Privacy Policy & Data Protection Information

The protection of your personal data is important to us.

In the following, we inform you about the processing of your personal data by us, as well as the claims and rights to which you are entitled under data protection regulations, in particular the European General Data Protection Regulation (GDPR).

This data protection information explains the nature, scope, and purpose of the processing of your personal data within our website (hereinafter “website”) and within the framework of the business relationship between us and our customers or cooperation partners. This information applies regardless of the domains, platforms, and devices used (e.g., desktop, mobile, etc.).

When we refer to “data” in the following, we mean your personal data. This refers to all information by which you can be identified, either directly or indirectly, as an individual. Which specific data is processed and how it is used depends largely on the services you utilize.

We use various other terms in our data protection information as defined by the GDPR. These include terms such as processing, restriction of processing, profiling, pseudonymization, controller, processor, recipient, third party, consent, supervisory authority, and international organization. You can find the corresponding definitions for these terms in Art. 4 of the GDPR.

Please read the following information carefully.

Note on the submission of third-party data by you: If you submit personal data regarding your patients, spouses, life partners, relatives, or other third parties, please inform them about the processing of their personal data by us and refer them to this privacy policy. Consent from these individuals for the data transfer may be required.

CONTROLLER

The party responsible for the data processing described herein (the “Controller”) is:

NORSAN GmbH Plauener Str. 163-165, Building E 13053 Berlin, Germany Email: post@norsan.de Phone: +49 (0)30 555 788 990

OUR DATA PROTECTION OFFICER

You can reach our Data Protection Officer at:

mip Consult GmbH Attorney Dietrich Felgner Wilhelm-Kabus-Str. 9 10829 Berlin, Germany Email: [Insert DPO Email Address here] Phone: +49 (0)30 20 88 999 0

WHERE WE OBTAIN YOUR DATA AND WHICH DATA WE USE

Informational Use of the Website If you use our website purely for informational purposes—meaning you do not place an order, register, or otherwise submit information to us—we only collect the personal data that your browser transmits to our server. In this case, we collect the following access data, which is technically necessary for us to display the website and to ensure its stability and security:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page accessed)
  • Access status/HTTP status code
  • Amount of data transferred
  • Referrer URL (the previously visited page)
  • Operating system and its interface
  • Browser type, language, and version of the browser software
  • Notification of successful retrieval

Active Communication and Chat If you start a chat conversation, we also process specific personal data, including: identification and legitimacy information, chat content, assigned user ID, and connection time. Chat inquiries are answered by chatbots or employees, depending on the topic.

Furthermore, we receive your personal data if you contact us by telephone, contact form, or email. Examples of personal data collected in these cases include your name, address, email address, and telephone number.

PURPOSES FOR WHICH WE PROCESS YOUR DATA

We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) for the following purposes and on the following legal bases:

Fulfillment of Pre-contractual and Contractual Obligations (Art. 6(1)(b) GDPR)

  • Contact Inquiries: When you contact us (via contact form, email, login, or your user account), your details are processed to handle and resolve your request.
  • Contract Management: To establish, execute, and manage the contractual relationship or orders placed via our website, including customer service. This includes the documentation of phone calls, chats, emails, and other contact inquiries.
  • Job Applications: If you contact us regarding a job application (specifically via contact form or email), we process your data to assess your suitability for the position (or other open positions within our companies) and to conduct the application process. Suitable applications are forwarded internally to the relevant decision-makers. Access to your data is strictly limited to individuals involved in the proper execution of the application process.

Within the framework of the balancing of interests – legitimate interests (Art. 6 (1) lit. f GDPR):

We process your data to protect the legitimate interests of ourselves or third parties, insofar as this is necessary. In doing so, we pursue the following legitimate interests in particular:

  • Administration of professional circles and seminars (especially online seminars);
  • Publication and management of testimonials (as far as these are provided by our customers);
  • Improvement of the quality of our products and services, testing and optimization of procedures for demand analysis and direct customer communication as well as measures for customer retention and service enhancement;
  • Ensuring IT security and the IT operation of our company, specifically the security of the website (see the data listed above under “Where we obtain your data and which data we use”);
  • Assertion of legal claims and defense in legal disputes; Advertising (including competitions) or conducting customer satisfaction and opinion surveys, provided you have not objected to the use of your data for this purpose – in this context, the cooperation with Trusted Shops SE takes place;

