In the following, we provide information about the collection of personal data. Personal data means any data that can be related to you personally, e.g. name, address, email addresses, user behavior. We have taken extensive technical and operational protective measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological progress.
1. Controller responsible for data processing
The controller pursuant to Art. 4(7) of the EU General Data Protection Regulation (GDPR) is Midea Europe GmbH, Ludwig-Erhard-Str. 14, 65760 Eschborn.
2. Contact details of the Data Protection Officer
You can contact our Data Protection Officer at DSB-Midea_Europe@intersoft-consulting.de .
Data Processing on the Website
1. Your Rights
You have the following rights vis-à-vis us with regard to your personal data:
1.1. General Rights
You have the right to access, rectification, erasure, restriction of processing, objection to processing, and data portability. Insofar as processing is based on your consent, you have the right to withdraw your consent vis-à-vis us with effect for the future.
1.2. Rights in the Case of Data Processing Based on Legitimate Interests
Pursuant to Art. 21(1) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) GDPR (data processing in the public interest) or Art. 6(1)(f) GDPR (data processing for the purposes of legitimate interests); this also applies to profiling based on these provisions. In the event of your objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
1.3. Rights in the Case of Direct Marketing
Insofar as we process your personal data for the purposes of direct marketing, pursuant to Art. 21(2) GDPR, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
In the event that you object to processing for the purposes of direct marketing, we will no longer process your personal data for these purposes.
1.4. Right to Lodge a Complaint with a Supervisory Authority
You also have the right to lodge a complaint with a competent data protection supervisory authority regarding our processing of your personal data.
2. Collection of Personal Data When Visiting Our Website
When using the website for purely informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security:
The legal basis for this is Art. 6(1)(f) GDPR; insofar as strictly necessary access to information stored in the user’s terminal equipment takes place, also Section 25(2) No. 2 TDDDG.
3. Contact by Email or Contact Form
When you contact us by email or via a contact form, the data you provide (your email address and, where applicable, your name and telephone number) will be stored by us in order to process your inquiry. Insofar as we request information via our contact form that is not necessary for contacting us, we have always marked such information as optional. This information serves to specify your inquiry and to improve the handling of your request. The provision of this information is expressly voluntary and based on your consent, Art. 6(1)(a) GDPR. Insofar as this concerns information relating to communication channels (for example, email address, telephone number), you also consent to us contacting you, where applicable, via this communication channel in order to respond to your request. You may, of course, withdraw this consent at any time with effect for the future.
We delete the data arising in this context once storage is no longer necessary, or restrict processing if statutory retention obligations exist.
4. Use of Cookies
When you use our website, cookies are stored on your computer. Cookies are small text files that are stored on your hard drive and assigned to the browser you use, and through which certain information is transmitted to the entity that sets the cookie. Cookies cannot execute programs or transmit viruses to your computer. They serve to make the website as a whole more user-friendly and effective.
This website uses the following types of cookies, the scope and functionality of which are explained below:
4.1 Transient Cookies
These cookies are automatically deleted when you close the browser. These include, in particular, session cookies. They store a so-called session ID, which allows various requests from your browser to be assigned to the same session. This enables your computer to be recognized when you return to our website. Session cookies are deleted when you log out or close the browser.
4.2 Persistent Cookies
These cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete the cookies at any time in your browser's security settings.
4.3 Flash Cookies
The Flash cookies used are not recorded by your browser, but by your Flash plug-in. We also use HTML5 storage objects that are stored on your terminal device. These objects store the required data independently of the browser you use and do not have an automatic expiration date. If you do not want Flash cookies to be processed, you must install an appropriate add-on, e.g. “Better Privacy” for Mozilla Firefox (https://addons.mozilla.org/de/firefox/addon/betterprivacy/) or the Adobe Flash Killer Cookie for Google Chrome. You can prevent the use of HTML5 storage objects by using private mode in your browser. We also recommend that you regularly delete your cookies and browser history manually.
4.4 Prevention of Cookies
You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may then not be able to use all functions of this website.
4.5 Legal Bases and Storage Period
The legal bases for possible processing of personal data by means of cookies and their storage period may vary. Insofar as you have given us your consent, the legal basis is Art. 6(1) sentence 1 lit. a GDPR. Insofar as data processing is carried out on the basis of our overriding legitimate interests, the legal basis is Art. 6(1) sentence 1 lit. f GDPR. The stated purpose then corresponds to our legitimate interest.
Insofar as we access a terminal device used by you within the meaning of Section 2(2) No. 6 TDDDG by means of cookies or similar technologies by storing or reading information there irrespective of whether it relates to a person, we obtain your purpose-specific, voluntary and informed consent in advance pursuant to Section 25(1) TDDDG.
Insofar as consent under the GDPR and the TDDDG can be combined, we will obtain such consent uniformly.
Consent under the TDDDG is not required for access to information on your terminal device that is already stored there and has been sent to us through your active transmission of such information; this concerns the public IP address of the terminal device, the address of the website accessed, the user-agent string including browser and operating system and their versions, and the language setting.
Furthermore, consent under the TDDDG is not required if the cookie or similar technology serves to ensure the transmission of a message via a public telecommunications network (Section 25(2) No. 1 TDDDG) or insofar as setting the cookie and thus storing information on your terminal device or accessing information already stored on your terminal device is strictly necessary to provide a telemedia service expressly requested by you (Section 25(2) No. 2 TDDDG).
We use cookies to ensure the proper operation of the website, to provide basic functionalities, to measure reach and – with your consent – to tailor our services to preferred areas of interest.
You can delete cookies already stored on your terminal device at any time. If you wish to prevent cookies from being stored, you can do so via the settings in your Internet browser. Alternatively, you can also install so-called ad blockers. Please note that individual functions of our website may not work if you have disabled the use of cookies.
When our website is accessed, all users of our website are also informed by means of an information banner about our use of cookies and are referred to this privacy notice. As a user, you are also asked for your consent to the use of certain cookies, in particular cookies relevant to the personalization of services and marketing measures. You may withdraw any consent you have given at any time with effect for the future by accessing the cookie management via the link below and removing the check mark next to the processing to which you had consented, or by clicking on the “Cookie Settings” button at the bottom of our website and removing the check mark next to the processing to which you had consented.
5. OneTrust “CookiePro”
CookiePro is a consent management platform that enables websites to protect users' privacy and comply with the GDPR with regard to cookies and tracking. “CookiePro” is a service offered by the provider OneTrust LLC., 1200 Abernathy Rd NE, Sandy Springs, GA 30328, USA, hereinafter referred to as “OneTrust”.
Through the functionality of OneTrust, we inform visitors to our website about the use of cookies and other technologies on our website and enable them to make a decision regarding their use.
If the visitor gives consent to the use of cookies, the following data is automatically logged:
The encrypted key and the cookie status are stored by means of a cookie on the user’s terminal device in order to establish the corresponding cookie status during future visits to the website. This cookie is automatically deleted after 12 months.
The collected data will be stored until you request us to delete it, delete the OneTrust cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.
Further information on data processing by OneTrust can be found at https://www.onetrust.com/privacy/.
OneTrust LLC. has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that OneTrust LLC. has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
Legal Basis
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the user-friendliness of the website as well as in compliance with the legal requirements of the GDPR and the TDDDG.
The user can prevent or terminate the installation and storage of the cookie, and thus their cookie consent, at any time through their browser settings. You can subsequently update the OneTrust settings via the cookie settings in the footer of our website.
