Who we are

Our website address is: https://kiutra.com.

Privacy Policy

Personal data (usually referred to just as “data” below) will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.

Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the “GDPR”), “processing” refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.

The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under our own control or in conjunction with others. We also inform you below about the third-party components we use to optimize our website and improve the user experience which may result in said third parties also processing data they collect and control.

Our privacy policy is structured as follows:

I. Information about us as controllers of your data
II. The rights of users and data subjects
III. Information about the data processing

I. Information about us as controllers of your data

The party responsible for this website (the “controller”) for purposes of data protection law is:

kiutra GmbH
Flößergasse 2
81369 Munich
Germany

Telephone: +49 89 356479770
Fax: +49 89 99950573
Email: info(at)kiutra.com

The controller’s data protection officer is:

Dr. Alexander Regnat

II. The rights of users and data subjects

With regard to the data processing to be described in more detail below, users and data subjects have the right

  • to confirmation of whether data concerning them is being processed, information about the data being processed, further information about the nature of the data processing, and copies of the data (cf. also Art. 15 GDPR);
  • to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
  • to the immediate deletion of data concerning them (cf. also Art. 17 DSGVO), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict said processing per Art. 18 GDPR;
  • to receive copies of the data concerning them and/or provided by them and to have the same transmitted to other providers/controllers (cf. also Art. 20 GDPR);
  • to file complaints with the supervisory authority if they believe that data concerning them is being processed by the controller in breach of data protection provisions (see also Art. 77 GDPR).

In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.

Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller’s future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.

III. Information about the data processing

Your data processed when using our website will be deleted or blocked as soon as the purpose for its storage ceases to apply, provided the deletion of the same is not in breach of any statutory storage obligations or unless otherwise stipulated below.

Server data

For technical reasons, the following data sent by your internet browser to us or to our server provider will be collected, especially to ensure a secure and stable website:

These server log files record the type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on our site visited, the date and time of your visit, as well as the IP address from which you visited our site.

The data thus collected will be temporarily stored, but not in association with any other of your data.

The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.

The data will be deleted within no more than seven days, unless continued storage is required for evidentiary purposes. In which case, all or part of the data will be excluded from deletion until the investigation of the relevant incident is finally resolved.

Order processing

The data you submit when ordering goods and/or services from us will have to be processed in order to fulfill your order. Please note that orders cannot be processed without providing this data.

The legal basis for this processing is Art. 6 Para. 1 lit. b) GDPR.

In order to process your order, we will share your data with the shipping company responsible for delivery to the extent required to deliver your order and/or with the payment service provider to the extent required to process your payment.

The legal basis for the transfer of this data is Art. 6 Para. 1 lit. b) GDPR.

Contact

If you contact us via email or the contact form, the data you provide will be used for the purpose of processing your request. We must have this data in order to process and answer your inquiry; otherwise we will not be able to answer it in full or at all.

The legal basis for this data processing is Art. 6 Para. 1 lit. b) GDPR.

Online job applications / publication of job advertisements

We offer you the opportunity to apply for jobs with our company via our website. For this purpose, we use the recruiting platform Personio, operated by Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany. When you click on a job ad, you will be redirected to our application page hosted on Personio’s servers.

Your application data will be collected and processed electronically via Personio in order to manage the application process. We remain the data controller; Personio acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. For more information on how Personio handles data, please refer to their privacy policy.

The legal basis for this processing is §26 Para. 1 Sentence 1 BDSG in conjunction with Art. 88 Para. 1 GDPR.

If you are hired as a result of the application process, we will store the data you provide during the application process in your personnel file for the purpose of the usual organizational and administrative procedures, in compliance with applicable legal obligations.

The legal basis for this processing is §26 Para. 1 Sentence 1 BDSG in conjunction with Art. 88 Para. 1 GDPR.

If we do not hire you, we will automatically delete the data submitted to us two months after the final decision has been made. We will not delete the data, however, if we must retain it for legal reasons (e.g. evidence of equal treatment of applicants), in which case it will be stored for up to four months or until any legal claims are resolved.

