Right to data portability in a machine-readable format.
  • Right to object to processing (Art. 21 GDPR).
  • Revocation of data protection consents.

14. Data protection for applications

We process applicant data to handle the application procedure. In the case of rejections, the documents are automatically deleted after two months, provided no obligation to provide evidence (e.g. AGG) precludes this.

15. Use of Google Analytics

We use Google Analytics with IP anonymisation. You can prevent the collection via the browser add-on or an opt-out link.

16. Use of libraries (web fonts)

We use Google Web Fonts for the correct display of fonts. In doing so, a connection to Google servers is established.

17. Use of Adobe Typekit

For visual design we use Adobe Typekit. In this process your IP address is transmitted to Adobe.

18. Social media plug-ins

We use plugins from LinkedIn and YouTube. For protection we use a 2-click solution; data is only transmitted after activation.

19. Payment methods

  • PayPal: Data transmission for payment processing and fraud prevention.
  • Klarna: Transmission for purchase on invoice and credit check.
  • Sofortüberweisung: Cashless payment with PIN/TAN procedure.

20. Google Ads

We use conversion tracking to analyse advertising efficiency. Cookies expire after 30 days.

21. Google Remarketing

Serves the display of interest-based advertising within the Google advertising network.

22. HubSpot

We use HubSpot for marketing automation and download services. Data is stored on HubSpot servers.

23. LinkedIn Insight Tag

Enables personalised advertising and statistical evaluation of website interaction on LinkedIn.

24. Legal basis of processing

Processing takes place primarily on the basis of Art. 6 I GDPR (consent, performance of a contract, legal obligation or legitimate interest).

25. Legitimate interests

Our interest lies in conducting our business activity for the benefit of our employees and shareholders.

26. Storage period

The criterion is the respective statutory retention period.

27. Provision requirements

In some cases the provision is required by law (tax law) or by contract. A failure to provide can prevent the conclusion of a contract.

28. Amendment of the data protection provisions

We adapt this policy in the event of new services or legal changes.

29. Automated decision-making

We refrain from profiling and automated decision-making.

30. Use of the software "SuCri"

When using SuCri, your IP address is collected via Cryptolens for license validation (Art. 6 (1) lit. f GDPR).