PRIVACY POLICY
I take the protection of your personal data on my website very seriously. In this privacy policy I explain how I collect, store and protect data. By using my services, you agree to this policy. I therefore recommend that you read the privacy policy carefully before using my services.
​
​
​
​
1. name and contact details of the data controller and the company data protection officer
​
This data protection information applies to data processing by
Zaranoya GmbH
Zähringerstrasse 9
Schweiz
8001 Zürich
​
2. collection and storage of personal data and the nature and purpose of their use
a) When visting my website
When you visit my website, I automatically collect and store information such as IP address, date, time, files accessed and browser data. This data is used to ensure a secure connection, to optimize the use and security of the website. In accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, this is the legal basis for data processing. I do not use this data to draw conclusions about your person. Personal data such as names, email addresses and IP addresses may be collected by me and will be treated in accordance with the data protection regulations. I also use cookies and analysis services on my website. Unless a specific retention period has been specified in this privacy policy, your personal data will be stored by me until the purpose of the data processing no longer applies. You have the right to have your data deleted, provided there are no legal reasons for its retention.
b) When using our contact form
For questions of any kind, I offer the option of contacting me via a form provided on the website. You will need to provide your name, a valid email address and a message so that I know who sent the request and can answer it.
The data processing for the purpose of contacting me is carried out in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR.
c) Storage duration
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with me until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless I have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion will take place after these reasons no longer apply.
​
d) Deletion
The data processed by me will be deleted in accordance with Art. 17 GDPR or its processing restricted in accordance with Art. 18 GDPR.
Unless otherwise stipulated in this privacy policy, the data processed by me will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention obligations. I review the necessity every six months. If the data is not deleted because it is required for other, legally permissible purposes, its processing will be restricted. This means that the data is blocked and not used. This applies, for example, to data that must be retained for commercial or tax law reasons.
3. disclosure of data
I will only pass on your personal data if you expressly consent (Art. 6 para. 1 sentence 1 lit. a GDPR), if this is necessary to assert legal claims, if there are legal obligations or if it is necessary to process contractual relationships.
Your data may also be passed on to service providers for the operation of my services. Under certain circumstances, I may disclose your data, for example to investigate unlawful activities, to defend my rights or for the safety of users and the public.
​
4. hosting
I host the content of my website with the following provider: Wix.com Ltd, 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel (hereinafter “WIX”).
WIX is a tool for creating and hosting websites. When you visit my website, WIX is used to analyze user behavior, visitor sources, the region of website visitors and visitor numbers. WIX stores cookies on your browser that are required to display the website and to ensure security (necessary cookies).
The data collected by WIX may be stored on various servers worldwide. The WIX servers are located in the USA, among other places.
Details can be found in the WIX privacy policy: https://de.wix.com/about/privacy
According to WIX, data transfer to the USA and other third countries is based on the standard contractual clauses of the EU Commission or comparable guarantees in accordance with Art. 46 GDPR. You can find details here: https://de.wix.com/about/privacy-dpa-users
The use of WIX is based on Art. 6 para. 1 lit. f GDPR. I have a legitimate interest in the most reliable presentation of my website. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. A GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time. The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:
​
5. cookies
I use cookies on my website. These are small files that your browser automatically creates and that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit my website. Cookies do not cause any damage to your end device and do not contain any viruses, Trojans or other malware.
Information is stored in the cookie that results in each case in connection with the specific end device used. However, this does not mean that I gain direct knowledge of your identity.
On the one hand, the use of cookies serves to make the use of my website more pleasant for you. For example, I use so-called session cookies to recognize that you have already visited individual pages of my website.
In addition, I also use temporary cookies to optimize user-friendliness, which are stored on your device for a specified period of time. If you visit my site again to use my services, it will automatically recognize that you have already visited my site and which entries and settings you have made so that you do not have to enter them again.
On the other hand, I use cookies to statistically record the use of my website and to evaluate it for the purpose of optimizing my offer for you. These cookies enable me to automatically recognize when you visit our site again that you have already visited us. These cookies are automatically deleted after a defined period of time.
The data processed by cookies is required for the purposes mentioned to protect our legitimate interests and the interests of third parties in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer, or a message always appears before a new cookie is created. However, completely deactivating cookies may mean that you cannot use all the functions of my website to their full extent.
Your browser allows you to prevent the use of cookies completely or in individual cases. Please refer to the operating instructions for your browser for more information. You can also delete cookies; I have compiled some instructions on how to do this here:
for Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de
for Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
for Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen
for Edge: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
6. disclosure of the data
Forwarding to third parties
I don't like spam any more than you do. I will therefore not pass on your data to third parties unless this is permitted by law. Your data may be passed on either
- necessary for the fulfillment of a contract and then be permitted under Art. 6 para. 1 lit. b GDPR or
- be permitted based on our legitimate interest in effective service design pursuant to Art. 6 para. 1 lit. f GDPR,
- be covered by your consent or
- become necessary if I am lawfully required by a state or authority to disclose your data in accordance with Art. 6 para. 1 lit. c GDPR.
