PRIVACY POLICY

We are very pleased about your interest in our company. Data protection is of particular importance to the management of TenEntertainment GmbH i. Gr. As a rule, the websites of TenEntertainment GmbH i. Gr. can be used without providing any personal data. However, if a data subject wishes to use particular services offered by our company via our website, the processing of personal data may become necessary. Where the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data, such as the name, address, email address or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and with the country-specific data protection provisions applicable to TenEntertainment GmbH i. Gr. Through this Privacy Policy, our company informs the public about the nature, scope and purpose of the personal data we collect, use and process. It also informs data subjects about the rights to which they are entitled.

TenEntertainment GmbH i. Gr., as the controller, has implemented numerous technical and organisational measures to provide the most complete protection possible for personal data processed through this website. Nevertheless, internet-based data transmissions may in principle contain security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to provide personal data to us by alternative means, for example by telephone.

1. Definitions

This Privacy Policy is based on the terminology used by the European legislator when adopting the GDPR. It is intended to be easy to read and understand for the public as well as for our customers and business partners.

The following terms are used, among others:

a) Personal data

Any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

b) Data subject

Any identified or identifiable natural person whose personal data is processed by the controller.

c) Processing

Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing

The marking of stored personal data with the aim of limiting its future processing.

e) Profiling

Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) Pseudonymisation

Processing personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures designed to prevent attribution to an identified or identifiable person.

g) Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by that law.

2. Name and address of the controller

The controller within the meaning of the GDPR, other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is:

TenEntertainment GmbH i. Gr.
Steinstraße 45
51429 Bergisch Gladbach
Germany

Email: buero@ten-entertainment.de

Managing Directors authorised to represent the company: Stefan Gottschalk, Stefan Wolter, Lukas Wachten. Registration Court: Local Court of Köln. Commercial Register Number: to follow.

3. Cookies

The websites of TenEntertainment GmbH i. Gr. use cookies. Cookies are text files that are stored on a computer system via an internet browser.

Many websites and servers use cookies. Many cookies contain a so-called cookie ID, a unique identifier consisting of a string of characters. This enables websites and servers to distinguish the individual browser in which the cookie is stored from other browsers containing different cookies. A specific internet browser can therefore be recognised and identified via the unique cookie ID.

By using cookies, TenEntertainment GmbH i. Gr. can provide users of this website with more user-friendly services that would not be possible without cookies. Cookies can be used to optimise the information and offers on our website in the interests of the user and to make the website easier to use.

The data subject can prevent the setting of cookies by our website at any time by selecting the appropriate setting in the internet browser used and can thereby permanently object to the setting of cookies. Cookies that have already been set can also be deleted at any time via an internet browser or other software programs. If the data subject deactivates cookies in the internet browser used, not all functions of our website may be fully available.

4. Collection of general data and information

Each time the website of TenEntertainment GmbH i. Gr. is accessed by a data subject or an automated system, the website collects a range of general data and information. This general data and information is stored in the server log files. The information collected may include:

  1. browser types and versions used
  2. the operating system used by the accessing system
  3. the website from which the accessing system reaches our website (referrer)
  4. the subpages accessed on our website
  5. the date and time of access
  6. an Internet Protocol address (IP address)
  7. the internet service provider of the accessing system, and
  8. other similar data and information used for security purposes in the event of attacks on our information technology systems.

When using this general data and information, TenEntertainment GmbH i. Gr. does not draw conclusions about the data subject. Rather, the information is required to deliver the content of our website correctly, optimise the content of our website and its advertising, ensure the longterm functionality of our IT systems and website technology, and provide law-enforcement authorities with information necessary for prosecution in the event of a cyberattack. The anonymously collected data and information is therefore evaluated statistically and with the aim of increasing data protection and data security within our company. Anonymous server log data is stored separately from any personal data provided by a data subject.

5. Routine erasure and blocking of personal data

The controller processes and stores personal data only for the period necessary to achieve the purpose of storage or where this is provided for by the European legislator or another legislator in laws or regulations to which the controller is subject.

If the purpose of storage no longer applies or a statutory retention period expires, the personal data is routinely blocked or erased in accordance with the applicable legal provisions.

