With this data protection declaration, Pink Internet GmbH (hereinafter, “We” or “Femtasy”) would like to inform you in accordance with Art. 13 of the General Data Protection Regulation (hereinafter, “GDPR”) about how our company processes personal data, as well as inform you about your rights.
The processing of your personal data is carried out in compliance with the GDPR, as well as all other applicable data protection regulations. The terms used, such as “user”, are to be understood as gender-neutral.
Pink Internet GmbH
Boxhagener Strasse 71E
10245 Berlin
E-mail: hello@femtasy.com
Contact details of the data protection officer: datenschutz@femtasy.com
Pridatect S.L. (by Borneo)
Avinguda Josep Tarradellas 8-10, 5º 4ª, 08029 Barcelona, Spanien
E-Mail: legal@borneo.io
We collect and process the following personal data:
Your data is processed in accordance with the following legal bases: your consent in accordance with Art. 6 Para. 1 lit. a) GDPR or, if applicable, Art. 9 Para. 2 lit. a) GDPR, for the performance of a contract with you in accordance with Art. 6 Para. 1 lit. b) GDPR, for the fulfillment of legal obligations in accordance with Art. 6 Para. 1 lit. c) GDPR or for a legitimate interest in accordance with Art. 6 Para. 1 lit. f) GDPR.
The legal basis for processing your data in accordance with the stated processing purposes is:
Unless otherwise stated in this privacy policy and if we base the processing of your personal data on legitimate interests pursuant to Art. 6 (1) lit. f) GDPR, such interests are the protection against misuse, the enforcement of our legal claims, the adaptation of our offer and the processing of enquiries that arise.
We collect and obtain the data from you (including via the devices you use) and you only. If we do not collect the personal data directly from you, we will also tell you the source of the personal data and, if applicable, whether it is from publicly available sources.
When processing your data, we work together with service providers who have access to your data. Possible recipients of your personal data are: (i) software companies that enable us to provide our services, help us to improve them and/or serve us for marketing purposes (for example, to send newsletters, emails, manage customer contacts or applications); (ii) public bodies and administrations, insofar as we are legally obliged to do so; (iii) payment service providers; (iv) hosting providers; (v) social media platforms; (vi) service companies, such as tax advisors or lawyers.
For the purpose of fulfilling the contract, we may also transfer your personal data to anyone to whom we assign rights arising from the contractual relationship with you.
Some of the recipients of your personal data are:
Algolia | We use Algolia to optimize our internal search function. Personal data may be disclosed in the process. We use the aforementioned services to optimize our search results. |
---|---|
Chargebee | We use Chargebee to process payments. Personal data may be passed on in the process. We use the above services to sell our services online. |
Facebook & Instagram | We integrate content from Facebook on our website. Personal data may be passed on in the process. The integration of content serves us for analysis, optimisation and advertising purposes. We also operate a profile on Facebook and Instagram. |
Google Ireland Limited | We include Google services on our website to (i) analyse the use of our website, (ii) manage tags, (iii) and for other analysis, optimisation and advertising purposes. In doing so, personal data may be passed on to Google. We use the aforementioned services to (i) understand the use of our website and (ii) to manage analysis tools (Google Tag Manager). |
Hotjar | We integrate services from Hotjar on our website. In doing so, personal data may be passed on to Hotjar. We use these services to analyse the use of our website. |
insic GmbH | We use technology from insic GmbH, Bei der Doppeleiche 3, 22926 Ahrensburg (“insic”) to carry out the age verification. The integration of insic takes place via a server call within the EU |
Klaviyo | We integrate services from Klaviyo on our website. Personal data may be passed on in the process. The integration of Klaviyo is used for analysis, optimisation and advertising purposes. |
Linkster | We use the services of Linkster GmbH. Personal data may be passed on in the process. We use the aforementioned services to measure and visualise insights into partnerships and advertising channels. This is a function to measure the efficiency of the corresponding advertising measures. |
Matomo | We use the services of Matomo (InnoCraft Ltd). Personal data may be passed on in the process. We use these services to analyse the use of our website. |
PayPal | We use PayPal to process payments. Personal data may be passed on in the process. We use the above services to sell our services online. |
We integrate content from Pinterest on our website in order to display personalised advertisements on this platform and to carry out a corresponding measurement of success. Personal data may be passed on in the process. | |
Segment | We integrate services from Segment on our website. Personal data may be passed on in the process. The integration of Segment is used for analysis, optimisation and advertising purposes. |
Snapchat | We integrate content from Snapchat on our website. Personal data may be passed on in the process. The integration of content is used for analysis, optimisation and advertising purposes. |
Stripe | We use Stripe to process payments. Personal data may be passed on in the process. We use the above services to sell our services online. |
PAIR Finance | PAIR Finance serves the purpose of debt collection and debt management. |
Taboola | We include content from Taboola on our website. Personal data may be passed on in the process. The integration of content is used for analysis, optimisation and advertising purposes. |
Typeform | We use services from Typeform to manage forms. Personal data may be passed on in the process. We use these services to provide complete and user-friendly products and processes. |
There is a transfer of data to third countries outside the European Union or the European Economic Area. Information we collect from you could be processed in the United States or other third countries. Some third countries, such as the United States, have not currently received an adequacy decision from the European Union under Article 45 of the GDPR, which means that your data may not receive the same level of protection there as it does under the GDPR.
