Data Privacy Information
This data privacy information informs you about the handling of your personal data. To make the processing of your data transparent, we would like to provide you with the following information to give you an overview of these processing operations. In order to guarantee fair processing, this data protection declaration contains general information about our handling of your data as well as information about your rights according to the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
We will inform you in detail about
General Data Processing
Data processing on our website
Data processing on our Facebook and Instagram fan page
The party responsible for data processing is Konzepthaus Consulting GmbH (hereinafter ‘we’ or ‘us’).
General Data Processing
1. Contact
If you have any questions or feedback concerning this information or wish to contact us to assert your rights, please send your enquiry to
Konzepthaus Consulting GmbH
Osterwaldstr. 10
80805 München
Germany Tel.: +49 89 125 019 010
E-Mail: contact@konzepthaus-consulting.com
2. Legal basis
The data protection term “personal data” refers to all information relating to an identified or identifiable natural person.
We process personal data in compliance with the data protection regulations, primarily the GDPR and the BDSG. Our data processing solely occurs on a legal permission. We will process personal data solely with your consent (Art. 6 Sec. 1 letter a) GDPR), to perform a contract to which you are a party, or to take steps at your request prior to entering into a contract (Art. 6 Sec. 1 letter b) GDPR), for compliance with a legal obligation (Art. 6 Sec. 1 letter c) GDPR) or where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data (Art. 6 Sec. 1 letter f) GDPR).
4. Recipients of data
We may use Service Providers for individual processes. This includes, for example, hosting, maintenance and support of IT-systems, marketing actions or destruction of files and data carriers. These Service Providers process the data only according to strict instructions and are contractually bound to guarantee suitable technical and organisational measures for data protection. In addition, we may transfer personal data of our customers to parties such as postal and delivery services, payment and information services, banks, tax consultants/auditors, the tax authorities or partners and sponsors of our events.
5. Processing in the exercise of your rights pursuant to Art. 15 to 22 GDPR
If you exercise your rights pursuant to Art. 12 to 22 GDPR for the purpose of providing information and preparing such information, we will process stored data only for this purpose and for purposes of data protection control and otherwise restrict processing in accordance with Art. 18 GDPR. These processing operations are based on the legal basis of Art. 6 Sec. 1 letter c) GDPR in combination with Art. 15 to 22 GDPR and § 34 Sec. 2 BDSG.
6. Your rights
As the person concerned, you are entitled to exercise your rights against us. In particular, you have the following rights:
Pursuant to Art. 15 GDPR and § 34 BDSG, you have the right to request information confirming whether or not and, if so, to what extent we are processing personal data concerning you.
Pursuant to Art. 16 GDPR, you have the right get your data rectified.
Pursuant to Art. 17 GDPR and § 35 BDSG, you have the right to delete personal data.
Pursuant to Art. 18 GDPR, you have the right to require us to restrict the processing of your personal data.
Pursuant to Art. 20 GDPR, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit such data to another controller.
Where you have granted us separate consent to process your data, you can withdraw such consent at any time pursuant to Art. 7 Sec. 3 GDPR. Any such withdrawal of consent shall not affect the lawfulness of processing based on that consent prior to its withdrawal.
If you consider that the processing of personal data relating to you infringes GDPR provisions, you have the right to lodge a complaint with a supervisory authority pursuant to Art.77 GDPR.
7. Right to object
Pursuant to Art. 21 Sec. 1 GDPR, you have the right to object to processing operations based on Art. 6 Sec. 1 letter e) or letter f) GDPR on grounds arising from your particular situation. If we process personal data about you for the purpose of direct marketing, you may object to such processing pursuant to Art. 21 Sec. 2 and Sec. 3 GDPR.
Data processing on our website
When using our website, we collect and use information that you provide by yourself. We also automatically collect certain information about your use of the site during your visit on the site. In data protection law, the IP address is also considered as a personal date. An IP address is assigned to each device connected to the internet by the internet provider so that it can send and receive data.