6. Rights of the data subject

a) Right to confirmation

Every data subject has the right granted by the European legislator to obtain confirmation from the controller as to whether personal data concerning them is being processed.

b) Right of access

Every data subject has the right to obtain from the controller, free of charge and at any time, information about personal data stored concerning them and a copy of that information. This includes, in particular, the purposes of processing, the categories of personal data processed, recipients or categories of recipients, the envisaged storage period or the criteria used to determine it, the existence of rights to rectification, erasure, restriction or objection, the right to lodge a complaint with a supervisory authority, information about the source of the data where it was not collected from the data subject, and information about automated decision-making including profiling where applicable. Where personal data is transferred to a third country or an international organisation, the data subject also has the right to be informed of the appropriate safeguards relating to the transfer.

c) Right to rectification

Every data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the data subject also has the right to have incomplete personal data completed, including by means of a supplementary statement.

d) Right to erasure (right to be forgotten)

Every data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay where one of the legal grounds under Article 17 GDPR applies, including where the data is no longer necessary for the purposes for which it was collected, consent is withdrawn and no other legal basis applies, the data subject objects and there are no overriding legitimate grounds, the data has been unlawfully processed, erasure is required to comply with a legal obligation, or the data was collected in relation to information-society services under Article 8(1) GDPR. Where personal data has been made public and the controller is obliged to erase it, the controller will, taking account of available technology and implementation costs, take reasonable steps to inform other controllers processing the data that the data subject has requested the erasure of links to, copies of or replications of that personal data, insofar as processing is not required.

e) Right to restriction of processing

Every data subject has the right to obtain restriction of processing where one of the conditions in Article 18 GDPR applies, including where the accuracy of the data is contested, processing is unlawful and erasure is opposed, the controller no longer needs the data but the data subject requires it for legal claims, or the data subject has objected pending verification of overriding legitimate grounds.

f) Right to data portability

Every data subject has the right to receive personal data concerning them which they have provided to a controller in a structured, commonly used and machine-readable format and has the right to transmit that data to another controller without hindrance, where the processing is based on consent or a contract and is carried out by automated means. Where technically feasible, the data subject may also request direct transmission from one controller to another, provided that this does not adversely affect the rights and freedoms of others.

g) Right to object

Every data subject has the right, on grounds relating to their particular situation, to object at any time to processing of personal data concerning them based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. TenEntertainment GmbH i. Gr. will then no longer process the personal data unless it can demonstrate compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims. Where personal data is processed for direct marketing, the data subject has the right to object at any time to processing for such marketing, including related profiling. If the data subject objects to processing for direct marketing, the personal data will no longer be processed for those purposes.

h) Automated individual decision-making, including profiling

Every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except where such a decision is necessary for entering into or performing a contract, is authorised by Union or Member State law providing suitable safeguards, or is based on the data subject’s explicit consent. Where such processing is permitted, appropriate measures will be taken to safeguard the data subject’s rights and freedoms and legitimate interests, including at least the right to obtain human intervention, express their point of view and contest the decision.

i) Right to withdraw consent

Every data subject has the right to withdraw consent to the processing of personal data at any time. To exercise any of the rights described above, the data subject may contact an employee of the controller at any time.

7. Privacy provisions relating to the use of Google Web Fonts

When you visit our website, fonts may be loaded from Google servers via the Google Fonts service in order to display those fonts on the website, unless the font is already stored in your browser cache. Google is responsible for processing the data transmitted as part of your browser request. Further information about Google Fonts is available from Google, as is Google’s Privacy Policy.

8. Legal basis for processing

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific purpose. Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, the processing is based on Article 6(1)(b) GDPR. The same applies to processing operations necessary to carry out pre-contractual measures, for example enquiries concerning our products or services.

Where our company is subject to a legal obligation requiring the processing of personal data, processing is based on Article 6(1)(c) GDPR. In rare cases, processing may be necessary to protect the vital interests of the data subject or another natural person and would then be based on Article 6(1)(d) GDPR. Finally, processing operations may be based on Article 6(1)(f) GDPR where processing is necessary for the purposes of legitimate interests pursued by our company or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject.

9. Legitimate interests pursued by the controller or a third party

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of our employees and shareholders.

10. Period for which personal data is stored

The criterion used to determine the storage period for personal data is the applicable statutory retention period. Once that period has expired, the corresponding data is routinely erased unless it is still required for the performance or initiation of a contract.

11. Statutory or contractual requirements to provide personal data

We inform you that the provision of personal data may in part be required by law, for example under tax regulations, or may result from contractual provisions, such as information concerning a contractual partner. In some cases, it may be necessary for a data subject to provide us with personal data in order to enter into a contract, and we must then process that data. Failure to provide the required personal data may mean that the contract cannot be concluded. Before providing personal data, the data subject may contact one of our employees, who will explain in the individual case whether the provision of the personal data is required by law or contract, whether there is an obligation to provide the data, and what the consequences of not providing it would be.

12. Automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

Source note

This English text is based on the Privacy Policy currently published on royal-wiesn.koeln. The German page states that the original policy was created using the privacy-policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH in cooperation with data protection lawyer Christian Solmecke.