Data protection information for the JUMO smartCONNECT app

WE ARE COMMITTED TO YOUR DATA PROTECTION

Name and address of the data controller

The data controller is the entity which, solely or together with other parties, makes decisions on the purposes and means of the processing of personal data. The data controller pursuant to the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is:

JUMO GmbH & Co. KG
Dr. Steffen Hossfeld
Moritz-Juchheim-Straße 1
36039 Fulda
Germany
Tel.: +49 661 6003-0
Email: mail@jumo.net
Website: www.jumo.de

Contact details of the external data protection supervisor

We have appointed an external data protection supervisor:

BerIsDa GmbH | Website: http://www.berisda.de

You can contact the data protection supervisor via mail at JUMO GmbH & Co. KG, Attn: Data Protection Supervisor, Moritz-Juchheim-Straße 1, 36039 Fulda, Germany, or via email at datenschutz@berisda.de

I. General information about data processing

1. Scope of processing of personal data

The data controller shall strictly only collect and use the personal data of its users (also referred to as "data subject" or "visitor" below) insofar as this is required to provide a functional app and to display the content and services. A user's personal data shall only be collected and processed for other purposes with the user's consent. An exception shall apply in cases in which prior consent cannot be obtained for practical reasons, the processing takes place based on precontractual or contractual measures, the processing of data is permitted by law, and/or the data controller has a legitimate interest in processing.

Your personal data shall always be collected directly from you, for example if you contact us, consent to services in this app, or use forms in this app. Furthermore, technical data that is strictly necessary to run the app shall be recorded automatically during installation and use of the app.

Insofar as the data controller obtains consent from the data subject for the processing of personal data, Art. 6(1)(1)(a) of the EU General Data Protection Regulation (GDPR) shall serve as the legal basis for processing personal data. Insofar as special data categories are processed according to Art. 9(1) GDPR, Art. 9(2)(a) GDPR shall be considered as the legal basis. Processing shall take place based on Art. 49(1)(1)(a) GDPR in the case of any transmission to an unsecure third country. Insofar as you have consented to the storage of cookies or information being accessed on your end device, data processing shall also take place based on Art. 25(1) TTDSG.

Art. 6(1)(1)(b) GDPR serves as the legal basis for processing the personal data required for the fulfillment of a contract in which the data subject is a contractual party. This also applies to processing operations that are required to carry out pre-contractual measures.

Art. 6(1)(1)(c) GDPR serves as the legal basis insofar as processing of personal data is required for the fulfillment of a legal obligation to which the data controller is subject.

Art. 6(1)(1)(d) GDPR serves as the legal basis in the event that the vital interests of the data subject or another natural person require the processing of personal data.

Art. 6(1)(1)(f) GDPR serves as the legal basis for processing if processing is required to safeguard a legitimate interest of the data controller or a third party and if the interests, fundamental rights, and freedoms of the data subject do not outweigh the first-mentioned interest.

3. Data erasure and duration of processing

If a precise storage duration is not specified within this data protection information, we shall retain our app users' personal data until the purpose of data processing ceases to apply. The personal data of the data subject shall be deleted or blocked as soon as the purpose of storage ceases to apply or the consent granted by the data subject is revoked, or processing is objected to. Data may be stored beyond this period if this has been foreseen by the European or national legislator in EU regulations, laws or other provisions to which the data controller is subject. The data shall also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of data for the conclusion or fulfillment of a contract.

4. Transmission of data to a third country or international organization

The European General Data Protection Regulation (GDPR) assumes that the transmission of personal data, whether it is already being processed or it is intended to be processed after its transmission to a third country or an international organization, is only admissible if a level of data protection comparable with the specifications of the GDPR is ensured. It is therefore ensured that the provisions of the GDPR are adhered to – the presence of an adequacy decision from the EU Commission pursuant to Art. 45(1) and (3) GDPR or the introduction of internal company data protection regulations approved by a supervisory authority (so-called "appropriate safeguards", Art. 46(2) and (3) GDPR) can count toward this, for example. If a data protection level comparable with the standards of the GDPR is not provided, there may be risks involved in processing in a third country.

