Principles of data processing at Ypsilon.Net AG

You have come to this page via a link because you want to find out how we handle (your) personal data. In order to fulfil our information obligations under Art. 12 ff. of the General Data Protection Regulation (GDPR), we would like to present our information on data protection below:

Who is responsible for data processing?

The responsible party within the meaning of data protection law is

Ypsilon.Net AG
Vilbeler Landstraße 203
60388 Frankfurt a.M.

You can find further information about our company, details of the authorized representatives and other contact options in the imprint of our website: https://www.ypsilon.net/impressum

Which of your data do we process? And for what purposes?

If we have received data from you, we will generally only process it for the purposes for which we received or collected it.

Data processing for other purposes will only be considered if the necessary legal requirements in accordance with Art. 6 Para. 4 GDPR are in place. In this case, we will of course observe any information obligations in accordance with Art. 13 Para. 3 GDPR and Art. 14 Para. 4 GDPR.

What is the legal basis for this?

The legal basis for the processing of personal data is generally - unless there are specific legal provisions - Art. 6 GDPR. The following options in particular come into consideration here:

  • Consent (Art. 6 Para. 1 lit. a) GDPR)
  • Data processing to fulfill contracts (Art. 6 Para. 1 lit. b) GDPR
  • Data processing based on a balance of interests (Art. 6 Para. 1 lit. f) GDPR)
  • Data processing to fulfill a legal obligation (Art. 6 Para. 1 lit. c) GDPR)

If personal data is processed on the basis of your consent, you have the right to revoke your consent at any time with effect for the future.

If we process data on the basis of a balance of interests, you as the data subject have the right to object to the processing of personal data, taking into account the requirements of Art. 21 GDPR.

How long will the data be stored?

We process the data as long as it is necessary for the respective purpose.

If there are statutory retention periods - e.g. in commercial or tax law - the personal data in question will be stored for the duration of the retention period. After the retention period has expired, a check will be carried out to determine whether further processing is necessary. If the data is no longer necessary, the data will be deleted.

As a general rule, towards the end of each calendar year we check data to see whether further processing is necessary. Due to the volume of data, this check is carried out with regard to specific data types or purposes of processing.

You can of course request information about the data we have stored about you at any time (see below) and, if there is no longer any need, request that the data be deleted or processing restricted.

To which recipients will the data be passed on

As a general rule, your personal data will only be passed on to third parties if this is necessary for the performance of the contract with you, if the transfer is permissible on the basis of a balance of interests within the meaning of Art. 6 (1) (f) GDPR, if we are legally obliged to pass the data on or if you have given your consent to do so.

Where is the data processed?

We process your personal data exclusively in data centers in the Federal Republic of Germany.

Your rights as a “data subject”

You have the right to information about the personal data we process about you.

If you do not request information in writing, we ask for your understanding that we may then require evidence from you that proves that you are the person you claim to be.

You also have the right to rectification or erasure or to restriction of processing, insofar as you are legally entitled to this. You also have the right to object to processing within the framework of the statutory requirements. The same applies to the right to data portability.

In particular, you have the right to object to the processing of your data in connection with direct advertising in accordance with Art. 21 (1) and (2) GDPR if this is done on the basis of a balance of interests.

Our data protection officer

We have appointed a data protection officer in our company. You can reach her using the following contact options:

Günther Rams
DEBIT Computer Service GmbH
Seestraße 11
63571 Gelnhausen
E-Mail: datenschutz@ypsilon.net

Right to complain

You have the right to complain to a data protection supervisory authority about our processing of personal data.

  

Status: 30.10.2018