6. Amazon CloudFront
We use the Content Delivery Network (CDN) Amazon CloudFront, a service provided by Amazon Web Services Inc., 410 Terry Avenue North, Seattle, WA 98109-5210. AWS acts as a processor on our behalf pursuant to Art. 28 GDPR.
6.1 Type and Purpose of Processing:
A CDN is a network of servers distributed worldwide that is capable of delivering content to website users in an optimized manner. This serves to ensure security (protection against outages, protection against data loss) and to increase the delivery speed of our website. For this purpose, personal data may be processed in AWS server log files. In doing so, Amazon collects the following data:
Additionally, we retain log files in order to respond to customer inquiries regarding potential disruptions in connection with the use of our website.
6.2 Recipients of the Data:
6.3 Third-Country Transfer:
Insofar as data is processed outside the EU/EEA, Amazon has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Amazon has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
6.4 Storage Period:
Your personal data will be stored by AWS for as long as necessary for the purposes described. It will then be deleted without undue delay. We delete the stored log files after 180 days.
6.5 Legal Basis and Right to Object:
It is in our legitimate interest within the meaning of Art. 6(1) sentence 1 lit. f GDPR not to operate a Content Delivery Network ourselves while nevertheless ensuring a modern and effective provision of our website.
You have the right to object to the processing. Whether the objection is successful must be determined by balancing the respective interests. In doing so, consideration will be given to the fact that this service is technically necessary for the secure provision of our services.
The current AWS Privacy Notice can be found here:
https://aws.amazon.com/privacy/
7. Website Analytics and Online Marketing Services
For the purposes of analyzing and optimizing our website, we use various services, which are described below. Through these services, we analyze how many users visit our website, which information is most in demand, or how users find our website. We also collect data about the website from which a user came to our website (the so-called referrer), which subpages of the website are accessed, and how often and for how long a subpage is viewed. This helps us to make our website more user-friendly and to identify and correct errors, which also constitutes our legitimate interest in using these tools. The data collected in this process is not used to personally identify individual users. We follow the principle of data minimization: anonymous or, at most, pseudonymous data is collected. The legal basis for this data processing is your consent pursuant to Section 25(1) sentence 1 TDDDG, Art. 6(1) sentence 1 lit. a and Art. 7 GDPR.
7.1 Google Analytics
Insofar as you have given your consent, Google Analytics, a web analytics service provided by Google LLC, is used on this website. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
Scope of Processing
Google Analytics uses cookies that enable an analysis of your use of our websites. The information collected by the cookies about your use of this website is generally transmitted to a Google server in the USA and stored there.
We use the User-ID function. With the help of the User ID, we can assign a unique, permanent ID to one or more sessions (and the activities within these sessions) and analyze user behavior across devices.
We use Google Signals. This enables Google Analytics to collect additional information about users who have enabled personalized ads (interests and demographic data), and ads can be delivered to these users in cross-device remarketing campaigns.
We use the ‘anonymizeIP’ function (so-called IP masking): Due to the activation of IP anonymization on this website, your IP address is shortened by Google within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of Google Analytics is not combined with other Google data.
During your visit to the website, the following data, among other things, is collected:
Purposes of Processing
On behalf of the operator of this website, Google will use this information to evaluate your (pseudonymous) use of the website and to compile reports on website activities. The reports provided by Google Analytics are used to analyze the performance of our website and the success of our marketing campaigns.
Recipients
The recipient of the data is: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as a processor. We have concluded a data processing agreement with Google for this purpose. Google LLC, based in California, USA, and, where applicable, US authorities may access the data stored by Google.
Transfer to Third Countries
A transfer of data to the USA cannot be ruled out.
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search
Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework.
Storage Period
The data sent by us and linked to cookies is automatically deleted after 14 months. Data whose retention period has expired is automatically deleted once a month.
In addition, you can prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address), as well as the processing of this data by Google, by
a. not giving your consent to the setting of the cookie, or
b. downloading and installing the browser add-on for deactivating Google Analytics HERE.
You can also prevent the storage of cookies by configuring your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in restrictions to the functionality of this and other websites.
Legal Basis and Right of Withdrawal
The legal basis for this data processing is your consent, Art. 6(1) sentence 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future by accessing the cookie settings and changing your selection there.
Further information on the Google Analytics Terms of Service and data protection at Google can be found at Google Analytics Terms of Service and Google Privacy Policy.
7.2 Google DoubleClick
Insofar as you have given your consent, the online marketing tool DoubleClick by Google is used on this website. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
DoubleClick uses cookies to display advertisements that are relevant to users, improve campaign performance reports, or prevent users from seeing the same advertisements multiple times. For this purpose, Google uses a cookie ID to record which advertisements are displayed in which browser. This prevents the same advertisement from being displayed multiple times. In addition, DoubleClick can use cookie IDs to record so-called conversions relating to advertisements. This is the case, for example, when a user sees a DoubleClick advertisement and later visits the advertiser’s website using the same browser and makes a purchase.
When you access a page that uses DoubleClick and on which the DoubleClick script is permitted, your browser automatically establishes a direct connection to Google’s server. By integrating DoubleClick, Google receives the information that you have accessed the corresponding part of our website or clicked on one of our advertisements. If you are registered with a Google service, Google can associate the visit with your account.
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
You can prevent collection through this tracking procedure in various ways:
Further information on DoubleClick by Google can be found at Google DoubleClick and Google AdSense Help, and information on data protection at Google in general can be found in Google’s privacy policy. Alternatively, you can visit the Network Advertising Initiative (NAI) website.
The legal basis for this data processing is your consent, Art. 6(1) lit. a GDPR. You can withdraw your consent at any time with effect for the future by opening the privacy settings at the bottom left (“shield”) and adjusting the corresponding slider.
7.3 Facebook Custom Audience
As part of usage-based online advertising, we use the Facebook Custom Audience service provided by Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA.
For this purpose, we define target groups of users in the Facebook Ads Manager based on certain characteristics, who are subsequently shown advertisements within the Facebook network. Users are selected by Facebook on the basis of the profile information they have provided and other data made available through the use of Facebook. If a user clicks on an advertisement and subsequently visits our website, Facebook receives information via the Facebook Pixel integrated into our website that the user clicked on the advertising banner. In principle, a non-reversible and non-personal checksum (hash value) is generated from your usage data and transmitted to Facebook for analysis and marketing purposes. A Facebook cookie is set in this process. This collects information about your activities on our website (e.g. browsing behavior, subpages visited, etc.). Your IP address is also stored and used for the geographical targeting of advertising.
Further information about the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your options for configuring settings to protect your privacy, can be found in Facebook’s privacy policies. Settings regarding which advertisements are displayed to you on Facebook can be configured via the relevant link and in your Facebook account settings.
Further information on data processing and the storage period can be obtained from the provider or at Facebook Privacy Policy.
Logged-in users can deactivate the “Facebook Custom Audience” function at Facebook Ad Settings.
You can also prevent the storage of cookies entirely by configuring your browser software accordingly. However, please note that in this case you may not be able to use all functions of our website to their full extent. Further options for disabling third-party cookies can be found at the Network Advertising Initiative or on the Digital Advertising Alliance Opt-Out Platform.
The legal basis for this data processing is your consent, Art. 6(1) lit. a GDPR. You can withdraw your consent at any time with effect for the future by opening the privacy settings at the bottom left (“shield”) and adjusting the corresponding slider.
