Information on Data Privacy Statement

Data Privacy Statement

1. Generalities
1.1 Personal Data (Article 4(1) GDPR)

The subject matter of the data protection is the personal data (hereinafter also referred as data). Personal data mean all information relating to an identified or identifiable natural person. These concern in particular data such as last name, address, occupation, e-mail address, state of health, income, marital status, genetic characteristics, phone number and possibly user data such as IP address.

1.2 Controller (Article 4(7) GDPR)
The controller responsible for the processing of your personal data in connection with the use of the application SMARTCRM (hereinafter referred as application) is SMARTCRM GmbH (hereinafter referred as operator or controller). The contact details are:

SMARTCRM GmbH
Georg-Todt-Straße 1
76870 Kandel
Germany

Managing director: Ralph Rastert
Phone: +49 7275 988660
Fax: +49 7275 98866-64
E-mail: info@smartcrm.de

1.3 Data Protection Officer
The controller has appointed an external data protection officer. The data protection officer can be reached under the e-mail address datenschutz@m-consecom.de.

1.4 Right to Object
If you wish to object the processing of your data by the operator in accordance with this data privacy statement as a whole or for individual measures, you can do so under the contact details specified in the imprint. Please note that in case of such an objection the use of the application and the retrieval of the offered services may be limited or not possible at all.

2. Scope and Purpose of Data Processing, Legal Bases, Provision of Data and Duration of Storage

2.1 Use of the Application
When downloading the application, information such as user name, customer number, e-mail address, time of the download, payment details and the device code number are transferred to the store. The store operator is responsible for this data collection. When using the application, following data, which are necessary for the use of the application are collected:

  • IP address
  • Date and time of the request
  • Transmitted data volume
  • Operating system
  • User agent
  • Sequential number
  • Location (when shared)

The admissibility of this processing is governed by Article 6(1)(b) GDPR, according to which the processing is lawful if it is necessary for the performance of a contract of which the data subject is a party or if pre-contractual measures are taken at the request of the data subject. The data processed by the operator are required by the operator in order to enable you to access and use the application. These are data that must be processed while using a telecommunication and electronic media. Otherwise, you cannot start the application.

Following data are collected for carrying out an error analysis.

  • User ID
  • User sequential number
  • Registered devices
  • Running sessions
  • Server activities
  • Error report
  • User Agent
  • Sequential number
  • Location (if shared)

The admissibility of this processing is governed by Article 6(1)(b) GDPR, according to which the processing is lawful if it is required for the protection of the legitimate interest of the controller or a third party and provided that the interests or fundamental rights and basic freedom of the data subject, who requires the protection of personal data, do not prevail. The legitimate interest of the operator lies in providing an application with information and in offering services to its customers as well as in optimizing the application and the quick troubleshooting.

The data are deleted after four weeks.

2.2 Advertising
The operator uses your data on promotional purposes. The admissibility of this processing is governed by Article 6(1)(f) GDPR, according to which the processing is lawful if it is necessary to safeguard the legitimate interest of the controller or a third party and provided that the interests or fundamental rights and basic freedom of the data subject, who requires the protection of personal data, do not prevail. The use of data for advertising purposes constitutes a legitimate interest of the operator within the meaning of Article 6(1)(f) GDPR. The operator is required to actively present his services to new and existing customers.

The personal data processed for advertisement will be deleted unless the controller has a legitimate interest in keeping the data for a longer period. In any event, only data required to achieve the specific purpose will be stored.

3. Right of Access, Right to Rectification, Right to Erasure, Right to Restriction of Processing, Right to Object and Right to Data Portability

3.1 Right of Access (Article 15 GDPR)
You shall have the right to obtain from the operator the confirmation as to whether or not your personal data are being processed. The operator strives toward replying to such request for information as soon as possible.

3.2 Right to Rectification (Article 16 GDPR)
You shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning you.

3.3 Right to Erasure (Article 17 GDPR)
You shall have the right to obtain from the controller the erasure of personal data without undue delay and the controller is obliged personal data to erase without undue delay provided that one of the grounds pursuant to Article 17(1)(a-f) GDPR is met.

3.4 Right of Restriction of Processing (Article 18 GDPR)
You shall have the right to obtain from the controller restriction of processing where one of the requirements pursuant to Article 18 (1)(a-d) applies.

3.5 Right to Object (Article 21 GDPR)
You shall have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you pursuant to Article 6(1)(e)(f), including profiling based on these provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing, which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
Where personal data are processed for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning you for such marketing; this applies to profiling to the extent that it is related to such direct marketing.

Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89 (1) GDPR, on grounds relating to your particular situation, you shall have the right to object to processing of personal data concerning you unless the processing is necessary for the performance of a task carried out for reasons of public interest.
For your notification, please use the contact address given in the imprint.

3.6 Right to Data Portability (Article 20 GDPR)
You shall have the right to receive your personal data which you have provided to the controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which personal data have been provided where the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) or on a contract pursuant to Article 6(1)(b) and the processing is carried out by automated means.

4. Withdraw your consent

If you have given your consent to the processing of your personal data and revoke it, the lawfulness of processing based on this consent before its withdraw shall not be affected.

5. Right to lodge a complaint with a supervisory authority
You shall have the right to lodge a complaint with a supervisory authority at any time.

6. Recipients

The data collected during the access and the use of the application and the data you provided from the first contact shall be transmitted to the server of the operator and stored there. Apart from that, your data may be disclosed to the following categories of recipients:

  • Person employed by the controller, who is involved in the processing (i.e., customer support, development department)
  • Processor (i.e.,  data center, software support)
  • Contractor of the operator (i.e., banks)