If your data is passed on to third parties, this is listed in this privacy policy.
Transfer abroad, in particular to the USA
My website uses external providers based outside the EU for various functions. In particular, cookies, active Java scripts and other technologies may result in your data being processed and stored outside the EU. However, I will not transfer your data to a third country unless the EU Commission has established a level of data protection comparable to that in the EU or I have agreed the standard contractual clauses with the provider to protect your data.
Note on data transfer to the USA and other third countries​​
Among other things, I use tools from companies based in the USA or other third countries that are not secure under data protection law. If these tools are active, your personal data may be transferred to these third countries and processed there. I would like to point out that no level of data protection comparable to that in the EU can be guaranteed in these countries. For example, US companies are obliged to hand over personal data to security authorities without you as the data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. secret services) may process, evaluate and permanently store your data on US servers for surveillance purposes. I have no influence on these processing activities.
7. Google Analytics
I use Google Analytics from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 to compile usage statistics
The following data is stored when you visit my website:
-
IP address
-
Date and time of the request
-
Content of the request (specific page)
-
Access status/HTTP status code
-
Amount of data transferred in each case
-
Website from which the request originates
-
browser
-
Information about your end device
-
Operating system and its interface
-
Language and version of the browser software
-
Screen and window resolution
-
Location, if applicable
-
Information about your length of stay
-
Information about your actions on the website
The processing of your personal data enables me to analyze your interaction behavior with my website. This enables me to constantly improve my website and its user-friendliness.
Your data will only be processed with your express consent in accordance with Art. 6 para. 1 lit. a GDPR.
When using Google Analytics, your data will also be transmitted to the USA. Google LLC is certified in accordance with the EU-US Data Privacy Framework, so that the EU Commission's adequacy decision of 2023 applies to the transfer and processing. In addition, Google LLC has agreed the Standard Contractual Clauses (SCC) in its data processing agreement.
The data is deleted as soon as it is no longer required for analysis purposes. We review the necessity every 6 months.
The relationship with the web analytics provider Google Analytics is based on an adequacy decision by the European Commission and a data processing agreement (data processing agreement/addendum) has been concluded.
8. social media links
In addition to my website, I am active on social media platforms. When you visit our social media presences, certain information about you is processed. If you are logged into your own user account when you visit my presence on this social network, the data collected will be assigned directly to your existing account.
It is possible that your personal data will be collected even if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.
Social networks store the data collected about you as usage profiles and can use these for the purposes of analysis, advertising and market research.
When you visit my social media presence, I process data about your actions and interactions with my social media presence and your publicly visible profile data (e.g. your name and profile picture). Which personal data from your profile is publicly visible depends on the settings you have made in your social media account.
The purpose of our data processing on my social media presences is to inform customers about offers, products and company news, as well as to interact with visitors to the social media presences, answer questions, etc. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. The data processing is carried out in the interest of my public relations and communication.
Facebook/Instagram
My website uses links to my presence on the Facebook social network of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. It is just a normal link, so when you visit our site, Facebook does not find out about your visit to my website. However, if you click on the link, you will be redirected to Facebook, which will also inform Facebook that you have visited my site.
Your data will be transmitted by Facebook Ireland to Facebook in the USA based on the standard contractual clauses.
I have no knowledge of and no influence on the possible collection and use of your data by Facebook after clicking on the link. For more information, please refer to Facebook's privacy policy at https://www.facebook.com/privacy/policy/.
9. right of appeal to the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in the Member State of your habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
​
​
10. information, correction and deletion
You have the right to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if necessary, a right to correction or deletion of this data at any time within the framework of the applicable legal provisions. You can contact me at any time if you have further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact me at any time to do this. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by me, I usually need time to check this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of erasure.
If you no longer need your personal data, but you need it for the exercise, defense or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
If you have lodged an objection in accordance with Art. 21 para. 1 GDPR, a balance must be struck between your interests and mine. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
​
11. security
SSL and TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to me as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to me cannot be read by third parties.
​
​
12. Google Fonts
​
​
This site uses so-called web fonts for the uniform display of fonts, which are provided by Google, based in: Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland. When you access a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly. For this purpose, the browser you are using must connect to Google's servers. This gives Google knowledge that my website has been accessed via your IP address. The use of Google Fonts is in the interest of a uniform and appealing presentation of my online offers, this represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Google LLC has committed itself to the principles of the EU-U.S. Data Privacy Framework and has self-certified to the U.S. Department of Commerce: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active. Further information on data protection at Google can be found at: https://policies.google.com/privacy?hl=de.
Appropriate guarantees for the rights of data subjects also exist through the conclusion of EU standard contractual clauses: https://business.safety.google/adsprocessorterms/; https://support.google.com/analytics/answer/9012600. You can find out more in Google's privacy policy at: https://policies.google.com/privacy?hl
You can find more information about Google Web Fonts at https://developers.google.com/fonts/faq.
​
​
13. topicality and amendment of this data protection notice
​
I will update this data protection notice - should changes to this website or other events make this necessary. You can find the current version here on this website.