Data Protecion and Privacy Policy


Thank you very much for visiting our website or for otherwise getting in contact with us.

We place very high value on the protection of personal data. In principle, it is possible to use this website without handing over any personal data. However, if you would like to make use of an offer from our company online, then it may be necessary to process personal data. If it does prove necessary to process personal data and if there is no legal basis for this processing, then we will generally obtain consent from the data subject.

Processing of a data subject’s personal data, for instance their name, address, e-mail address or telephone number, shall always be carried out in compliance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable data protection regulations, in particular the Telecommunications Digital Services Data Protection Act (TDDDG), where applicable.

With this data privacy statement, our company endeavours to provide information about the nature, scope and purpose of the personal data we process and to inform data subjects of their rights.

Our company has implemented numerous technical and organisational measures for the data collected in order to ensure as complete protection as possible for the personal data that is processed. Nevertheless, internet-based data transfers may have flaws in security and as such, absolute protection cannot be guaranteed.

1.     Definitions
Our company’s data privacy statement is based on the GDPR. Our data privacy statement should be easily readable and comprehensible. In order to ensure this, we shall first define the terms used.

1.1.     Personal data
Personal data refers to “any information relating to an identified or identifiable natural person (hereinafter referred to as ‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors that are specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” (article 4, section 1 of the GDPR). 

1.2.     Data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the person responsible for data processing. 
1.3.     Processing
Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. 

1.4.     Restriction of processing
Restriction of processing refers to the marking of stored personal data with the aim of limiting its processing in the future. 

1.5.     Profiling
Profiling is any form of automated processing of personal data in which this personal data is used in order to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. 

1.6.     Pseudonymisation
Pseudonymisation refers to processing personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information. This additional information is kept separately and is subject to the technical and organisational measures, thus guaranteeing that the personal data is not attributed to an identified or identifiable natural person. 

1.7.     Controller or person responsible for processing
The controller or person responsible for processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. 

1.8.     Processor
The processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. 

1.9.     Recipient
The recipient is a natural or legal person, public authority, agency or another body, to which the personal data is disclosed, regardless of whether this is a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients. 

1.10.  Third parties
A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data. 

1.11.  Consent
Consent of the data subject is any freely given, specific, informed and unambiguous indication of the data subject’s wishes in the form of a declaration or other clearly verified deed with which the data subject signifies agreement to the processing of personal data relating to him or her.   

 2.     Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the Member States as well as other applicable data protection regulations is:

mse e2e solutions GmbH
Koppstr. 16
81379 München
Germany
Tel.: +49 174-2 67 62 52
E-mail: contact@mse-e2e.com
Website: https://www.plugnplan.ai   

3.     Data Protection Officer

For questions or comments regarding data protection, our Data Protection Officer can be contacted as follows:

BCCO GmbH
Hermann-Köhl-Straße 14
93049 Regensburg
Germany
Tel.: +49 941 69800800
E-mail: datenschutz@bcco.de

4.     Provision of Website
4.1.     Every time you visit our webpage, our system automatically gathers data and information from the system of the accessing computer.

Following data is collected here:·       

·       the user’s operating system        
·       the user’s internet service provider        
·       the user’s IP-address        
·       date and time of access        
·       websites that direct the user's system to our website     
·       websites accessed by the user's system from our website
·       files retrieved        
·       quantity of data sent

The legal basis for the temporary storage of data is Art. 6 (1) (f) of the GDPR

4.2. The temporary storage of the IP address by the system is required so that the website can be connected to the user’s computer. For this purpose, the IP address of the user must be saved for the duration of the web session. For this purpose, our legitimate interest is in accordance with Art. 6 (1) (f) of the GDPR.

4.3. Data will be deleted as soon as it is no longer required for the purpose for which it was collected. In the event of collecting data to ensure the website is functioning correctly, this is the case once the relevant session has ended.

4.4. The collection of data for providing the website is absolutely necessary for the website to operate and therefore the user has no right to object.

5. Logfiles
5.1. The data is also stored in our system’s log files. This data is stored separately from the user’s personal data. The legal basis for the creation of log files is Art. 6 (1) (f) of the GDPR.

5.2. Storage takes place in log files to ensure that the website is functioning correctly. Furthermore, the data allows us to optimise the website and to guarantee the security of our information technology systems. The data is not evaluated for marketing purposes in this context. For this purpose, our legitimate interest in data processing corresponds with Art. 6 (1) (f) of the GDPR.

5.3. The data in the log files is deleted after seven days at the latest. However, data may be stored for periods extended beyond this. In such cases, the users’ IP addresses are deleted or altered, meaning that the IP address can no longer be traced back to the respective client.