Risks of transmission to an unsecure third country: The provider may possibly transmit personal data to another third party (which uses the data for advertising purposes, for example) for a purpose which goes above and beyond order fulfilment. The data subject will also probably not be able to effectively assert any data subject rights vis-à-vis the provider. There may be a higher probability of incorrect data processing occurring, as the provider's technical and organizational measures to protect personal data do not fully meet the requirements of the GDPR qualitatively and quantitatively. It may also be the case that governmental bodies access the provided personal data without the data subject being aware of it. In principle, this also conforms with European legal regulations, for example for the purpose of averting hazards. However, the threshold for permissibility of this type of data processing is higher in the European Union than in the respective country of the data recipient. In summary, the level of data protection in unsecure third countries is not comparable with the standards of the GDPR.

In our app, we use features including tools from providers who have their corporate headquarters or their parent company's corporate headquarters (or their affiliated companies) in a third country from a data protection perspective. We also transmit data to the USA. The transmission of data to the USA is admissible if the recipient is certified under the "EU-US Data Privacy Framework" (DPF) or has appropriate additional safeguards in place. The DPF is an (individual) agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards during data processing in the USA. Each company certified according to the DPF undertakes to adhere to these data protection standards. If data is transmitted to a provider which is certified according to the DPF, the respective service provider provides a separate notice.

5. Necessity of providing personal data

In principle, you are neither legally nor contractually obligated to provide your personal data. No obligation to provide it exists. However, if the data is not provided, this may mean that you cannot use functions, services, forms, and other data processing options in our app. We recommend that you only provide the personal data that is required to process your request, carry out your requested service, and to use the functions we offer. If you are required to provide your personal data for legal or contractual reasons, we shall inform you of this fact by providing a separate notice for the respective processing in this data protection information.

The recording of technical data (and possibly the recording of your IP address as personal data) in order to provide the app and store data in log files is strictly necessary to run the app and is carried out automatically when this app is used. If you do not want your data to be recorded, you must close or uninstall the app.

II. Rights of the data subject

If we process your personal data, you as the data subject have the following rights vis-à-vis us as the data controller:

1. Right of access, Art. 15 GDPR

Within the applicable legal provisions, you have the right at any time to request (free of charge) access to your collected and stored personal data. This also includes access to the purposes of its processing, its origin and recipients, the storage duration, and the existence of various rights.

2. Right to rectification, Art. 16 GDPR

You have a right to rectification (including to completion) of your data vis-à-vis the data controller if the personal data processed concerning you is incorrect or is incomplete for the purpose of processing. The data controller must make the rectification without delay.

3. Right to erasure, Art. 17 GDPR

Under the conditions of Art. 17 GDPR, you can request the erasure of your personal data at any time, unless certain circumstances still exist that entitle or obligate the data controller to continue to process your personal data (such as statutory retention requirements).

4. Right to restriction of processing, Art. 18 GDPR

If the legal requirements are met, you may request restriction of the processing of your personal data within the scope of Art. 18 GDPR.

5. Right to be informed, Art. 19 GDPR

If your personal data has been processed by recipients to whom the data controller has disclosed the data, the data controller is obligated to inform them about your demands with regard to rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate level of effort. You can demand that the data controller informs you about these recipients.

6. Right to data portability, Art. 20 GDPR

If you have provided personal data to us and automated processing takes place based on your consent or based on a contract, you have a right to transmission of the data you provided within the scope of Art. 20 GDPR, as long as this does not affect the rights and freedoms of other persons. It shall be provided in a common, machine-readable format. If you request the direct transmission of the data to another data controller, this shall only take place insofar as this is technically feasible.

7. Right to object, Art. 21 GDPR

You have the right to object to the processing of your data at any time, insofar as processing takes place based on balancing interests. This is the case if the data controller invokes public interest or their legitimate interest for processing (see Art. 6(1)(1)(e) and (f)). You shall be required to assert reasons resulting from your particular situation which outweigh the interest of the data controller. The data controller shall no longer process your personal data unless they can prove compelling and legitimate grounds for processing, which outweigh your interests, rights, and freedoms or the processing serves to assert, exercise, or defend legal claims.

There is a special, differing rule in Art. 21(2) GDPR if your personal data is used for direct advertising. Without any further conditions, you shall have the right to submit an objection to the processing of your personal data at any time. Your personal data shall no longer be processed for the purpose of direct advertising. If profiling is carried out in connection with direct advertising, you can also object to this.

You have the option to exercise your right of objection in connection with the use of information society services by means of automated processes using technical specifications.

