1. Data Protection at a Glance
General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data that can be used to identify you personally. Detailed information on the subject of data protection can be found in our privacy policy below this text.

Data Collection on This Website
Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Their contact details can be found in the section “Information on the Controller” in this privacy policy.

How do we collect your data?

Your data is collected, for example, when you provide it to us – such as through a contact form.
Other data is automatically collected by our IT systems when you visit the website. These are mainly technical data (e.g., browser, operating system, time of page visit). These data are collected automatically as soon as you enter the site.

What do we use your data for?

Some data are collected to ensure the error-free provision of the website. Other data may be used to analyze user behavior. If contracts are initiated or concluded via the website, transmitted data may also be processed for handling offers, orders, or related inquiries.

What rights do you have regarding your data?

You have the right to receive information free of charge about the origin, recipients, and purpose of your stored personal data at any time. You also have the right to request correction or deletion of this data. If you have given consent to data processing, you can revoke it at any time with future effect. You also have the right to request restriction of processing under certain circumstances and the right to lodge a complaint with a supervisory authority.

You can contact us at any time with questions about data protection.


2. Hosting
Hosting Provider: IONOS

We host our website content with the provider IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (hereinafter “IONOS”). When you visit our website, IONOS collects various log files including your IP address. For more details, see the IONOS privacy policy: https://www.ionos.de/terms-gtc/terms-privacy

Use of IONOS is based on Art. 6(1)(f) GDPR – our legitimate interest in reliable website presentation. If corresponding consent has been requested, processing is based solely on Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device (e.g. device fingerprinting). Consent can be revoked at any time.

Data Processing Agreement

We have entered into a Data Processing Agreement (DPA) with IONOS. This contract ensures that IONOS processes personal data of our website visitors only according to our instructions and in compliance with the GDPR.


3. General Notes and Mandatory Information
Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your data confidentially and in accordance with legal data protection regulations and this privacy policy.

When you use this website, various personal data are collected – data that can identify you personally. This policy explains what data we collect and for what purpose. It also explains how and why we do it.

Please note that data transmission on the Internet (e.g., communication by email) can have security vulnerabilities. Complete protection of the data from access by third parties is not possible.

Controller Information

Automobile Expert GmbH
Rockwool Str. 22
45966 Gladbeck
Phone: +49 2043 78 44 910
Email: info@automobile-expert.com

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

Storage Period

Unless a more specific storage period is mentioned in this privacy policy, your personal data will remain with us until the purpose for processing no longer applies. If you request deletion or revoke consent, we will delete your data unless other legally permitted reasons for retention exist (e.g., tax or commercial law obligations).

Legal Bases for Data Processing

  • Consent: Art. 6(1)(a) GDPR

  • Contractual performance: Art. 6(1)(b) GDPR

  • Legal obligation: Art. 6(1)(c) GDPR

  • Legitimate interest: Art. 6(1)(f) GDPR

  • Special categories of data: Art. 9(2)(a) GDPR

  • Transfers to third countries: Art. 49(1)(a) GDPR

  • Cookies: § 25(1) TDDDG

Recipients of Personal Data

We work with various external service providers in the course of our business. Data may be shared with these providers if legally required, contractually necessary, or based on our legitimate interest. If we use processors, we only share personal data based on valid DPAs. For joint processing, a Joint Controller Agreement is concluded.

Revocation of Your Consent to Data Processing

You may revoke your consent at any time with future effect. This does not affect the lawfulness of processing carried out before the revocation.

Right to Object to Data Processing (Art. 21 GDPR)

If data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object on grounds relating to your particular situation. This also applies to profiling. If you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds that override your interests or the processing is for the establishment, exercise or defense of legal claims (Art. 21(1) GDPR).

If your data is processed for direct marketing purposes, you have the right to object at any time. This also applies to profiling related to such marketing. After your objection, your data will no longer be used for this purpose (Art. 21(2) GDPR).

Right to Lodge a Complaint with a Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work or place of the alleged infringement.

Right to Data Portability

You have the right to receive the data that we process based on your consent or in fulfillment of a contract in a commonly used, machine-readable format. You may also request the transfer of this data to another controller.

Right to Information, Rectification, and Erasure

Under applicable law, you have the right to request free access to your stored personal data, its origin and recipients, the purpose of processing, and the right to correct or delete it.

Right to Restrict Processing

You may request restriction of processing in the following cases:

  • You contest the accuracy of the data – for the duration of verification.

  • The processing is unlawful, and you oppose erasure.

  • We no longer need the data, but you need it for legal claims.

  • You have objected under Art. 21(1) GDPR and the outcome of the balancing of interests is pending.

In such cases, the data will only be processed – apart from storage – with your consent or for the establishment, exercise or defense of legal claims or protection of the rights of another person.

SSL or TLS Encryption

This site uses SSL or TLS encryption to secure the transmission of confidential content (e.g., orders or inquiries). You can recognize an encrypted connection by the “https://” and the padlock symbol in your browser.

4. Data Collection on This Website
Cookies

Our websites use so-called “cookies”. Cookies are small data packets that do not harm your device. They can be stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted after your visit ends. Persistent cookies remain on your device until you delete them manually or they are automatically deleted by your browser.

