We ("we", "us", "our/s") take the privacy of users ("users" or "you") of our website and/or mobile app (the "Website" and the "Mobile App" respectively) very seriously and are committed to protecting the information users provide to us in connection with their use of our Website and/or Mobile App (together: "Digital Assets"). Further, we are committed to protecting and using your information in accordance with applicable law.
How we collect data
What data we collect
Why we collect this data
Who we share the data with
Where the data is stored
How long the data is kept
How we protect the data
How we treat minors
What data do we collect?
Below is an overview of the data we may collect:
Non-identified and non-identifiable information that you provide during the registration process or that is collected through the use of our services ("non-personal data"). Non-Personal Information does not identify who it was collected from. Non-Personal Information that we collect consists primarily of technical and aggregate usage information.
Individually identifiable information, which is any information that can be used to identify you or could be used to identify you with reasonable effort ("personal data"). Personally identifiable information we collect through our Services may include information requested from time to time, such as names, email addresses, addresses, phone numbers, IP addresses and more. When we combine personal data with non-personal data, as long as it is in combination, we will treat it as personal data.
How do we collect data?
Below are the main methods we use to collect data:
We collect data when you use our services. So when you visit our digital assets and use services, we may collect, record and store usage, sessions and related information.
We collect data that you provide to us yourself, for example, when you contact us directly through a communication channel (such as an email with a comment or feedback).
We may collect data from third party sources as described below.
We collect data that you provide to us when you sign up to our services through a third party provider such as Facebook or Google.
Why do we collect this data?
We may use your data for the following purposes:
to provide and operate our services;
to develop, customise and improve our services;
to respond to your feedback, enquiries and requests and to provide assistance;
to analyse request and usage patterns;
for other internal, statistical and research purposes;
to improve our data security and fraud prevention capabilities;
to investigate violations and enforce our terms and policies and to comply with applicable law, regulation or governmental request;
to provide you with updates, news, promotional materials and other information related to our services. For promotional emails, you can decide whether you want to continue receiving them. If not, simply click on the unsubscribe link in these emails.
Who do we share this data with?
We may share your information with our service providers to operate our services (e.g. storing data via third party hosting services, providing technical support, etc.).
We may also disclose your information in the following circumstances: (i) to investigate, detect, prevent or take action regarding illegal activities or other misconduct; (ii) to establish or exercise our rights of defence; (iii) to protect our rights, property or personal safety, or the safety of our users or the public; (iv) in the event of a change of control of us or any of our affiliates (by way of merger, acquisition or purchase of (substantially) all of the assets, etc.); (v) to protect our rights, property or personal safety, or the safety of our users or the public. (v) to collect, maintain and/or manage your information through authorised third party service providers (e.g. cloud service providers) as appropriate for business purposes; (vi) to work with third party service providers to improve your user experience. For the avoidance of doubt, we may transfer or disclose non-personal data to third parties or use it in any other way at our discretion.
Category: User has a blog or forum
Please note that our services allow for social interactions (e.g. posting content, information and comments publicly and chatting with other users). Please be aware that any content or data you provide in these areas may be read, collected and used by others. We discourage posting or sharing information that you do not wish to make public. If you upload content to our digital assets or otherwise make it available as part of using a service, you do so at your own risk. We cannot control the actions of other users or members of the public with access to your data or content. You acknowledge and hereby confirm that copies of your data may remain retrievable even after it has been deleted from cached and archived pages or after a third party has made a copy/stored your content.
Cookies and similar technologies
When you visit or access our Services, we authorise third parties to use web beacons, cookies, pixel tags, scripts and other technologies and analytics services ("Tracking Technologies"). These Tracking Technologies may allow third parties to automatically collect your information to improve the navigation experience on our digital assets, optimise their performance and provide a tailored user experience, as well as for security and fraud prevention purposes.
Category: The user is NOT connected to an advertising service.
We will not share your email address or other personal information with advertisers or ad networks without your consent.
Category: The user is connected to an advertising service, Campaign Manager or Facebook Ads.
We may provide advertising through our Services and our digital assets (including websites and applications that use our Services) that may also be tailored to you, such as ads based on your recent website, device or browser browsing behaviour.
Where do we store the data?
Category: User Collected Personal Data
Personal data may be maintained, processed and stored in the United States, Ireland, South Korea, Taiwan, Israel and to the extent necessary for the proper provision of our services and/or required by law (as further explained below) in other jurisdictions.
How long is the data retained?
Please note that we will retain the data we collect for as long as is necessary to provide our services, to comply with our legal and contractual obligations to you, to resolve disputes and to enforce our agreements.
We may correct, amend or delete inaccurate or incomplete data at any time at our sole discretion.
How do we protect the data?