If you have provided us with your email address when purchasing our products or during the provision of services, we reserve the right to regularly send you offers for similar products or services from our range, such as those already purchased, via email, in particular product recommendations. Pursuant to Section 7 (3) of the German Act Against Unfair Competition (UWG), we do not need to obtain separate consent from you for this. Data processing is carried out on the basis of our legitimate interest in personalized direct advertising in accordance with Art. 6 (1) lit. f GDPR in conjunction with Section 7 (3) UWG. If you initially objected to the use of your email address for this purpose, you will not be contacted by email. You have the option to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future, e.g., by clicking on the unsubscribe link at the end of our emails or by notifying us via the contact options mentioned above. You will only incur transmission costs according to the basic rates. In the event of an objection, we will no longer use your email address for the purpose of direct advertising.

Within the framework of a consent granted by you (Art. 6 (1) lit. a GDPR):

For certain processing of personal data (e.g., in the context of newsletter distribution, contact forms, and for the use of certain cookies), we inform you separately and ask you to explicitly consent to such processing (e.g., for advertising or analysis purposes). Please note that you can withdraw this consent at any time with effect for the future. The withdrawal can be sent, in particular, to the contact details mentioned above.

WHO WE SHARE YOUR DATA WITH (RECIPIENTS)

Within our company, those departments that need access to your data to fulfill our contractual and legal obligations will receive access in compliance with applicable data protection laws. Processors employed by us may also receive data for these purposes. These are companies in the categories of customer service, IT services, printing services, telecommunications, advice and consulting, as well as sales and marketing.

Outside of our company, we only pass on information about you to third parties if one of the legal bases mentioned under “For what purposes we process your data” exists, or if you have consented to the transfer of data, or if we are subject to a legal obligation to pass it on. If your request via contact form or email relates to the purchase of a product or service, we share your data with our respective cooperation partners.

When commissioning a NORSAN fatty acid analysis, your data will be passed on to Labor Omegametrix GmbH, Am Klopferspitz 19, D-82152 Martinsried.

When participating in seminars, your data will be passed on for the purpose of conducting online seminars to Zoom Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113; Representative in the EU: Lionheart Squared (Europe) Limited, Attn: Data Privacy, 2 Pembroke House, Upper Pembroke Street 28-32, Dublin, DO2 EK84, Republic of Ireland, email: zoom@LionheartSquared.eu

In the event of a completed order, order information (order totals, order number, if applicable, the product purchased) as well as your email address hashed via a cryptographic one-way function will be transmitted to Trusted Shops SE, Subbelrather Straße 15c, 50823 Cologne (hereinafter “Trusted Shops”). The legal basis for this is Art. 6 (1) lit. f GDPR (see above). This serves to check whether you are already registered for services with Trusted Shops and is therefore necessary for the fulfillment of our and Trusted Shops’ overriding legitimate interests in the provision of the respective rating services linked to the specific order in accordance with Art. 6 (1) lit. f GDPR. If a registration exists, further processing takes place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services, you will subsequently be given the opportunity to do so for the first time. Further processing after registration has taken place is also governed by the contractual agreement with Trusted Shops. If you are not yet registered for the services, you will subsequently be given the opportunity to grant your consent to receive review invitations. If you do not grant this, all transmitted data will be automatically deleted by Trusted Shops and identification will then no longer be possible. Trusted Shops acts here as an independent controller within the meaning of Art. 4, No. 7 GDPR.

In principle, no initial transfer of customer data to therapists takes place. However, it is possible that in individual cases customer data may be exchanged with therapists for the assertion, exercise, or defense of legal claims. Specific health data is not exchanged in this context.

A transfer of customer data to therapists also takes place if this is specifically requested by the customer. In this case, explicit consent from the customer for the transfer of data must be provided.

DATA TRANSFER TO A THIRD COUNTRY OR AN INTERNATIONAL ORGANIZATION

The processing of personal data generally takes place within the European Union (EU). Insofar as data is transferred to so-called third countries, we ensure that the recipients of the data are certified in accordance with the EU-U.S. Data Privacy Framework or that we agree on EU standard data protection clauses with recipients who are not certified. Insofar as we base the data transfer on the EU standard data protection clauses, we will take additional security measures in order to protect your data and to ensure an appropriate level of protection for your personal data. You have the possibility to obtain or view a copy of the EU standard data protection clauses.