5.4. The storage of data in log files is absolutely necessary to ensure that the website is fully operational. As such, users have no right to object.

6. Cookies
6.1. Our website uses cookies.
Cookies are text files that are stored in your browser or on the user’s computer system by the internet browser. If a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a unique character sequence that enables a unique identification of the browser when the user reconnects to the website.The following information may be stored and transmitted via cookies:
·        cookie settings and consent preferences
·        technical information required for website functionality

We also use cookies and similar technologies for analytics purposes, provided that you have given your consent. Details regarding the analytics services used can be found in the corresponding sections of this Privacy Policy.

6.2. The legal basis for the processing of personal data by means of technically necessary cookies is Art. 6 (1) lit. f GDPR. Cookies and similar technologies that are not technically necessary are only used on the basis of your consent pursuant to Art. 6 (1) lit. a GDPR. The storage of or access to information on your terminal device is carried out in accordance with Section 25 TDDDG.

6.3. We use cookies in order to simplify website use for our users. Analysis cookies are used to improve the quality of our website so that we can continuously optimise our offer in line with the knowledge we gain about precise use of the website. In this context, our legitimate interest in processing personal data also corresponds with Art. 6 (f) of the GDPR.

6.4. Cookies are stored on the user’s computer and sent from there to our website. Therefore, as the user you have full control over the use of cookies. You can limit or deactivate the transmission of cookies by changing the settings in your internet browser. Previously stored cookies can be deleted at any time. This can also be done automatically. If you choose to deactivate cookies for our website, you may no longer be able to use the full range of functions on the site.

7. The Real Cookie Banner
Description and scope of data processing
When you visit our website for the first time, a pop-up window appears providing information about cookies and similar technologies. Through this consent banner, you can decide whether you wish to consent to the use of services requiring your consent.
By clicking “Accept all”, you consent to the use of the selected services. If you click “Continue without consent”, only technically necessary services will be used.

We use The Real Cookie Banner, a consent management solution provided by

devowl.io GmbH,
Tannet 12, 94539 Grafling, Germany,
to manage your consent.

The Real Cookie Banner sets a technically necessary cookie (real_cookie_banner-*) to store your consent preferences and to document whether consent has been granted or refused. In particular, your selected preferences, the date and time of your decision, and technical information required to document your consent are processed. Your consent decision is not transferred to devowl.io GmbH.

Further information on data protection at The Real Cookie Banner is available at:https://devowl.io/privacy-policy/

Legal basis for data processing
The legal basis for the use of the consent management platform is Art. 6 (1) lit. c GDPR. The storage of technically necessary information on your terminal device is carried out in accordance with Section 25 (2) No. 2 TDDDG.

Purpose of data processing
The purpose of the processing is to obtain and document your consent for the use of services requiring consent and to enable you to modify or withdraw your consent at any time with effect for the future.

Storage period, objection and removal options
Your consent decision will be stored for one year.You can change or withdraw your consent at any time with effect for the future via the “Your Consent” link or by accessing the cookie settings on our website.
Alternatively, you may delete the real_cookie_banner-* cookie at any time via your browser settings. If you revisit or reload our website afterwards, you will be asked to provide your consent again.

8. Wordfence
Description and scope of data processing

We use Wordfence, a security solution provided by

Defiant, Inc.,
1700 Westlake Ave N Ste 200,
Seattle, WA 98109, United States,

to protect our website against unauthorized access, cyberattacks, malware and brute-force attacks.

Wordfence may process personal data, in particular your IP address and technical metadata, in order to detect and prevent security threats. Depending on the configuration of the service, technically necessary cookies may also be set to support security-related functions, for example to recognize authenticated WordPress users, detect suspicious login attempts or enable access despite regional restrictions.

Further information on data protection at Wordfence can be found at:https://www.wordfence.com/privacy-policy/

Legal basis for data processing
The processing of personal data in connection with the use of Wordfence is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR. Our legitimate interest lies in ensuring the security, integrity and availability of our website and in protecting it against unauthorized access and malicious attacks.Where technically necessary cookies are stored or information is accessed on your terminal device, the legal basis is Section 25 (2) No. 2 TDDDG.

Transfer to third countries
When using Wordfence, personal data may be transferred to the United States. According to the information provided by the provider, appropriate safeguards within the meaning of Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses, are used for such transfers.

Purpose of data processing
The purpose of the processing is to detect and prevent security incidents, protect our website against cyberattacks and unauthorized access, and ensure the secure operation of our website.

Storage period, objection and removal options
Personal data processed in connection with Wordfence is stored only for as long as necessary to fulfil the respective security purpose or as required by statutory retention obligations.