Cookies can be set by us (first-party cookies) or by third-party companies (third-party cookies). Third-party cookies allow the integration of certain services provided by third parties (e.g., payment services).

Cookies serve various purposes. Many are technically necessary because certain website functions would not work without them (e.g., shopping cart or video display). Other cookies are used to analyze user behavior or for advertising purposes.

Cookies that are required for electronic communication, to provide certain functions (e.g., shopping cart), or to optimize the website (e.g., audience measurement cookies) are stored based on Art. 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies to ensure technically error-free and optimized provision of its services. If consent to the use of cookies and similar technologies was requested, processing is based solely on this consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); consent may be revoked at any time.

You can configure your browser to inform you about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Which cookies and services are used on this website can be found in this privacy policy.

Consent with Borlabs Cookie

Our website uses the Borlabs Cookie consent technology to obtain your consent to store certain cookies in your browser or to use certain technologies and to document them in a data protection-compliant manner. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany.

When you enter our website, a Borlabs cookie is stored in your browser, in which the consents you have given or the revocation of those consents are stored. This data is not passed on to the provider of Borlabs Cookie.

The collected data will be stored until you request deletion, delete the Borlabs cookie yourself, or the purpose for data storage no longer applies. Mandatory legal retention periods remain unaffected. Details on Borlabs Cookie data processing: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

The use of Borlabs Cookie Consent Technology is carried out to obtain the legally required consents for the use of cookies. The legal basis is Art. 6(1)(c) GDPR.

Server Log Files

The provider of these pages automatically collects and stores information in so-called server log files, which your browser transmits to us automatically. These include:

  • Browser type and version

  • Operating system used

  • Referrer URL

  • Hostname of the accessing computer

  • Time of the server request

  • IP address

This data is not combined with other data sources.

The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of their website – for this, server log files must be recorded.

Contact Form

If you send us inquiries via the contact form, your details from the form, including the contact information you provide, will be stored for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.

The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if requested. Consent can be withdrawn at any time.

The data you enter in the contact form will remain with us until you request deletion, revoke your consent, or the purpose for storage no longer applies (e.g., after the processing of your inquiry is completed). Mandatory legal requirements – especially retention periods – remain unaffected.

Inquiry via Email, Phone or Fax

If you contact us by email, phone or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.

The processing of this data is based on Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively handling the inquiries (Art. 6(1)(f) GDPR) or your consent (Art. 6(1)(a) GDPR) if requested. Consent can be withdrawn at any time.

The data you send to us via contact inquiries will remain with us until you request deletion, revoke your consent or the purpose for storage no longer applies. Mandatory statutory provisions – especially legal retention periods – remain unaffected.

Communication via WhatsApp

We use WhatsApp for communication with customers and third parties. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Communication takes place using end-to-end encryption (peer-to-peer), which prevents WhatsApp or third parties from accessing content. However, WhatsApp does collect metadata such as sender, recipient, and timestamp. According to WhatsApp, it may share personal data with its US-based parent company Meta. Details: https://www.whatsapp.com/legal/#privacy-policy

We use WhatsApp based on our legitimate interest in fast and effective communication (Art. 6(1)(f) GDPR). If consent has been requested, processing is based on that consent – revocable at any time.

Messages exchanged on WhatsApp will remain with us until you request deletion, revoke your consent, or the purpose no longer applies. Mandatory retention obligations remain unaffected.

The company is certified under the “EU-US Data Privacy Framework” (DPF). Learn more: https://www.dataprivacyframework.gov/participant/7735

We use the “WhatsApp Business” version.

Data transfer to the USA is based on the EU Commission’s Standard Contractual Clauses. Details: https://www.whatsapp.com/legal/business-data-transfer-addendum


5. Plugins and Tools
Google Fonts (Local Hosting)

This site uses Google Fonts for uniform font representation, provided by Google. The fonts are installed locally – there is no connection to Google servers.

More info on Google Fonts: https://developers.google.com/fonts/faq
Google’s privacy policy: https://policies.google.com/privacy?hl=en

Google Maps

This site uses the Google Maps service. Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to integrate map content into the website.

To use Google Maps, your IP address must be stored. This data is generally transmitted to a Google server in the USA. We have no influence over this transmission. When Google Maps is activated, Google may also use Google Fonts for map rendering. Your browser loads these web fonts to correctly display text and fonts.

Google Maps is used in the interest of a visually appealing presentation and to help users easily find our location. This is a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If consent was requested, processing is carried out on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, provided the consent includes cookie storage or access to information on the user’s device (e.g., device fingerprinting). Consent can be withdrawn at any time.

Data transfer to the USA is based on the EU Commission’s Standard Contractual Clauses:
https://privacy.google.com/businesses/gdprcontrollerterms/
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/

More info on how Google handles user data: https://policies.google.com/privacy?hl=en

Google is certified under the “EU-US Data Privacy Framework” (DPF). More info: https://www.dataprivacyframework.gov/participant/5780


Last updated: 12.12.2024