Please contact our Data Protection Officer if required.

HOW LONG WE STORE YOUR DATA

Insofar as necessary, we process and store your personal data within the scope of your inquiry via contact form or email. In this respect, we are subject to various retention and documentation obligations depending on the inquiry, which arise, among other things, from the German Commercial Code (HGB), the German Fiscal Code (AO), the German Banking Act (KWG), and the German Money Laundering Act (GwG). The retention and documentation periods specified there are generally ten years.

Finally, the storage period is also determined by statutory limitation periods, which, for example, according to Sections 195 et seq. of the German Civil Code (BGB), are generally three years, but in certain cases can be up to thirty years, whereby the regular limitation period is three years.

For security reasons (e.g., to investigate acts of abuse or fraud), log file information is stored for a maximum period of 30 days and then deleted (see above “Where we obtain your data and which data we use”). Data whose further retention is required for evidentiary purposes is exempted from deletion until the final clarification of the respective incident.

YOUR RIGHTS

With regard to your data and our processing of your data, you have the following rights in particular:

  • the right to access pursuant to Art. 15 GDPR (i.e., you have the right to request information about your personal data stored by us at any time),
  • the right to rectification pursuant to Art. 16 GDPR (i.e., in the event that your personal data is incorrect or incomplete, you can request the correction of this data),
  • the right to erasure pursuant to Art. 17 GDPR and the right to restriction of processing pursuant to Art. 18 GDPR (i.e., you may have the right to request the deletion or restriction of the processing of your personal data if, for example, there is no longer a legitimate business purpose for such processing and statutory retention obligations do not require further storage),
  • the right to data portability under Art. 20 GDPR (i.e., you may have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and to transmit this data to another controller without hindrance).

To exercise these rights, please feel free to contact us directly using the contact details provided above (see above: “Controller”).

Furthermore, you have a right to lodge a complaint with the competent supervisory authority under Article 77 GDPR.

We would appreciate the opportunity to resolve your concerns before you contact the regulatory authority and, therefore, encourage you to reach out to us first with your complaint.

Additionally, we would like to point out your right to object pursuant to Art. 21 GDPR:

Information about your right to object under Art. 21 GDPR

You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) lit. e GDPR (data processing in the public interest) and Art. 6 (1) lit. f GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on these provisions within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims. In individual cases, we process your personal data to conduct direct advertising. You have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling, insofar as it is associated with such direct advertising. If you object to processing for the purposes of direct advertising, we will no longer process your personal data for these purposes. The objection can be made without any formal requirements and should be addressed to: NORSAN GmbH, Plauener Str. 163-165, Building E, 13053 Berlin, post@norsan.de.

AUTOMATED DECISION-MAKING INCLUDING PROFILING

We generally do not use fully automated decision-making as defined in Art. 22 GDPR. Should we use these procedures in individual cases, we will inform you separately, provided this is required by law. We do not process your data automatically with the aim of evaluating certain personal aspects (profiling).

OUR SOCIAL MEDIA PRESENCE

We maintain presences within social networks and platforms so that we can communicate with you there and inform you about our services.

We point out that your data may be processed outside the European Union when using social media networks or platforms and that the providers of social networks generally process the data for market research and advertising purposes. User profiles can be created from the usage behavior and resulting interests of the users. These usage profiles can in turn be used, for example, to place advertisements within and outside the platforms that presumably correspond to the interests of the users. For this purpose, cookies and comparable technologies may be stored on the users’ end devices, in which the usage behavior and interests of the users are stored. Other data may also be stored in these usage profiles, especially if the users are members of the respective platforms and are logged in.

Please note that when you click on a link to social networks, data is transmitted to their servers. If you are logged into the respective social network at this time with your username and password, the information that you have visited our company profile on the respective social network from our website will be transmitted there, and the respective provider can store this information in your user account and use it for its own purposes.

In principle, we have no significant influence on the data processing of social network operators. However, we receive statistics from the providers about the use and visits to our company profiles on social networks (e.g., information about the number of views, interactions such as likes and comments, as well as aggregated demographic and other information or statistics). Further information on the data used by the providers can be found in the privacy policies of the providers linked below.