7.4 Google AdSense
We use Google AdSense, an online advertising service provided by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The controller responsible for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. Google AdSense uses cookies that are stored on your computer and collects statistical information about you that is processed by our advertising partners. We use Google AdSense to present you with advertising tailored to your interests. By visiting our website, Google receives information that you have accessed our website. Your data is transferred to the USA and evaluated there. If you are logged into your Google account, your data can be directly associated with it. If you do not want your data to be associated with your Google profile, you must log out. It is possible that this data may be disclosed to Google’s contractual partners as well as to third parties and authorities. This website has also enabled Google AdSense advertisements from third-party providers. The aforementioned data may be transferred to these third-party providers.
Further information on the purpose and scope of data collection and its processing by Google can be found at Google Advertising Technologies.
Data is collected and stored only with express consent pursuant to Art. 6(1) lit. a GDPR. This consent can be withdrawn at any time with effect for the future.
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
7.5 Google Dynamic Remarketing
For the optimization and economic operation of our online offering, we use the marketing and remarketing services (“Google Marketing Services” for short) provided by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The controller responsible for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
Google Marketing Services enable us to display advertisements for our website in a more targeted manner in order to present you only with advertisements that potentially correspond to your interests. If, for example, advertisements for our services are displayed to you on other websites, this is referred to as “remarketing”. For these purposes, when our website and other websites on which Google Marketing Services are active are accessed, Google immediately executes Google code and integrates so-called (re)marketing tags (invisible graphics or code, also referred to as “web beacons”) into the website. With their help, an individual cookie, i.e. a small file, is stored on your device (comparable technologies may also be used instead of cookies).
The cookies may be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which websites you have visited, which content you were interested in and which offers you clicked on, as well as technical information about the browser and operating system, referring websites, time of visit, and other information about the use of the online offering. Your IP address is also collected, whereby, within the framework of Google Analytics, we inform you that the IP address is shortened within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area and is only transferred in full to a Google server in the USA and shortened there in exceptional cases.
The IP address is not combined with your data within other Google services. The aforementioned information may also be combined by Google with information from other sources. If you subsequently visit other websites, advertisements tailored to you may be displayed in accordance with your interests.
We process your data pseudonymously within the framework of Google Marketing Services. This means that Google does not, for example, store and process your name or email address, but processes the relevant data on a cookie-related basis within pseudonymous user profiles. The information collected about users by Google Marketing Services is transmitted to Google and stored on Google’s servers in the USA.
The Google Marketing Services we use include, among others, the online advertising program “Google Ads” (formerly “Google AdWords”). In the case of Google Ads, each Ads customer receives a different “conversion cookie”. Cookies therefore cannot be tracked across the websites of Ads customers. The information obtained with the help of the cookie is used to generate conversion statistics for Ads customers who have opted for conversion tracking. Ads customers are informed of the total number of users who clicked on their advertisement and were redirected to a page containing a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
Furthermore, we may use the “Google Tag Manager” to integrate and manage Google analytics and marketing services on our website.
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
Further information on Google’s use of data for marketing purposes can be found on the overview page: Google Advertising Technologies; Google’s privacy policy is available at Google Privacy Policy.
Data is collected and stored only with express consent pursuant to Art. 6(1) sentence 1 lit. a GDPR. This consent can be withdrawn at any time with effect for the future.
7.6 Google Tag Manager
For reasons of transparency, we would like to point out that we use Google Tag Manager. This is a tag management system for managing JavaScript and HTML tags used to implement tracking and analytics tools. It is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The controller responsible in the EU/EEA is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
Google Tag Manager itself does not collect any personal data. Tag Manager makes it easier for us to integrate and manage our tags. Tags are small code elements that are used, among other things, to measure traffic and visitor behavior, record the impact of online advertising and social channels, set up remarketing and targeting, and test and optimize websites. If you have deactivated tracking, this deactivation will be respected by Google Tag Manager.
Recipients of the data are:
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
The legal basis for this data processing is your consent. You have the option to withdraw consent once given with effect for the future by changing your settings via the “Cookie Settings” button in the footer of our website.
The lawfulness of the data processing carried out prior to withdrawal remains unaffected.
Further information on Google Tag Manager can be found at:
Google Tag Manager Use Policy.
7.7 Google Maps
Insofar as you have given your consent, we use the Google Maps mapping service on our website. Google Maps is a mapping service provided by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The responsible service provider for users in the EU/EEA and Switzerland is Google Ireland Limited (“Google”).
When you visit a website containing Google Maps, your browser establishes a direct connection to Google’s servers, whereby the map content is sent to your browser and integrated by it. This includes the following data:
· Date and time of the visit to the relevant website,
· Location information,
· IP address, (starting) address entered as part of route planning,
· Internet address or URL of the website accessed,
· Usage data, and
· Search terms.
Further information on how user data is handled can be found in Google’s privacy policy: Google Privacy Policy.
The information collected via the API about your use of this website is generally processed in the European Union.
Insofar as data is processed in the United States of America (USA), Google Inc. has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search. Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework.
Google also provides EU Standard Contractual Clauses and thereby offers an additional guarantee of compliance with European data protection law. The existing EU Standard Contractual Clauses remain valid after the adequacy decision has entered into force.
For further information on security measures, please refer to the privacy policy of the respective provider or contact the provider directly.
The data will be deleted as soon as it is no longer required for the purposes of processing.
The legal basis for this data processing is your consent, Art. 6(1) lit. a GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future by opening the privacy settings in the footer of our website (“Website Cookies”) and making the corresponding changes.
7.8 Shopify Analytics
Insofar as you have given your consent, we use Shopify’s analytics functions for the statistical evaluation and optimization of our online shop.
Shopify collects information about the use of our shop, in particular:
The processing is carried out to analyze the use of our online shop, improve our offering and optimize user-friendliness.
The legal basis for the processing is your consent pursuant to Art. 6(1) lit. a GDPR and Section 25(1) TDDDG.
Insofar as personal data is processed outside the European Union or the European Economic Area, this is carried out on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
You can withdraw your consent at any time with effect for the future via the cookie settings.
Further information can be found at: Shopify Privacy Policy.
7.9 Shopify Marketing and Remarketing
Insofar as you have given your consent, we may use Shopify functions to measure the success of marketing measures and to display interest-based advertising.
For this purpose, information about
may be processed.
The information obtained enables us to evaluate the effectiveness of our advertising measures and to display personalized advertising on other platforms.
The processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR and Section 25(1) TDDDG.
Consent can be withdrawn at any time with effect for the future via the cookie settings.
Further information can be found at: Shopify Privacy Policy.
7.10 Shopify Payments
If you make a payment as part of the ordering process, payment processing may be carried out via Shopify Payments.
The provider is Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.
For the purpose of processing the payment, Shopify Payments processes in particular:
The processing is carried out for the purposes of payment processing, fraud prevention and compliance with legal obligations.
The legal basis is Art. 6(1) lit. b GDPR (performance of a contract) and Art. 6(1) lit. c GDPR (legal obligations).
Further information can be found at: Shopify Privacy Policy.
7.11 Shop Pay
We may offer our customers the use of the “Shop Pay” express checkout service.
Shop Pay enables an accelerated ordering process by storing certain customer data for future orders.
In particular, the following data may be processed:
The use of Shop Pay is voluntary.
The legal basis for the processing is Art. 6(1) lit. b GDPR for carrying out the ordering process and, where required, Art. 6(1) lit. a GDPR.