8. Automated individual decision-making, Art. 22 GDPR

According to Art. 22 GDPR, you have the right not to be subject to decisions based exclusively on automated processing which have legal effect or significantly impair you in a similar manner – including profiling. Exceptions may exist if appropriate measures to protect your person are guaranteed, and there are necessary contractual rules or a legal regulation or you have expressly consented.

You have the right to revoke your declaration of consent under data protection law at any time. The legality of the data processing which has taken place until withdrawal shall remain unaffected by the withdrawal of consent. You can send the withdrawal of consent by email or mail to the data controller.

10. Right to file a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority for data protection, in particular in the member state where you are domiciled, the location of your place of work, or the location of the suspected infringement, if you believe that the processing of your personal data breaches the GDPR.

The supervisory authority responsible for us is the Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian commissioners for data protection and freedom of information). However, if you are located in a different German federal state or are not in Germany, you can also contact the data protection authority there.

III. SSL/TLS encryption

For reasons of security and to protect the transmission of confidential content such as the requests you, the data subject, send to us as the app operator, this app uses SSL/TLS encryption. You can recognize an encrypted connection by the address line in the browser switching from "http//" to "https//" and due to the lock icon in the browser line. If SSL/TLS encryption is enabled, the data you send to us cannot also be read by third parties.

IV. Provision of the app and creation of log files

1. Description and scope of data processing

Each time our app is opened, our system automatically records data and information from the system of the end device that is opening the app.

The following access rights are required here:

  • Location data
  • Bluetooth
  • NFC
  • Call
  • Internet

The following data is collected here:

  • Information about the app (version)
  • The user's operating system (incl. version)
  • The user's Internet service provider
  • The user's IP address
  • The user's network and WiFi status
  • Date and time of access

The data shall also be stored in our system's log files. This data shall not be stored together with other personal data from the user.

The legal basis for temporary storage of data and log files is Art. 6(1)(1)(f) GDPR.

3. Purpose of data processing

Temporary storage of the IP address by the system is necessary to enable the app content to be delivered to the user's device. The user's IP address remains stored for this purpose for the duration of the session.

Log files are stored in order to ensure the app functions correctly. In addition, the data is intended to help us optimize the app and ensure the security of our IT systems. The data shall not be evaluated for marketing purposes in relation to this.

These purposes constitute our legitimate interest in data processing according to Art. 6(1)(1)(f) GDPR.

4. Duration of storage, right of objection and removal

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. The data is deleted when the respective session is ended if data was recorded in order to deliver the app.

If data is stored in log files, the data is deleted after seven days at the latest. It may be stored beyond this. In this case, users' IP addresses are deleted or anonymized, meaning that the end device which used the app can no longer be assigned.

The recording of data to provide the app and store data in log files is strictly necessary to run the app. The user cannot object to this.

V. Contact by email and/or telephone

1. Description and scope of data processing

Email addresses and telephone numbers are provided in our app and signatures which can be used to make contact electronically and/or by telephone. In this case, the data subject's personal data transmitted by email is stored. If contact is made by telephone, personal data may also be stored to process your request.

In this context, the data will not be passed on to third parties. The data is used exclusively to get in contact and engage in the conversation.

The legal basis for processing data transmitted in the course of sending an email or as part of a telephone call is Art. 6(1)(1)(f) GDPR. If the aim of contact is the conclusion of a contract, then an additional legal basis for processing is Art. 6(1)(1)(b) GDPR.

3. Purpose of data processing

Personal data shall only be processed for the purpose of handling the contact request. This also constitutes the necessary legitimate interest in the processing of data.

4. Duration of storage, right of objection and removal

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data which is sent via email or transmitted via telephone, this will be carried when the respective conversation with the data subject has finished. The conversation has been ended if it can be assumed from the circumstances that the situation in question has been conclusively clarified. If the contact results in the contract being concluded, the relevant (legal) retention obligations and rules apply.

If the data subject contacts us by email or telephone, they can object to the storage of their personal data at any time. In such cases, the conversation cannot be continued. All personal data stored in the course of establishing contact shall be deleted in this case.