As the processing is necessary to ensure the secure operation of the website, you generally cannot object to this processing while using the website.

9. Contact by e-mail
Description and scope of data processing
You can contact us via the provided e-mail address. In this case, the personal data transmitted with the e-mail will be stored.

In this context, no data will be transferred to third parties. The data will be used exclusively for processing the conversation.

Legal basis for data processing
The legal basis for the processing of data transmitted in the course of sending an e-mail is Art. 6 (1) lit. f GDPR. If the purpose of the e-mail contact is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
In the case of contacting us by e-mail, this also constitutes the necessary legitimate interest in the processing of the data.

Purpose of data processing
The processing of personal data transmitted via e-mail depends on the sender’s request and serves exclusively to process and respond to this request.This also constitutes the necessary legitimate interest in the processing of the data.

Storage period, objection and removal options
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data transmitted by e-mail, this is the case when the respective conversation with the user has ended. The conversation is considered ended when it can be inferred from the circumstances that the matter concerned has been conclusively resolved.
If the user contacts us by e-mail, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.
All personal data stored in the course of contacting us will be deleted in this case.

10.  Matomo Cloud Description and scope of data processing 

We use the web analytics service Matomo Cloud (formerly Piwik) provided by

InnoCraft Ltd.,
150 Willis St,
6011 Wellington, New Zealand,

on our website.
Matomo Cloud is a cloud-based Software-as-a-Service (SaaS) solution that enables us to statistically record and analyze the use of our website. The technical provision, storage and processing of the analytics data is carried out via the cloud infrastructure provided by InnoCraft Ltd.

After you have given your consent, Matomo uses cookies that are stored on your device and enable us to analyze the use of our website.

In this context, the following information in particular may be processed:

·        shortened/anonymized IP address,
·        date and time of access,
·        pages accessed,
·        time spent on the website,
·        referrer URL,
·        browser and operating system used.

We shorten and anonymize IP addresses before they are stored in order to protect your privacy. The anonymized IP address cannot be used to identify you as a user.

The collected data is used exclusively for statistical purposes and serves to optimize our website and its content.

We have concluded a data processing agreement with InnoCraft Ltd. pursuant to Art. 28 GDPR. 

Legal basis for data processing
The processing is carried out exclusively on the basis of your consent pursuant to Art. 6 (1) lit. a GDPR. The storage of cookies or access to information on your device is carried out on the basis of your consent pursuant to Section 25 (1) TDDDG.You can withdraw your consent at any time with effect for the future by deactivating the corresponding category in the privacy settings of this website. 

Transfer to third countries
When using Matomo Cloud, a transfer of personal data to New Zealand may occur. An adequacy decision by the European Commission pursuant to Art. 45 GDPR exists for New Zealand. 

Purpose of data processing
The use of Matomo serves the statistical analysis of user behavior, the improvement of our website and the optimization of user-friendliness. 

Storage period, objection and removal options
You can withdraw your consent at any time with effect for the future via the privacy settings on our website.
Furthermore, you can prevent the storage of cookies by selecting the appropriate settings in your browser software.
Further information on data protection in connection with Matomo can be found at:
https://matomo.org/privacy/

11. Leadfeeder
Description and scope of data processingWe use the Leadfeeder Website Tracker, a service provided by

Dealfront Group GmbH,
Durlacher Allee 73,
76131 Karlsruhe,
Germany,


to identify companies that visit our website and to better understand the interest in our products and services.

According to the current implementation, we use the Leadfeeder Light version, which identifies companies based on IP addresses. The service is used exclusively to identify business visitors to our website. Any subsequent sales or marketing activities are carried out independently of Leadfeeder.

Depending on the visit, the following data may be processed in particular:
· IP address
· Company information derived from the IP address
· Date and time of the website visit
· Pages visited
· Technical information relating to the website visit

Further information on the processing of personal data by Dealfront can be found at: https://www.dealfront.com/privacy-notice/

Legal basis for data processing
The processing is carried out on the basis of Art. 6 (1) lit. f GDPR.Our legitimate interest lies in identifying companies interested in our products and services, analysing the use of our website by business visitors and optimising our sales and marketing activities.

Purpose of data processingThe processing serves to:· identify companies visiting our website;· analyse interest in our products and services;· support our business development and marketing activities.

Recipients and transfer to third countriesThe service is provided by Dealfront Group GmbH. Further information regarding recipients, subprocessors and possible transfers to third countries can be found in the provider's privacy information.