Further information can be found at: Shopify Privacy Policy.
7.12 PayPal
Insofar as you select PayPal as your payment method, the personal data required for payment processing will be transmitted to PayPal.
The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
The data processed includes in particular:
The transmission takes place exclusively for the purposes of payment processing, fraud prevention and identity verification.
PayPal may, under certain circumstances, disclose the transmitted data to affiliated companies, credit agencies or other service providers insofar as this is necessary for the performance of the contract or fraud prevention.
The legal basis for the processing is Art. 6(1) lit. b GDPR.
Insofar as PayPal carries out credit checks, this is based on Art. 6(1) lit. f GDPR. Our legitimate interest lies in avoiding payment defaults.
Further information can be found at: PayPal Privacy Statement.
7.13 Klarna
Insofar as you choose to make a payment via Klarna, the personal data required for payment processing will be transmitted to Klarna.
The provider is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden.
In particular, the following data may be processed:
Klarna uses the data to process the payment, establish identity, prevent fraud and, where applicable, perform a credit check.
As part of the credit check, Klarna may obtain information from credit agencies and use it to determine statistical probability values regarding the ability to pay.
The legal basis for the processing is Art. 6(1) lit. b GDPR.
Insofar as credit checks are carried out, the processing is additionally based on Art. 6(1) lit. f GDPR. The legitimate interest lies in avoiding payment defaults and cases of fraud.
Further information can be found at: Klarna Privacy Policy.
8. Data Transfer
As a general rule, your data will not be transferred to third parties unless we are legally obliged to do so, the transfer of data is necessary for the performance of the contractual relationship, or you have expressly consented in advance to the transfer of your data.
External service providers and partner companies, such as online payment providers or the shipping company commissioned with delivery, receive your data only insofar as this is necessary to process your order. In these cases, however, the scope of the data transmitted is limited to the necessary minimum. Insofar as our service providers come into contact with your personal data, we ensure within the framework of processing pursuant to Art. 28 GDPR that they comply with the provisions of data protection laws in the same manner. Please also note the respective privacy notices of the providers. The respective service provider is responsible for the content of third-party services, whereby we review the services for compliance with legal requirements to the extent reasonable.
Are your data transferred to countries outside the European Union (so-called third countries)?
Countries outside the European Union (and the European Economic Area, “EEA”) handle the protection of personal data differently from countries within the European Union. For the processing of your data, we also use service providers located in third countries outside the European Union. There is currently no decision by the EU Commission that these third countries generally provide an adequate level of protection. We have therefore taken special measures to ensure that your data is processed just as securely in third countries as within the European Union. With service providers in third countries, we conclude the Standard Contractual Clauses provided by the European Commission. These clauses provide appropriate safeguards for the protection of your data with service providers in third countries. If you wish to inspect the existing safeguards, you can contact us at datenschutz@midea.com.
9. Online Shop (Shopify)
For the provision of our online shop, we use the Shopify platform of Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Shopify processes personal data on our behalf and provides the technical infrastructure for operating the online shop.
9.1 Scope of Processing
When you visit our online shop or place an order there, the following personal data in particular may be processed:
9.2 Purposes and Legal Bases
The processing is carried out:
9.3 Customer Account
If you create a customer account, we store the data you provide in order to enable you to use your customer account, manage your orders and place future orders.
You can have your customer account deleted at any time. Statutory retention obligations remain unaffected.
9.4 Cookies and Similar Technologies
Shopify uses technically necessary cookies and similar technologies to ensure the functionality of the online shop, in particular for:
9.5 Recipients and Third-Country Transfers
As part of the provision of the online shop, personal data may be transferred to companies of the Shopify Group as well as technical service providers.
Insofar as data is processed outside the European Union or the European Economic Area, this is carried out exclusively in compliance with Art. 44 et seq. GDPR and using appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission.
9.6 Storage Period
The data is stored for the duration of the contractual relationship and in accordance with statutory retention periods. After the statutory periods have expired and the purposes of processing no longer apply, the data will be deleted, provided that there are no statutory retention obligations to the contrary.
Further information on data processing by Shopify can be found at: Shopify Privacy Policy.
10. Data Security
We have taken extensive technical and operational protective measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological progress.
11. Cashback Promotion
As part of cashback promotions, we process participants’ personal data in order to conduct the promotion, verify eligibility, pay out cashback amounts, prevent abusive or fraudulent participation and – insofar as specified in the respective promotion and legally permissible – evaluate the promotion and use it for marketing purposes (e.g. statistical analyses and promotions).
As part of cashback promotions, we process in particular the following categories of data: identification and contact data (e.g. name, address, email address, where applicable telephone number), billing and payment data (e.g. IBAN and BIC), promotion data (e.g. submitted receipts or invoices, purchase date, products purchased, retailer and branch, model number), participation information (e.g. time of registration, IP address, communication content in connection with processing) and, where applicable, further information requested in the participation form.
The legal basis for the processing is Art. 6(1) lit. a GDPR (consent to participate in the cashback promotion). You may withdraw your consent at any time with effect for the future. To do so, please contact marketing.meg@midea.com. Insofar as we process data for fraud prevention, the establishment, exercise or defense of legal claims, or the internal evaluation of the promotion, this is based on our legitimate interest pursuant to Art. 6(1) lit. f GDPR. Insofar as we are legally obliged to retain certain documents (e.g. retention obligations under commercial and tax law in connection with payments), the processing is additionally based on Art. 6(1) lit. c GDPR.
Recipients of the data may include promotion and service companies engaged by us, payment service providers, banks, IT and hosting providers and, where necessary, legal advisors and authorities.
Insofar as a transfer to a third country outside the EU/EEA takes place, we ensure that an adequate level of data protection is in place, e.g. through an adequacy decision of the EU Commission or by concluding appropriate safeguards (in particular EU Standard Contractual Clauses); further information is available upon request.
We store personal data arising in connection with the cashback promotion for the duration of the promotion and its processing (including payment and any follow-up inquiries) and beyond this only insofar as and for as long as this is necessary for evidentiary purposes, fraud prevention, the defense against or enforcement of legal claims, or due to statutory retention obligations; thereafter, the data will be deleted or anonymized.
Participants have the right to request access to personal data concerning them, to have inaccurate data rectified and, subject to the statutory requirements, to request erasure or restriction of processing, to object to processing on grounds relating to their particular situation, and to withdraw consent given at any time with effect for the future, without affecting the lawfulness of processing carried out prior to withdrawal. Furthermore, there is a right to data portability pursuant to Art. 20 GDPR and the right to lodge a complaint with a competent data protection supervisory authority.
12. Customer Survey
As part of customer surveys conducted by video interview or home visit, we process personal data in order to prepare and conduct the survey, evaluate the responses, improve our products and services, ensure quality assurance and – insofar as expressly specified in the respective survey and legally permissible – use the results and selected excerpts from video/audio recordings for internal training purposes.
For this purpose, we process in particular identification and contact data (e.g. name, address, email address, telephone number), organizational data (e.g. appointment arrangements, address of the home visit), video and audio recordings (image and sound recordings of the participating persons and the premises being interviewed), interview content (responses, opinions, assessments), billing and payment data (e.g. bank details), promotion data (e.g. submitted receipts or invoices, purchase date, products purchased, retailer and branch, promotion codes, serial numbers), as well as any further information you voluntarily provide as part of the survey. Due to recordings in a domestic environment, special categories of personal data within the meaning of Art. 9 GDPR may also be processed (e.g. inferences regarding health data, religious or political beliefs based on visible objects or symbols).