1. Processing Server-Log-Files
When using our website for purely informative purposes, general information that your browser transmits to our server is initially stored automatically (not via registration). This includes by default: browser type/-version, operating system used, page called, the previously visited page (referrer URL), IP address, date and time of server request and HTTP status code. The processing is carried out to ensure our legitimate interests and is based on the legal basis of Art. 6 Sec. 1 letter f) GDPR. This processing provides the technical administration and security of the website. The stored data will be deleted after 180 days unless there is a justified suspicion of illegal use based on concrete indications and further examination and processing of the information is necessary for this reason. We are not able to identify you as a data subject based on the stored information. Art. 15 to 22 GDPR therefore do not apply pursuant to Art. 11 Sec. 2 GDPR, unless you provide additional information to enable your identification in order to exercise the rights set out in these articles.
2. Data transmission to the USA
Visiting our website may involve the transmission of certain personal data to the USA. For the transfer of data to the USA as a non-member country, a country in which the GPDR is not applicable law, the European Commission has decided in accordance with Art. 45 GDPR that an adequate level of data protection is required for companies certified under the EU-US Privacy Shield. The transfer to the USA will then take place in a permissible manner. Certified companies are listed by the U.S. Department of Commerce at https://www.privacyshield.gov/list.
3. Contact form and requests
Our website provides a contact form, through which you can enquire an offer from us. Your data is transferred encrypted (note the ‚https‘ in the address bar of your browser). All data fields marked as mandatory are necessary to be filled in for the handling of your request. Failure to provide the required information will result in us being unable to process your request. You have the alternative option to send us an email. When you sign up for something on this website, we collect personal information from you to fulfill the interest. We may collect information like your:
Email address
Name
Company
Job Title
We share this information with Squarespace, our online store hosting provider, so that they can provide website services to us.
When you submit information to this website via webform, we collect the data requested in the webform in order to track and respond to your submissions. We share this information with Squarespace, our online store hosting provider, so that they can provide website services to us.
We process the data for the purpose of handling your request. If your request relates to the establishment or execution of a contract with us, the processing of your data is based on Art. 6 Sec. 1 letter b) GDPR. In all other cases we process data out of our legitimate interest in contacting the person enquiring. The latter data processing finds its legal basis in Art. 6 Sec. 1 letter f) GDPR.
4. Cookies
This website uses cookies and similar technologies, which are small files or pieces of text that download to a device when a visitor accesses a website or app. For information about viewing the cookies dropped on your device, visit The cookies Squarespace uses.
These necessary and required cookies are always used, which allow Squarespace, our hosting platform, to securely serve this website to you.
These analytics and performance cookies are used on this website, as described below, only when you acknowledge our cookie banner. This website uses analytics and performance cookies to view site traffic, activity, and other data.
5. Analytics
This website collects personal data to power our site analytics, including:
Information about your browser, network, and device
Web pages you visited prior to coming to this website
Your IP address
This information may also include details about your use of this website, including:
Clicks
Internal links
Pages visited
Scrolling
Searches
Timestamps
We share this information with Squarespace, our website analytics provider, to learn about site traffic and activity.
6. Integrated services and third-party content
We use services and content (collectively, “Content”) provided on our Website by third parties. For such an integration a processing of your IP address is necessary, so that the contents can be sent to your browser. Your IP address will therefore be transmitted to the respective third party providers. This data processing is carried out in order to safeguard our legitimate interests in the optimisation and economic operation of our website and finds its legal basis in Art. 6 Sec. 1 letter f) GDPR.
You can object to this data processing at any time by changing the settings of your browser or by using certain browser extensions. One such extension is the uMatrix matrix-based firewall for the Firefox and Google Chrome browsers. Please note that this may result in functional restrictions on the website.
We have incorporated into our website content from the following third-party services:
Services provided by Google Ireland Limited (Ireland/EU):
Google Web Fonts to display fonts
When using Google services, we cannot rule out the possibility that the processed data may be transferred to Google LLC (USA), which is based in the USA. Google LLC is certified under the EU-US Privacy Shield.
„YouTube“ by YouTube LLC (USA) to display videos. As a subsidiary of Google, YouTube is certified under the EU-US Privacy Shield.
„Vimeo“ by Vimeo Inc. (USA) to display videos. Vimeo is certified under the EU_US Privacy Shield.
„Fontawesome“ by Fonticons Inc. (USA) for the display of fonts and icons.
“Cloudinary” by Cloudinary Inc. (for the display of content). Cloudinary is certified under the EU_US Privacy Shield.