VI. Data permissions and installing the app

Our app is available for the Android and iOS operating systems. The respective operators of the relevant App Stores are the data controllers when it comes to the provision and processing of data when these App Stores are used:

The email address, the user name, the customer number of the account downloading the app, the individual device identifier, payment information, and the time of download may be transmitted to the respective App Store when downloading the app. We have no influence on the collection and processing of this data; rather, it is carried out exclusively by the App Store you have selected.

Data permissions are defined by your device's respective operating systems; they enable apps (such as the JUMO smartCONNECT app) to access certain data and transmit data to us or other services.

You can modify your data permissions as follows:

Advertising ID / device ID (system-wide):

  • Android: Settings > Google > Ads > Reset advertising ID
  • iOS: Settings > Privacy & Security > Tracking > Allow Apps to Request to Track

Device information / statistics / usage and diagnostics data (system-wide):

  • Android: Settings – Google – More (three-dot menu) – Usage and diagnostics
  • Android (alternatively): Settings – Privacy – Usage & diagnostics
  • iOS: Settings – Privacy & Security – Analytics & Improvements – Share iPhone & Watch Analytics

VII. App and Google Firebase

1. Description and scope of data processing

Our app uses Google Firebase technologies. The provider is Google Ireland Limited, Gordon House, Battow Street 4, Ireland (hereinafter "Google"). Google Firebase is a service which enables the use of notifications (push notifications), the creation of crash reports, and support for app installation and updating among other things. You can find more information about the functions Google Firebase offers at https://firebase.google.com/terms/.

Google Firebase services use so-called "Instance IDs". Instance IDs are unique identifiers which are given a time stamp and enable different incidents or processes in relation to the app to be linked. This data is used to analyze and optimize user behavior, for example to evaluate crash reports. According to Google, Instance IDs do not process any personally identifiable data.

You can find further information about the "Instance IDs" used and about how to manage the data concerned at: https://firebase.google.com/support/privacy/manage-iids

Information about the Google Firebase services used and data processed:

Google Firebase Cloud (Google Cloud Messaging, Google Tag Manager, Google Firebase Analytics, Google Analytics, Google AdMob):

  • Push notifications about Cloud Messaging services
  • Identifiers (device ID, app ID/installation ID, advertising ID / IDFA)
  • App state, version management

Google Crashlytics:

  • Device-specific information (e.g. model, operating system, and version number);
  • ID per installation (a random installation ID which is only valid for Firebase);
  • Rough geographical location information derived from your IP address (e.g. town/city, country);
  • Other crash-related information (e.g. date and time of the crash and crash data/logs).

Dynamic links are also used for push notifications in iOS (Apple Push Notifications).

You can find further information on data protection in Google Firebase at: https://firebase.google.com/support/privacy/

Data will be transmitted to Google servers due to the use of Google Firebase when installing and using the app.

The provider has a certification according to the "EU-US Data Privacy Framework" (DPF). You can find further information on the DPF in this data protection information under "I. General information about data processing – 4. Transmission of data to a third country or international organization". You can find further information on the provider's DPF at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active

The data is processed based on Art. 6(1)(1)(f) GDPR. The app provider has a legitimate interest; this is in the provision of the function of push notifications to send news or other messages and in the provision, troubleshooting, and assurance of the operational capability and security of the app.

3. Purpose of data processing

Google Firebase (Cloud Messaging) is used to provide and ensure the operational reliability for the app and as a service for push notifications. For the provision of the service, identifiers (device IDs) are required (Google advertising ID or IDFA) to perform the service functions. Push notifications are used to inform app users about news or other messages (including outside the app).

Google Firebase Crashlytics is used to identify and rectify problems with this app. Firebase Crashlytics helps us to collect crash-related data and device information to identify and rectify problems with the app and improve the service it provides.

We do not combine any personal data collected by Google Firebase with other personal data we have received from you for other purposes.

4. Duration of storage, right of objection and removal

Your data we have stored for Google Firebase shall be stored by us for up to 180 days and then deleted.

Data can also be used anonymized for Google Firebase for technical or statistical purposes.

You can restrict or deactivate the processing of your personal data using your device settings in the operating system. You can find more information on this in section "VI. Data permissions and installing the app" in this data protection information.

5. Concluding a contract concerning order processing

We have concluded a contract concerning order processing with Google (https://firebase.google.com/terms/data-processing-terms). This is a contract required by data protection law and ensures that Google only processes the personal data of our app users in accordance with our instructions and in compliance with data protection regulations (GDPR, BDSG, etc.).