For the organization, conduct and evaluation of the purchaser survey, we use an external market research service provider. This provider processes your data exclusively on our behalf and in accordance with our instructions. Insofar as information and statements are evaluated or passed on, this is done only in anonymized form unless expressly stated otherwise.
The legal basis for the processing is generally your consent pursuant to Art. 6(1) lit. a GDPR; insofar as special categories of personal data are affected in an individual case, the processing is based on your explicit consent pursuant to Art. 9(2) lit. a GDPR. You may withdraw your consent at any time with effect for the future. To do so, please contact marketing.meg@midea.com. Insofar as participation in the survey is based on contractual arrangements or conditions of participation (e.g. an agreement on expense reimbursement), Art. 6(1) lit. b GDPR is an additional legal basis for the processing of data necessary for the performance of this contract. In addition, the processing of individual data may be based on our legitimate interest pursuant to Art. 6(1) lit. f GDPR, for example for quality assurance, internal evaluation of the survey, improvement of our products and services, defense against or establishment of legal claims, or ensuring IT security.
Recipients of the data are exclusively entities involved in the planning, conduct and evaluation of the respective survey, in particular internal project and specialist departments (e.g. product management, service quality, marketing), service providers engaged by us for video and interview technology, market research companies, as well as IT and hosting providers acting on our behalf and contractually obliged to maintain confidentiality and comply with data protection requirements.
Insofar as a transfer to a third country outside the EU/EEA takes place, we ensure that an adequate level of data protection is in place, e.g. through an adequacy decision of the EU Commission or by concluding appropriate safeguards (in particular EU Standard Contractual Clauses); further information is available upon request.
We store personal data from customer surveys only for as long as necessary to conduct the survey, evaluate it and achieve the stated purposes; video/audio recordings are generally deleted after completion of the evaluation following the expiry of a specified period or – insofar as possible and intended – are further used only in anonymized or pseudonymized form. Beyond this, we store data only insofar as and for as long as statutory retention obligations or legitimate interests (e.g. for the defense against or enforcement of legal claims) require this; thereafter, the data will be deleted or anonymized.
Participants have the right to request access to personal data concerning them, to have inaccurate data rectified and, subject to the statutory requirements, to request erasure or restriction of processing, to object to processing on grounds relating to their particular situation, and to withdraw consent given at any time with effect for the future, without affecting the lawfulness of processing carried out prior to withdrawal. Furthermore, there is a right to data portability pursuant to Art. 20 GDPR and the right to lodge a complaint with a competent data protection supervisory authority.
Data Processing of Business Partners
1. Which of Your Personal Data Do We Use?
If you make an inquiry, ask us to prepare an offer, or conclude a contract with us, we process your personal data. In addition, we also process your personal data, among other things, to comply with legal obligations, safeguard a legitimate interest, or on the basis of consent you have given.
Depending on the legal basis, this includes the following categories of personal data:
In the course of initiating a contract, we also use data provided to us by third parties. Depending on the type of contract, this includes the following categories of personal data:
2. From Which Sources Does the Data Originate?
We process personal data that we receive from our customers, service providers and suppliers.
We also receive personal data from the following sources:
3. For What Purposes Do We Process Your Data and on What Legal Basis?
We process your personal data in particular in compliance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and all other relevant laws.
3.1 On the Basis of Consent Given by You (Art. 6(1)(a) GDPR)
If you have voluntarily consented to the collection, processing or transfer of certain personal data, this consent constitutes the legal basis for the processing of such data.
In the following cases, we process your personal data on the basis of consent given by you:
3.2 For the Performance of a Contract (Art. 6(1)(b) GDPR)
We use your personal data for the performance of the order/purchase agreement/treatment agreement/rental agreement.
Within this contractual relationship, we will process your data in particular to carry out the following activities:
Further information on the purposes of data processing can be found in the respective contractual documents and General Terms and Conditions.
3.3 For Compliance with Legal Obligations (Art. 6(1)(c) GDPR)
As a company, we are subject to various legal obligations. Processing of personal data may be necessary in order to comply with these obligations.
3.4 On the Basis of a Legitimate Interest (Art. 6(1)(f) GDPR)
In certain cases, we process your data to safeguard our legitimate interests or those of third parties.
4. To Whom Will Your Data Be Disclosed?
In order to fulfill our contractual and legal obligations, your personal data will be disclosed to various public or internal bodies as well as external service providers.
Companies within the Group:
Midea Group Co. Ltd.
External Service Providers:
We work with selected external service providers to fulfill our contractual and legal obligations.
Public Authorities:
In addition, we may be required to transfer your personal data to other recipients, such as authorities, in order to comply with statutory reporting obligations.
5. Will Your Data Be Transferred to Countries Outside the European Union (So-Called Third Countries)?
Countries outside the European Union (and the European Economic Area, “EEA”) handle the protection of personal data differently from countries within the European Union. For the processing of your data, we also use service providers located in third countries outside the European Union. There is currently no decision by the EU Commission that these third countries generally provide an adequate level of protection. We have therefore taken special measures to ensure that your data is processed just as securely in third countries as within the European Union. With service providers in third countries, we conclude the Standard Contractual Clauses provided by the European Commission. These clauses provide appropriate safeguards for the protection of your data with service providers in third countries. If you wish to inspect the existing safeguards, you can contact us at DSB-Midea_Europe@intersoft-consulting.de.
6. How Long Will My Data Be Stored?
We store your personal data for as long as necessary to fulfill our statutory and contractual obligations.
If storage of the data is no longer necessary for the fulfillment of contractual or statutory obligations, your data will be deleted unless further processing is necessary for the following purposes:
7. What Rights Do You Have in Connection with the Processing of Your Data?
Every data subject has the right of access pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR, the right to object pursuant to Art. 21 GDPR, and the right to data portability pursuant to Art. 20 GDPR. With regard to the right of access and the right to erasure, the restrictions pursuant to Sections 34 and 35 BDSG apply.
7.1 Right to Object
You may object at any time to the use of your data for advertising by means of electronic mail without incurring any costs other than the transmission costs according to the basic rates.
What right do you have in the event of data processing based on your legitimate or public interest?
Pursuant to Art. 21(1) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) GDPR (data processing in the public interest) or Art. 6(1)(f) GDPR (data processing for the purposes of legitimate interests); this also applies to profiling based on these provisions. In the event of your objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
What right do you have in the event of data processing for the purposes of direct marketing?
Insofar as we process your personal data for the purposes of direct marketing, pursuant to Art. 21(2) GDPR, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing. In the event that you object to processing for the purposes of direct marketing, we will no longer process your personal data for these purposes.
7.2 Withdrawal of Consent
You can withdraw your consent to the processing of personal data at any time. Please note that the withdrawal only takes effect for the future.
7.3 Right of Access
You can request information as to whether we have stored personal data about you. If you wish, we will inform you which data is involved, for what purposes the data is processed, to whom this data is disclosed, how long the data is stored, and what other rights you have with regard to this data.
7.4 Further Rights
In addition, you have the right to have inaccurate data rectified or your data erased. If there is no reason for further storage, we will delete your data; otherwise, we will restrict the processing. You may also request that we provide all personal data that you have provided to us in a structured, commonly used and machine-readable format, either to you or to a person or company of your choice.