The hosting service for our digital assets provides us with the online platform through which we can offer our services to you. Your data may be stored via our hosting provider's data storage, databases and general applications. It stores your data on secure servers behind a firewall and it provides secure HTTPS access to most areas of its services.
Category: User Accepts Payments/eCom
All payment options offered by us and our hosting provider for our digital assets adhere to the PCI Security Standards Council's PCI-DSS (Payment Card Industry Data Security Standard) regulations. This is the collaboration of brands such as Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card data (including physical, electronic and procedural measures) by our shop and service providers.
Notwithstanding the measures and efforts taken by us and our hosting provider, we cannot and do not guarantee absolute protection and security of the data you upload, post or otherwise share with us or others.
For this reason, we ask that you establish strong passwords and, where possible, do not provide us or others with confidential information that you believe could cause you significant or lasting harm if disclosed. In addition, as email and instant messaging are not considered secure forms of communication, we ask that you do not disclose confidential information through either of these communication channels.
How do we deal with minors?
Category: User does NOT collect data from minors.
The Services are not intended for users who are under the legal age of majority. We will not knowingly collect data from children. If you are under the legal age of majority, you should not download or use the Services or provide any information to us.
We reserve the right to request proof of age at any time so that we can verify whether minors are using our Services. In the event that we become aware that a minor is using our Services, we may prohibit such users from accessing our Services and block them, and we may delete any information we hold about that user. If you have reason to believe that a minor has disclosed data to us, please contact us as explained below.
Category: User collects data from minors
Children can use our services. However, if they wish to access certain features, they may be required to provide certain information. The collection of some data (including data collected through cookies, web beacons and other similar technologies) may be automatic. If we knowingly collect, use or disclose information collected from a child, we will indicate this in accordance with applicable law and obtain parental consent. We do not condition a child's participation in an online activity on the child providing more contact information than is reasonably necessary to participate in that activity. We will only use the information we collect in connection with the services the child has requested.
We may also use a parent's contact information to communicate about the child's activities in the Services. Parents may review data we have collected from their child, prohibit us from collecting further data from their child, and request that any data we have collected be deleted from our records.
Please contact us to view, update or delete your child's information. For your child's protection, we may ask you to provide proof of your identity. We may deny you access to the data if we believe your identity is questionable. Please note that certain data cannot be deleted due to other legal obligations.
the use of your personal data is necessary to perform or enter into a contract (for example, to provide you with the Services themselves or customer care or technical support);
the use of your personal data is necessary to comply with relevant legal or regulatory obligations; or
the use of your personal data is necessary to support our legitimate business interests (provided that at all times this is done in a way that is proportionate and respects your data protection rights).
As an EU resident, you can:
Request confirmation as to whether or not personal data relating to you is being processed and request access to your stored personal data and certain additional information;
obtain the personal data you have provided to us in a structured, commonly used and machine-readable format;
request the correction of your personal data that we have stored;
request the deletion of your personal data
object to the processing of your personal data by us;
request the restriction of the processing of your personal data, or
lodge a complaint with a supervisory authority.
However, please note that these rights are not unlimited and may be subject to our own legitimate interests and regulatory requirements. If you have any general questions about the personal data we collect and how we use it, please contact us as set out below.
In the course of providing the Services, we may transfer data across borders to affiliates or other third parties and from your country/jurisdiction to other countries/jurisdictions around the world. By using the Services, you consent to the transfer of your data outside the EEA.
If you are located in the EEA, your personal data will only be transferred to locations outside the EEA if we are satisfied that there is an adequate or comparable level of protection for personal data. We will take appropriate steps to ensure that we have adequate contractual arrangements in place with our third parties to ensure that appropriate safeguards are in place so that the risk of unlawful use, alteration, deletion, loss or theft of your personal data is minimised and that these third parties act at all times in accordance with applicable laws.
Rights under the California Consumer Privacy Act
If you are a California resident using the Services, then you may be entitled under the California Consumer Privacy Act ("CCPA") to request access to and deletion of your information.
To exercise your right to access and delete your information, please see below for how to contact us.
Category: The website does not sell its users' data
We do not sell users' personal information for the purposes and intent of the CCPA.
Category: Websites with a blog or forum
Users of the Services who are California residents and under the age of 18 may request and obtain removal of their posted content by emailing us at the address provided in the "Contact Us" section below. These requests must all be marked "California Removal Request". All requests must include a description of the content you wish to have removed and sufficient information to help us locate the material. We will not accept notices that are not marked or properly submitted, and we may not be able to respond if you do not provide sufficient information. Please note that your request does not ensure that the material will be fully or completely deleted. For example, material posted by you may be republished or re-posted by other users or third parties.
If you have any general questions about the Services or the information we collect about you and how we use it, please contact us at:
Name: surfinseason UG (CEO: Florian Lohmann).
Address: Sommerstr. 15; 81543 Munich; Germany
E-mail address: email@example.com