Insofar as we receive personal data from you via social networks (e.g., in the context of a message) and process it exclusively ourselves, we are the controller for the data processing. In this case, you are entitled to the rights mentioned above in this privacy information. You can send your inquiries regarding data processing within the framework of our company profiles to us using the contact details provided above. Please check carefully which personal data you share with us via social networks.

Insofar as the data transmitted by you via the social network is processed also or exclusively by the provider of the social network (Insights data), the respective provider is also a controller for data processing within the meaning of the GDPR alongside us. The data processing takes place in this respect on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR.

If you wish to assert rights in this regard against the provider of the social network, the easiest way to do this is to contact the respective providers directly. The provider knows both the details of the technical operation of the platform and the associated data processing as well as the specific purposes of the data processing. The contact details can be found in the privacy policies linked below. We are also happy to support you in asserting your rights where possible.

The processing of users’ personal data is generally based on your consent in accordance with Art. 6 (1) lit. a GDPR. The legal basis is also Art. 6 (1) lit. b GDPR if we receive and process your data in the context of a contract-related inquiry via our social media presence. The legal basis for linking and operating our company profiles on social networks, including the receipt of statistics on the use of our company profiles, is Art. 6 (1) lit. f GDPR based on our legitimate interest in our corporate communication on the respective social networks.

For information on the respective processing and the respective opt-out options, we refer to the privacy policies of the providers linked below:

Please note that disabling cookies may lead to functional restrictions of this website.

You can find information about the specific use of the aforementioned technologies and the scope of the information collected in each case within the cookie management tool. You will find this tool at the bottom left of our website (round circular symbol).

OUR SOCIAL MEDIA PRESENCE

You can find us on social networks and platforms, where we maintain a presence to communicate with you and provide information about our services.

We would like to point out that your data may be processed outside the European Union when using social media networks or platforms, and that the providers of these social networks generally process the data for market research and advertising purposes. Usage profiles can be created based on user behavior and the resulting interests of the users. These usage profiles can, in turn, be used, for example, to place advertisements within and outside the platforms that presumably correspond to the interests of the users. For this purpose, cookies and comparable technologies may be stored on the users’ devices to record usage behavior and interests. Other data may also be stored in these usage profiles, especially if users are members of the respective platforms and are logged in.

Please note that when you click a link to a social network, data is transmitted to their servers. If you are logged into the respective social network at that time with your username and password, the information that you have visited our company profile on that social network from our website will be transmitted, and the respective provider can store this information in your user account and use it for its own purposes.

In principle, we have no significant influence on the data processing performed by the operators of social networks. However, we receive statistics from the providers regarding the use and visits to our company profiles on social networks (e.g., information on the number of views, interactions such as likes and comments, as well as aggregated demographic and other information or statistics). Further information on the data used by the providers can be found in the privacy policies of the providers linked below.

Insofar as we receive personal data from you via social networks (e.g., as part of a message) and process it exclusively ourselves, we are the controller for that data processing. In this case, you are entitled to the rights mentioned above in this privacy policy. You may send your inquiries regarding data processing within the scope of our company profiles to us using the contact details provided above. Please carefully consider which personal data you share with us via social networks.

Insofar as the data you transmit via the social network is also or exclusively processed by the provider of the social network (Insights data), the respective provider is also a controller for data processing within the meaning of the GDPR, alongside us. In this regard, data processing is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR.

If you wish to assert your rights against the provider of the social network in this regard, the easiest way to do so is to contact the respective providers directly. The provider is familiar with both the details of the technical operation of the platform and the associated data processing, as well as the specific purposes of the processing. The contact details can be found in the privacy policies linked below. We are also happy to support you in asserting your rights where possible.

The processing of users’ personal data is generally based on your consent in accordance with Art. 6(1)(a) GDPR. The legal basis is also Art. 6(1)(b) GDPR if we receive and process your data in the context of a contract-related inquiry via our social media presence. The legal basis for linking to and operating our company profiles on social networks, including the receipt of statistics on the use of our company profiles, is Art. 6(1)(f) GDPR, based on our legitimate interest in our corporate communication on the respective social networks.

For information on the respective processing and the respective possibilities to object (opt-out), we refer to the following linked privacy information of the providers:

Item added to cart.
0 items - 0,00