In addition, you have the right to lodge a complaint with the competent data protection supervisory authority (Art. 77 GDPR in conjunction with Section 19 BDSG).
7.5 Exercising Your Rights
To exercise your rights, you can contact the controller or the Data Protection Officer using the contact details provided. We will process your requests without undue delay and in accordance with the statutory requirements and inform you of the measures we have taken.
8. Are You Obliged to Provide Your Personal Data?
In order to enter into a business relationship, you must provide us with the personal data that is necessary for the performance of the contractual relationship or that we are legally required to collect. If you do not provide us with this data, we will not be able to perform and process the contractual relationship.
9. Changes to This Information
If the purpose or manner of processing your personal data changes materially, we will update this information in good time and inform you of the changes in good time.
Use of Social Plugins
This website uses social plugins from the following provider(s):
· Instagram (operator: Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA)
· YouTube (operator: LLC, 901 Cherry Ave., 94066 San Bruno, CA, USA)
These plugins normally collect data from you by default and transmit it to the servers of the respective provider. To protect your privacy, we have taken technical measures to ensure that your data cannot be collected by the providers of the respective plugin without your consent. When you access a page on which the plugins are integrated, they are initially deactivated. The plugins are only activated when you click on the respective icon, thereby giving your consent for your data to be transferred to the respective provider. The legal basis for the use of the plugins is Art. 6(1) lit. a GDPR.
Once activated, the plugins also collect personal data such as your IP address and send it to the servers of the respective provider, where it is stored. In addition, activated social plugins set a cookie with a unique identifier when the relevant website is accessed. This also enables the providers to create profiles of your usage behavior. This occurs even if you are not a member of the respective provider’s social network. If you are a member of the provider’s social network and are logged into the social network while visiting this website, your data and information about your visit to this website may be linked to your profile on the social network. We have no influence over the exact scope of the data collected from you by the respective provider. For further information on the scope, nature and purpose of data processing and on rights and settings available to protect your privacy, please refer to the privacy notices of the respective social network provider. These are available at the following addresses:
Facebook: Facebook Privacy Policy
Instagram: Instagram Privacy Policy
YouTube: Google Privacy Policy
Insofar as data is processed outside the EU/EEA, Meta (the parent company of Facebook and Instagram) and Google (the parent company of YouTube) have certified themselves under the Data Privacy Framework (DPF) program and are listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Meta and Google have publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search
Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework.
1. Instagram Social Plugins
Our website also uses so-called social plugins (“plugins”) from Instagram, operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). The plugins are identified by an Instagram logo, for example in the form of an “Instagram camera”.
When you access a page of our website that contains such a plugin, your browser establishes a direct connection to Instagram’s servers. The content of the plugin is transmitted by Instagram directly to your browser and integrated into the page. Through this integration, Instagram receives the information that your browser has accessed the corresponding page of our website, even if you do not have an Instagram profile or are not currently logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there. If you are logged into Instagram, Instagram can directly associate your visit to our website with your Instagram account. If you interact with the plugins, for example by clicking the “Instagram” button, this information is also transmitted directly to an Instagram server and stored there. The information is also published on your Instagram account and displayed there to your contacts.
If you do not want Instagram to directly associate the data collected via our website with your Instagram account, you must log out of Instagram before visiting our website.
Further information can be found in Instagram’s Privacy Policy.
2. Information on Data Protection on Our Instagram Page
Midea Europe GmbH attaches great importance to the protection of personal data. In the following, we provide information about the collection of personal data when you visit our Instagram Page. If you have any further questions regarding the handling of your personal data, please contact our Data Protection Officer.
2.1 General Information
Social media have become an integral part of the Internet and modern communication. In order to remain in contact with our customers and interested parties, we have also set up our own Instagram Page. Instagram is an online service for sharing photos and videos belonging to Meta Platforms, Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. The entity responsible for operating the network, as with the Facebook social network, is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter: “Meta”).
We expressly point out that Meta stores users’ data (e.g. IP address, preferences and personal interests (e.g. through hashtags and groups with which a user is connected), behavior on Instagram pages, any personal information stored on Instagram, etc.) and uses it for business purposes.
We have no influence over the processing and further use of this data, as Meta alone determines the processing. We are currently unable to ascertain the extent to which, where and for how long the data is stored, the extent to which the data is linked and evaluated, and to whom the data is disclosed. We also have no insight into or influence over deletion periods, i.e. whether and to what extent deletion periods are observed.
Meta’s own information on what information is collected can be found in Instagram’s privacy policy, which can be viewed HERE.
If you are an Instagram member and are logged into your Instagram user account, Meta can associate your visit to our page with your user account. If you wish to prevent Meta from linking data about your visit to our Instagram Page with your membership data stored by Instagram, you should log out of Instagram before each visit to our Instagram Page, delete the cookies stored on your device, and close and restart your browser.
However, even after taking these steps, Meta may recognize you through so-called unique identifiers, such as device IDs and other identifiers, such as those from games, apps or accounts you use, or family device IDs (or other identifiers that are unique to Meta company products linked to the same device or account).
2.2 Scope of Data Collection and Storage
You do not have to be an Instagram member to view the content on our Instagram Page. However, Meta collects, stores and uses data every time our Instagram Page is visited.
When you access our Instagram Page, your browser establishes a connection to a Meta server. In doing so, data may be transferred to countries outside the European Union. In any event, regardless of whether you are registered with Instagram or not, your IP address is transmitted and cookies are set. If you are an Instagram member and are logged into your Instagram user account, Meta can associate your visit to our page with your user account.
According to Meta, the cookies used by Instagram serve authentication, security, website and product integrity, advertising and measurement, website functions and services, performance, as well as analysis and research. Further information is available in the Instagram Help Center at the following link: Instagram Help Center.
If you do not have an Instagram account, you can manage interest-based online advertising through the settings of the European Interactive Digital Advertising Alliance and through the settings of your mobile device. You can additionally object to the collection and storage of data through the use of the aforementioned Meta cookies at any time with effect for the future via the following opt-out link: Your Online Choices.
Under the aforementioned link, you can manage your preferences regarding usage-based online advertising. If you use the preference manager to object to usage-based online advertising from a particular provider, this applies only to the specific business data collection via the web browser currently being used. Preference management is cookie-based. Deleting all browser cookies will therefore also remove the preferences you have set using the preference manager.
You can also configure your browser before visiting our Instagram Page so that no cookies from Meta are stored. Information on how to adjust the cookie settings in your browser can be found in the help section of the browser you use.
We have no influence over whether and which cookies Meta sets via our Instagram Page or how this data is processed.
The processing of your data by us when you contact or interact with us via our Instagram Page is based on our legitimate interest pursuant to Art. 6(1) sentence 1 lit. f GDPR. Our overriding legitimate interest lies in contacting and communicating with our interested parties and responding to their specific concerns. Insofar as your message is aimed at concluding a contract or concerns matters relating to the performance of an existing contractual relationship, the legal basis for the processing is also Art. 6(1) sentence 1 lit. b GDPR.
As a general rule, we store personal data only until the respective purpose for which the data was collected has been achieved. Within the framework of a business relationship with you, we store your personal data for as long as the business relationship continues; this also includes the initiation and processing of a contract as well as the regular limitation period. In addition, we store the data if and insofar as we are subject to statutory retention obligations. Such obligations may arise, for example, from the German Commercial Code (HGB) or the German Fiscal Code (AO).
