Who we are
Our website address is: https://www.finfoot.de
This Website is operated by Finfoot Consulting GmbH (hereafter in this text often abbreviated as Finfoot or “we”) as described in our imprint. We place high priority on the protection of your personal data and treat your privacy in compliance with the General Data Protection Regulation (GDPR) of the European Union and the applicable national legislation on personal data protection.
Terminology used in this privacy policy
Our personal data processing activities are governed by the General Data Protection Regulation (Regulation (EU) 2016/679).
‘Personal data’ is any information that can be used to identify you, including your name, e-mail address, IP address, or any other data that could reveal your physical, physiological, generic, mental, economic, cultural or social identity.
For the purpose of the GDPRs, we are the ‘Data Controller’ of all personal data obtained by us as set out in this Policy, because we ultimately determine how your personal data will be handled by us or our sub-contractors, who would be our ‘Data Processors’.
If we handle your personal data then you are a ‘Data Subject’. This means you have certain rights under the GDPR in relation to how your personal data is processed, which are set out in this privacy policy.
Name and address of the data controller
The responsible controller of your personal data is:
Finfoot Consulting GmbH
Rosa-Bavarese-Str. 3
D – 80639 Munich, Germany
Email: info@finfoot.de
Internet: www.finfoot.de
For further information on the controller please refer to the imprint of this website.
Personal data on this website
It is possible for you to use this website without providing your personal data. Whenever we collect personal data you will be asked for consent, and you will be again informed about your rights in terms of protection of your personal data. We will only process your personal data in accordance with notices set out in this Policy, or as provided to you at the time we collect your personal data (if necessary for the intended processing).
Elements of this website which involve collecting of personal data from you are: (a) an email contact to our staff or (b) our contact form. You can find more details on these web forms and how we process the personal data collected below under the respective section headers.
a) Email contact
The user of this website can use the general company email address or the other email addresses presented to get in contact with the respective staff. In this case we will store the personal data transmitted by this email. The data are used exclusively for processing the conversation with you (purpose) and are not transmitted to any third party.
b) Contact form
Our website contains a contact form for your direct electronic communication with us. If you contact us by this form we store the information that you entered, i.e. your name, email address and your message text. The purpose is to respond to your message, to process your request and to reply to you. There is no transfer of this personal data to any third party.
Legal basis for data processing
The legal basis for the processing of data is Art. 6 para. 1 lit. a GDPR in case the user has given his consent to the processing.
The legal basis for the processing of personal data in the course of sending an email is Art. 6 para. 1 lit. f GDPR. If the e-mail contact aims at the conclusion of a contract, then additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.
Rights of the data subject in terms of data protection
You have the following rights in relation to your personal data:
- Right to confirmation – you can ask us to confirm whether we are processing personal data concerning you.
- The right to be informed – this is information on the personal data we are processing and the purpose for which we are processing them.
- The right of access – you have the right to be provided with copies of your personal data that we are processing.
- The right to rectification – if you think the personal data that we hold on you is inaccurate or incomplete, you can request us to correct this.
- The right to erasure – if you want us to delete the personal data we are holding for you, then you can request us to do so.
- The right to restrict processing – if you oppose the way how we are processing your personal data, then you have the right to inform us accordingly, and we will restrict the processing on the basis of your right.
- The right to data portability – if you want us to forward your personal data to a different organisation or person, then you have the right to inform us, and we will transfer your personal data respectively (without adversely affecting the rights of others).
- The right to withdraw your consent – you can withdraw your previously given consent to the processing of your personal data at any time by contacting us using the contact form provided.
If you want to exercise one or more of these rights, please contact one of our staff or use the general contact form provided on this website. You can request your rights free of charge unless your request is clearly unfounded, repetitive or excessive. Alternatively, in these circumstances, we may refuse to comply with your request. In accordance with the GDPR, we will try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex, or you have made a number of requests. In this case, we will notify you and keep you updated.
In addition to the above rights, as a data subject, you have the right to lodge a complaint with your local data protection authority within the European Union. Please note that you can use whichever local data protection authority within the EEA that is most convenient for you.
Transfer of personal data
We are not transmitting any personal data collected from you through emails, or the contact form of this website to any other third party on a regular basis, in particular not to third parties established outside the European Union or outside the European Economic Area (EEA). If you contact our staff during their potential business trips outside the EU, the staff is receiving your email through a secure connection, so that your data is not transmitted to a third party, but remains within the sphere of influence of our company.
If we are forwarding or copying a message that we have received by email or our contact form to persons outside our company, we will first ask you for your consent to do so, unless you have informed us explicitly about your consent already when you were writing your email to us.
Deleting personal data
We delete your personal data on a regular basis in accordance with the requirements of the GDPR.
After you have contacted us through email or by the contact form of our website, we are deleting your personal data as soon as the relevant communication with you is concluded, unless (i) you have provided us with separate consent to store your personal data longer, (ii) we still need your personal data to fulfil a contractual obligation, or (iii) statutory retention obligations require us to retain your personal data for a longer period.
Changes to this Policy
As and when necessary, changes to this privacy policy will be published on our website. Where changes are significant, we may also email you and where required by law, we will obtain your consent to these changes.