The legal basis in this case is Art. 6 Para. 1 lit. f GDPR and §24 Para. 1 No. 2 BDSG. Our legitimate interest lies in defending against possible legal claims.

If you expressly consent to longer storage of your data (e.g. inclusion in a pool of applicants or interested parties), we will store your data accordingly. The legal basis is then Art. 6 Para. 1 lit. a GDPR. You can withdraw your consent at any time with future effect pursuant to Art. 7 Para. 3 GDPR.

Embedded calculators

On some pages of our website, we use interactive calculators powered by Calculator Studio, a service provided by GRID ehf., Reykjavík, Iceland. These calculators are embedded using an iFrame but run on GRID’s infrastructure.

The calculators may include a contact form. If you submit a form, your personal data (e.g. name, email address, and enquiry) is transmitted directly to us and used solely to process your request (e.g. for a quote). GRID does not process or store this personal data.

We embed these tools to support our users in generating accurate requests and to simplify the quotation process (Art. 6(1)(b) and (f) GDPR). For more information on GRID’s service infrastructure, see their privacy-policy.

LinkedIn

We maintain an online presence on LinkedIn to present our company and our services and to communicate with customers/prospects. LinkedIn is a service of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

We would like to point out that this might cause user data to be processed outside the European Union, particularly in the United States. This may increase risks for users that, for example, may make subsequent access to the user data more difficult. We also do not have access to this user data. Access is only available to LinkedIn. LinkedIn Corporation is certified under the Privacy Shield and committed to comply with European privacy standards.

The LinkedIn privacy policy can be found here.

Newsletter

We use rapidmail to send our newsletter. When you subscribe, you consent to the entered data being forwarded to rapidmail.

The rapidmail privacy policy can be found here.

Matomo

We use Matomo on our website.

The Matomo privacy policy can be found here.

The Matomo service is used to analyze how our website is used. The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our site.

Matomo is an open source web analytics platform. A web analytics platform is used by a website owner in order to measure, collect, analyze and report visitors’ data for purposes of understanding and optimizing their website.

Matomo is used to analyze the behavior of the website visitors to identify potential pitfalls; not found pages, search engine indexing issues, which contents are the most appreciated. Once the data is processed (such as number of visitors reaching a not found page, viewing only one page), Matomo generates reports for website owners to take action, for example changing the layout of the pages, publishing new content etc.

Matomo processes the following personal data:

  • IP address
  • Location of the user

And also:

  • Date and time
  • Title of the page being viewed
  • URL of the page being viewed
  • URL of the page that was viewed prior to the current page
  • Screen resolution
  • Time in local timezone
  • Files that were clicked and downloaded
  • Pages generation time
  • Country, region, city
  • Main Language of the browser
  • Session recording, mouse events (movements, content forms and clicks)
  • Form interactions
  • Media interactions
  • A/B Tests

The personal data received through Matomo are sent to:
kiutra GmbH
Our service provider: STRATO AG
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

We are keeping the personal data captured within Matomo for a period of 24 months.

As Matomo is processing personal data on legitimate interests, you can exercise the following rights:

  • Right of access: you can ask us at any time to access your personal data.
  • Right to erasure: you can ask us at any time to delete all the personal data we are processing about you.
  • Right to object: you can object to the tracking of your personal data by contacting us info(at).kiutra.com.

Matomo does not engage in any profiling.

If you believe that the way we process your personal data with Matomo Analytics is infringing the law, you have the right to lodge a complaint with a supervisory authority. The relevant supervisory authority for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Germany
lda.bayern.de

Google Fonts

Our website uses Google Fonts to display external fonts. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland (hereinafter: Google).

Through certification according to the EU-US Privacy Shield Google guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

To enable the display of certain fonts on our website, a connection to the Google server in the USA is established whenever our website is accessed.

The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the optimization and economic operation of our site.

When you access our site, a connection to Google is established from which Google can identify the site from which your request has been sent and to which IP address the fonts are being transmitted for display.

Google offers detailed information at adssettings.google.com/authenticated and policies.google.com/privacy in particular on options for preventing the use of data.

Model Data Protection Statement for Anwaltskanzlei Weiß & Partner