If you have given us consent for a processing operation, the data associated with the granting of consent will be stored until withdrawal or, at the latest, for the duration of the processing operation and, following its completion, within the framework of the limitation period.
There is no statutory or contractual obligation to provide your personal data to us or to Instagram. Failure to provide such data has no negative consequences.
2.3 Instagram Insights
For statistical evaluation purposes, we use the Instagram Insights function. In this context, we receive anonymized data in the form of statistics that Meta collects, among other things, via cookies and pixels regarding visitors to our Instagram Page. This does not enable us to draw any conclusions about your identity.
The following information is provided to us by Meta through Instagram Insights:
Followers: Number of people who follow us – including developments over a period of up to 30 days.
Demographic data: Average age of visitors, gender, place of residence, language.
Activity data: Times at which most users from the community are active.
Reach: Number of people who see a post shared by us. Number of interactions with our post. This enables us to determine which content is more interesting to the community than other content.
Ad performance: Number of people reached by and interacting with a post or paid advertisement.
Activities on our Instagram Page: Number of clicks on our buttons (for planning a route, sending us emails, or accessing our website).
Views: Number of times our Instagram Page has been accessed.
Further information on the Insights functions is provided by Meta in its Instagram Privacy Policy.
The Instagram Help Center provides instructions explaining which settings must be configured to determine how targeted advertising is displayed. You can access these by visiting the Instagram Help Center, selecting the “Manage Your Account” tab and then “Instagram Ads”.
2.4 Disclosure and Use of Personal Data
It cannot be ruled out that the data will be transferred to and processed in countries outside the European Union (including the USA). The USA is currently regarded as an unsafe third country under data protection law, as the high European level of data protection does not exist there. It is possible that personal data may be subject to access by US authorities for monitoring and surveillance purposes, against which neither effective legal remedies nor data subject rights may be enforceable.
Recipients or Categories of Recipients |
Meta Platforms Ireland Limited Meta Platforms, Inc. Insofar as you interact via Instagram, Meta naturally also has access to your data. In particular, it is possible that Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, has access to your data. Meta is located in an unsafe third country where the level of data protection is lower.
According to Meta’s Instagram Privacy Policy, Standard Contractual Clauses are used, among other things, for data transfers from the EEA to the USA and other countries. In addition, since August 31, 2020, Meta has made available online a Facebook EU Data Transfer Addendum, through which the Standard Contractual Clauses are intended to be incorporated in cases where Meta Platforms Ireland Limited processes data from the EU/EEA as a processor and transfers it to Meta Platforms Inc. as a sub-processor. |
2.5 Your Rights
Provided that the requirements specified by law are met, you have the following rights:
Access |
Art. 15 DSGVO |
Rectification |
Art. 16 DSGVO |
Erasure |
Art. 17 DSGVO |
Blocking / Restriction of Processing |
Art. 18 DSGVO |
Objection |
Art. 21 DSGVO |
Data Portability |
Art. 20 DSGVO |
Right to Lodge a Complaint with the Competent Supervisory Authority |
Art. 77 DSGVO |
Right to Withdraw Consent with Effect for the Future, Provided Consent Has Been Given |
Art. 7 Abs. 3 DSGVO |
To exercise your rights, please contact Instagram or us at datenschutz@midea.com.
2.6 Contact Details of the Controllers
|
Controllers If you transmit personal data to us via our Instagram Page and we alone determine the purposes and means of the processing, Midea Europe GmbH DSB-Midea_Europe@intersoft-consulting.de is the sole controller responsible for the processing. Insofar as personal data is processed in connection with our Instagram Page and Meta alone determines the purposes and means of the processing, Meta Platforms Ireland Ltd. is the sole controller responsible for the processing. |
2.7 Further Information
Further information on the safe use of social networks can be found on the website of the German Federal Office for Information Security at Federal Office for Information Security.
3. YouTube (with Two-Click Solution)
We use services provided by YouTube, LLC, 901 Cherry Ave., 94066 San Bruno, CA, USA, a subsidiary of Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA, on our website. For users whose habitual residence is in the European Economic Area or Switzerland, Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland, is the controller responsible for your data.
To protect your personal data, we use a two-click solution. When you access a page in which a YouTube video is embedded, a connection to the YouTube servers is established only when you click the “Confirm” button. In this case, YouTube will set cookies and use your visit data for its own purposes. If you are logged into YouTube at that time, information about the videos you have viewed will be associated with your YouTube membership account. You can prevent this by logging out of your membership account before visiting our website.
Insofar as data is processed outside the EU/EEA, Google has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Google has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search
Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework
Further information on YouTube’s data protection practices is provided by Google at the following link: Google Privacy Policy
4. Facebook Fanpage
4.1 General Information
Social media have become an integral part of the Internet and modern communication. In order to remain in contact with our customers and interested parties, we have also set up our own fanpage on Facebook. Facebook is a service provided by Meta Platforms, Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (hereinafter referred to as “Facebook”).
We expressly point out that Facebook stores users’ data (e.g. IP address, preferences and personal interests, behavior on Facebook pages, any personal information stored on Facebook, etc.) and uses it for business purposes.
We have no influence over the processing and further use of this data, as Facebook alone determines the processing. We are currently unable to ascertain the extent to which, where and for how long the data is stored, the extent to which the data is linked and evaluated, and to whom the data is disclosed. We also have no insight into or influence over deletion periods, i.e. whether and to what extent deletion periods are observed.
Facebook’s own information on what information is collected can be found in Facebook’s privacy policy, which can be viewed here: Facebook Privacy Policy
If you are a Facebook member and are logged into your Facebook user account, Facebook can associate your visit to our page with your user account. If you wish to prevent Facebook from linking data about your visit to our fanpage with your membership data stored by Facebook, you must:
· log out of Facebook before each visit to our fanpage
· delete the cookies stored on your device
· and close and restart your browser.
According to Facebook, this will delete all information through which you can be identified by Facebook.
4.2 Scope of Data Collection and Storage
You do not have to be a Facebook member to view the content on our Facebook fanpage. However, Facebook collects, stores and uses data every time our page is visited. At the moment you access our fanpage, your browser establishes a connection to a Facebook server. In doing so, data may be transferred to countries outside the European Union. In any event, regardless of whether you are registered with Facebook or not, your IP address is transmitted and cookies are set. If you are a Facebook member and are logged into your Facebook user account, Facebook can associate your visit to our page with your user account.
The cookies used include session cookies, which are deleted when the browser is closed, and persistent cookies, which remain on the terminal device until they expire or are deleted by the user. A cookie is a tiny text file that enables a website to recognize a browser. Cookies are stored on the computer when a website is accessed and are retrieved and read by the web server the next time the website is accessed. You can use your browser settings to decide whether and which cookies you wish to allow, block or delete. Instructions for various browsers can be found here: Internet Explorer, Firefox, Google Chrome, Google Chrome mobile, Microsoft Edge, Safari, Safari mobile. Alternatively, you can also install so-called ad blockers, such as Ghostery.
According to Facebook, the cookies used by Facebook serve authentication, security, website and product integrity, advertising and measurement, website functions and services, performance, as well as analysis and research. Details of the cookies used by Facebook (e.g. cookie names, duration, content collected and purpose) can be viewed here: Facebook Cookie Policy by following the links provided there.
You can configure settings regarding which advertisements Facebook should or should no longer display to you at Facebook Advertising Settings and at Your Online Choices.