Storage period, objection and removal optionsPersonal data is stored only for as long as necessary to fulfil the above purposes or as required by statutory retention obligations.You have the right to object to the processing of your personal data based on Art. 6 (1) lit. f GDPR at any time for reasons arising from your particular situation pursuant to Art. 21 GDPR.


12. Our social media presence / channels

12.1 We maintain an online presence on social media platforms. Our social media presence is operated on the following platform:LinkedIn

Information regarding the provider, the URL of our presence on the platform and information on data protection can be found under the corresponding links to our social media channels.

12.2. For this information service, we use the technical platform and services provided by LinkedIn. Please note that you use our LinkedIn presence and its functions at your own responsibility. This applies in particular to the use of interactive functions (e.g. commenting, sharing, rating).When you visit our LinkedIn presence, LinkedIn may collect your IP address and other information stored on your device in the form of cookies. This information is used, among other things, to provide us, as the operator of the account, with statistical information about interactions with our LinkedIn presence.

12.3. The data processed about you in this context is processed by LinkedIn and may be transferred to countries outside the European Union, in particular the USA.
The information collected may also be stored on LinkedIn servers outside Europe. For such cases, LinkedIn has certified itself under the EU-U.S. Data Privacy Framework.We do not know in detail how LinkedIn uses the data collected from your visit to our presence and your interaction with our posts for its own purposes, how long this data is stored or whether data is passed on to third parties.The data processing may differ depending on whether you are registered and logged into LinkedIn or whether you visit our presence as a non-registered and/or non-logged-in user.

When accessing our LinkedIn presence or individual posts, the IP address assigned to your device is transmitted to LinkedIn. If you are logged into your LinkedIn account, LinkedIn may be able to track your usage behavior and assign this information to your personal profile. If you wish to avoid this, you should log out of your LinkedIn account, deactivate the “stay logged in” function, delete the cookies stored on your device and restart your browser.

12.4. As the provider of this information service, we only process data from your use of our LinkedIn presence that you provide to us and that requires interaction with us.
For example, if you ask us a question that we can only answer by e-mail, we will store your information in accordance with the general principles of data processing described in this Privacy Policy.The legal basis for processing your data in connection with our LinkedIn presence is Art. 6 (1) sentence 1 lit. f GDPR.

12.5. To exercise your data subject rights, you may contact either us or LinkedIn. If one party is not responsible for responding to your request or requires information from the other party, we or LinkedIn will forward your request to the respective party.
For questions regarding profiling or the processing of your data when using LinkedIn, please contact LinkedIn directly. For questions regarding the processing of your interaction with us via our LinkedIn presence, please contact us using the contact details provided above.

12.6. Information on which data LinkedIn receives and how this data is used can be found in LinkedIn’s Privacy Policy. There you will also find information about contact options and settings for advertisements.
Further information on social networks and how you can protect your data can also be found at:
www.youngdata.de

13. Data subject rights 
Where required by law, you have certain rights as a data subject regarding the processing of your personal data. We would like to inform you about your data subject rights and how you can exercise them: 

Right of access (Art. 15 GDPR):
You have the right to request information from us about which personal data we process about you and for what purpose. If you submit a request for information that is not made in writing via a contact address already stored in our systems, we ask for your understanding that we may request proof from you to verify that you are the person you claim to be. 

Right to rectification (Art. 16 GDPR) or erasure (Art. 17 GDPR):
You have the right to have inaccurate or incomplete personal data stored by us corrected or deleted if it is no longer required or if the processing violates data protection regulations. 

Right to restriction of processing (Art. 18 GDPR):
You have the right to request the restriction of the processing of your personal data if you contest the accuracy of the data, the processing is unlawful, or you have objected to the processing. 

Right to withdraw your declaration of consent under data protection law (Art. 7 (3) GDPR):
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. 

Right to data portability (Art. 20 GDPR):
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format and to transmit this data to another controller.
We do not use automated processing involving profiling. 

Right to lodge a complaint (Art. 77 GDPR):
You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. We expressly inform you that you have the right to:  

Object to processing 
You have the right to object to processing (Art. 21 GDPR) if the data processing is carried out on the basis of a legitimate interest and there are reasons arising from your particular situation that speak against the data processing.
We reserve the right to review your particular situation and the corresponding data processing.

If data processing is carried out on the basis of our legitimate interest for the purpose of direct marketing, you may object to the processing at any time without providing reasons. 

 Procedure for exercising data subject rights 
If you exercise your rights towards us, we will process the data transmitted to us in this context in order to fulfil your request.
After fulfilling your request, we will store the data transmitted by you to us and the data transmitted by us to you in response for documentation purposes until the expiry of the limitation period for administrative offences (3 years).