International data transfers usually take place on the basis of contractual or other regulations provided for by law, which are intended to ensure adequate protection of your data and which you can view on request. In doing so, we rely on the provisions set out in Article 49 of the GDPR or, where applicable, on safeguards pursuant to Article 46 of the GDPR. We and our processors aim to apply appropriate safeguards to protect the privacy and security of your personal data. Therefore, we only process your personal data in accordance with the practices described in our Privacy Policy.
We store your personal data only as long as it is necessary to achieve the purpose of processing. We store your data if you have consented to the processing at most until you revoke your consent, if we need the data to perform a contract at most as long as the contractual relationship with you exists, if we use the data on the basis of a legitimate interest at most as long as your interest in deletion or anonymisation does not prevail.
In addition, data may be stored if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the person responsible is subject. In these cases, the data is deleted when a storage or retention period prescribed by the aforementioned standards expires. Among others, the provisions of the HGB and the AO apply.
We store applicant documents for a period of six months if the application does not lead to an employment relationship and no further storage has been agreed. This period results from possible lawsuits against the responsible person according to the General Equal Treatment Act (AGG).
We store server log files for a maximum of seven days.
As a data subject, you may have the right under applicable data protection law to:
Information on the right to object pursuant to Art. 21 (4) GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. We shall no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims.
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
Revocation of consent
You also have the right to withdraw consent to the processing of personal data at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.
Pursuant to Article 77 of the GDPR, you also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR or other data protection provisions. This right of appeal is without prejudice to any other administrative or judicial remedy.
The supervisory authority responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information
Address: Alt-Moabit 59-61, 10555 Berlin
Telephone: +49 (0) 30 13889-0
Fax: +49 (0) 30 2155050
E-mail: mailbox@datenschutz-berlin.de
Unless expressly stated at the time of collection, the provision of data is not required or obligatory. Such an obligation may result from legal requirements or contractual regulations. Failure to provide required personal data generally results in a contract not being able to be concluded and/or in us not being able to provide a requested service. Our employees will clarify on a case-by-case basis whether the provision of personal data is required by law or contract or necessary for the conclusion of a contract, whether there is an obligation to provide the personal data and what the consequences of not providing the personal data would be.
We do not use automated decision-making mechanisms, including profiling, that have legal effect on the data subject or similarly significantly affect the data subject.
We take organisational, contractual and technical security measures in accordance with the state of the art to ensure that the provisions of the data protection laws are complied with and thus to protect the data processed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorised persons. The security measures include in particular the encrypted transmission of data between your browser and our server.
We also advertise our presence on the following social networks on our website:
Instagram - Social network of Meta Platforms Inc. (1601 Willow Road, Menlo Park, CA 94025, USA “Facebook”)“), which is operated in Europe by Meta Platforms Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland).
Tik Tok - social network of ByteDance Ltd. (Room 503 5F Building 2 43 North Third Ring West Road Beijing, 100086 China), which is operated in Europe by TikTok Germany GmbH (Stralauer Allee 2 10245, Berlin, Germany).
The integration takes place via a text link or a linked graphic of the network. The use of these links prevents the automatic establishment of a connection to the respective server of the social network when a website with a social media application is called up. The user is only forwarded to the service of the social network by clicking on the corresponding link.
After the user has been forwarded, information about the user is collected by the social network. It cannot be ruled out that the data collected in this way will be processed in the USA. The responsible party has no influence on the processing that takes place under the responsibility of the respective social network.
The data processed in this context is initially personal data such as IP address, date, time and page visited. If the user is also logged into his or her user account of the respective network during this time, the network operator may be able to assign the collected information of the user’s specific visit to the user’s personal account. If the user interacts via a “Share” button of the respective network, this information may be stored in the user’s personal user account and may be published. If the user wants to prevent the collected information from being directly assigned to his/her user account, he/she must log out of his/her account before clicking on the graphic link provided on our website. In addition, it is possible to configure the respective user account accordingly.
The legal basis for the integration of the links on our website is our legitimate interest in the promotion and visibility of our social media presences, Art. 6.1.f GDPR. A conflicting interest on your part is not apparent.
Please note: If you click on the respective link, you will be redirected to the website of the relevant social network. As a result of this redirection, your personal data may be transferred to servers in the USA despite the fact that any network subsidiaries are located in Europe. The United States of America is currently classified as an unsafe third country, i.e. as a third country with regard to which neither an adequacy decision pursuant to Article 45 of the GDPR exists nor a comparable level of protection can be assumed. With the transmission of your data, both the network operator and, if applicable, US authorities have access to the transmitted data.
The respective network operator may link your data with other data, such as your personal accounts, the usage data of other devices and all other data that the respective network operator has about you, and may also pass on your personal data to third parties. In addition, U.S. authorities may gain access and process your data without notice or notification to you (during and even after the processing is completed) or without providing you with comparable legal remedies and data subject rights. Unfortunately, we have no influence on the processing by the respective network operator and US authorities.
Further information on the respective data protection provisions of the social networks can be found under the following links.
We reserve the right to change this privacy policy at any time with effect for the future.
Status: 18 September 2024
Get our newsletter