Under the aforementioned link, you can manage your preferences regarding usage-based online advertising. If you use the preference manager to object to usage-based online advertising from a particular provider, this applies only to the specific business data collection via the web browser currently being used. Preference management is cookie-based. Deleting all browser cookies will therefore also remove the preferences you have set using the preference manager.
Data |
Purpose of Use |
Legal Basis |
User interactions (posts, likes, etc.) |
User communication |
Art. 6(1) lit. f) GDPR |
Facebook-Cookies* |
Targeted advertising |
Art. 6(1) lit. f) GDPR |
Demographic data (e.g. based on age, place of residence, language or gender information) |
Targeted advertising |
Art. 6(1) lit. f) GDPR |
Statistical data on user interactions in aggregated form, i.e. without being personally identifiable to us (e.g. page activities, page views, page previews, likes, recommendations, posts, videos, page subscriptions incl. origin, times of day) |
Targeted advertising |
Art. 6(1) lit. f) GDPR |
An automated decision-making process, including profiling pursuant to Art. 22 GDPR, does not take place.
We generally store personal data only until the respective purpose for which the data was collected has been achieved. Within the framework of a business relationship with you, we store your personal data for as long as the business relationship continues; this also includes the initiation and processing of a contract as well as the regular limitation period. In addition, we store the data if and insofar as we are subject to statutory retention obligations. Such obligations may arise, for example, from the German Commercial Code (HGB) or the German Fiscal Code (AO).
If you have given us consent for a processing operation, the data associated with the granting of consent will be stored until withdrawal or, at the latest, for the duration of the processing operation and, following its completion, within the framework of the limitation period.
4.3 Facebook Insights
For statistical evaluation purposes, we use the Facebook Insights function. In this context, we receive anonymized data about the users of our Facebook fanpage. This does not enable us to draw any conclusions about your identity. For further information, please refer to Facebook’s cookie policy.
4.4 Disclosure and Use of Personal Data
Insofar as you interact via Facebook, Facebook naturally also has access to your data. The provider of Facebook (Meta Platforms, Inc.) is based in the United States (USA) and thus outside the European Union.
Insofar as data is processed in the USA, Meta Platforms, Inc. has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Meta has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search. Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework.
Meta also provides EU Standard Contractual Clauses and thereby offers an additional guarantee of compliance with European data protection law. The existing EU Standard Contractual Clauses remain valid after the adequacy decision has entered into force.
Further information can be found HERE. You can also contact the provider directly.
4.5 Legal Bases
If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party and the interests, fundamental rights and freedoms of the data subject do not override the aforementioned interest, Art. 6(1) lit. f GDPR is the legal basis for the processing. We consider our legitimate interest in data processing to be the presentation of our company and our products and services for your information and, in particular, the provision of modern means of communication for and with you.
4.6 Joint Controllers
Midea Europe GmbH
Ludwig-Erhard-Str. 14
65760 Eschborn
and
Meta Platforms Ireland Limited
4 Grand Canal Square, Grand Canal Harbour
D2 Dublin
Ireland
In the opinion of the European Court of Justice (ECJ), we are jointly responsible with Facebook for the processing of your personal data.
With regard to joint controllership, pursuant to Art. 26 GDPR, we inform you below of the essence of the joint controllership arrangement between us and Facebook: Facebook Page Controller Addendum.
5. Facebook Connect
We offer you the option of using Facebook Connect and registering and logging in via your Facebook account. If you register via Facebook, Facebook will ask you for your consent to release certain data from your Facebook account to us. This may include your first name, last name and email address in order to verify your identity and gender, as well as your general location, a link to your Facebook profile, your time zone, your date of birth, your profile picture, your “Likes” and your friends list.
This data is used to set up, provide and personalize your account.
This data is collected by Facebook and transmitted to us in compliance with the provisions of Facebook’s Data Policy. You can control the information we receive from Facebook via the privacy settings in your Facebook account.
Insofar as data is processed in the United States of America (USA), Meta Platforms, Inc. has certified itself under the Data Privacy Framework (DPF) program and is listed on the Data Privacy Framework List of the International Trade Administration (ITA). This means that Meta has publicly committed to complying with the DPF obligations and that any transfer of data to the USA is unobjectionable on the basis of the current adequacy decision of the European Commission dated July 10, 2023.
A list of currently certified US companies can be found here: Data Privacy Framework Participant Search. Further information on the Data Privacy Framework program can be found on the official ITA website: Data Privacy Framework.
Meta also provides EU Standard Contractual Clauses and thereby offers an additional guarantee of compliance with European data protection law. The existing EU Standard Contractual Clauses remain valid after the adequacy decision has entered into force.
For further information on security measures, please refer to the privacy policy of the respective provider or contact the provider directly.
If you register with us via Facebook, your account will automatically be linked to your Facebook account and information about your activities on our websites may be shared on Facebook and published in your timeline and your friends’ news feeds.
The legal basis for this data processing is your consent, Art. 6(1) lit. a GDPR. You can withdraw your consent at any time with effect for the future by opening the privacy settings at the bottom left in the footer of our website (“Cookie Settings”) and adjusting the corresponding slider.
Privacy Notice for Sales Promotions and Competitions
For the implementation of sales promotions and competitions, it is necessary for Midea Europe GmbH and the commissioned service provider to store personal data (name, email address, address) in order to draw the winners or register participants and provide them with the prizes. Data is stored exclusively for the purpose of determining winners and participants. Processing is carried out only by Midea Europe GmbH and the commissioned service providers and is disclosed only between these parties. The legal basis for the processing of the data is Art. 6(1) lit. a and b GDPR. Midea Europe GmbH and the commissioned service providers do not disclose data to third parties. All data will be deleted after the competition or sales promotion has ended.
The participant may withdraw their consent to the processing of the data at any time, including during the competition or sales promotion period, by email to info-meg@midea.com. Midea Europe GmbH and the commissioned service providers will then delete the data without undue delay. If data is deleted before the end of the competition, the person concerned will no longer be able to participate. The participant has the right to access their personal data at any time, the right to rectification, the right to erasure, the right to restriction and the right to data portability. Reference is made to the right to lodge a complaint with the competent supervisory authority (poststelle@datenschutz.hessen.de – The Hessian Commissioner for Data Protection and Freedom of Information, 65189 Wiesbaden). The controller within the meaning of the GDPR is Midea Europe GmbH, Ludwig-Erhard-Str. 14, 65760 Eschborn. The Data Protection Officer can be contacted at DSB-Midea_Europe@intersoft-consulting.de.
Seminar Booking – Midea HVAC Academy
Booking seminars via the Midea HVAC Academy website requires registration. As part of the registration process, you will be asked to provide the following personal data: title, last name, first name, email address, telephone number. This information is required for booking our products and for related communication. The legal basis for the processing of this personal data is Art. 6(1) sentence 1 lit. b GDPR (necessity for the performance of a contract).
Disclaimer
The Midea Europe GmbH website has been compiled with the greatest possible care and is regularly reviewed and updated. Midea Europe GmbH does not guarantee the timeliness, accuracy, completeness and/or quality of the information on these pages. The website contains links to external third-party websites over whose content Midea Europe GmbH has no influence. Therefore, no guarantee or liability is assumed for such third-party content and functions.
All content, such as texts, images, audio, video and animation files, as well as their arrangements, is protected by copyright and other intellectual property laws. Reproduction, editing, distribution and any form of exploitation of the content of this website may not be carried out for commercial purposes unless expressly indicated otherwise or Midea Europe GmbH has given its written consent.