EN DE

Translation note: The language of the contract and the applicable law shall remain exclusively German. Translations of these privacy policy provided in other languages are for the convenience of the user only. The provider cannot accept any liability for the accuracy of this translation. For the original version (German text) please select German as the displayed language in the shortcut-menu at top of this site.

PRIVACY POLICY

DATA PROTECTION IS IMPORTANT TO US!

Responsibility for content and technical matters as well as parties involved

The purpose of this online offering is to inform you about occupational pension solutions at your employer WAYFAIR and is based on their requirements. The content and technical aspects of these portal pages are the responsibility of Pension+Services GmbH as the service provider for company pension systems selected by WAYFAIR. PensionIT GmbH was commissioned with the technical implementation and is responsible for the operation. PensionIT is also responsible for security and data protection on this pages. PensionIT is referred to hereinafter as the website operator.

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that is used to identify you. For detailed information please refer to the following paragraphs of this privacy policy.

Data collection on this website

Who is responsible for data collection on this website?
The website operator processes the data on this website. For contact details see the “Information on the controller” section of this privacy policy.

How do we collect your data?

On the one hand, your data is collected as a result of you sharing it with us. For example, this includes data that you enter in the internal area (after login). Other data is automatically collected by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or time of page visit). This data is collected automatically as soon as you go on this website. Note: Data from external service providers, investment companies, insurance companies or similar pension providers, legal social partners and social security providers as well as your employer can be presented within the portal. This does not constitute data collection within the meaning of these data protection regulations.

What do we use your data for?

Part of the data is collected to ensure correct provision of the website, another part to provide the functions of the website.

What rights do you have regarding your data?

You have the right at any time to obtain information free of charge about the source, recipient and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to the processing of your personal data, you may withdraw this consent at any time in the future. In addition, you have the right to request the restriction of the processing of your personal data in certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time to discuss this and any questions regarding data protection.

2. General and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy.
When you use this website a variety of personal data is collected. Personal data is any data that is used to identify you. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g. communication by email) may have security gaps. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller for processing data on this website is:

PensionIT GmbH
Dornacher Str. 3
85622 Feldkirchen / Munich
Phone: +49 89 388874-01
Email: info@pension-it.de

Note: The controller is the natural or legal person who, alone or jointly, determines the purposes and means of processing personal data (e.g. names, email addresses etc.).

Retention period

Unless a specific retention period is stated in this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies.
If you make a legitimate request for erasure or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for retaining your personal data (e.g. retention periods under tax, commercial or other laws); in the latter case, the data will be deleted once these reasons no longer apply.

Statutory data protection officer

We have appointed a data protection officer for our company.

Datenbeschützerin Regina Stoiber GmbH
Ms Regina Stoiber
Unterer Sand 9
94209 Regen
Phone: +49 (0) 99 21 906 27 20
Email: info@datenbeschuetzerin.de  

Information on data transfer to the USA and other third countries

Your personal data in our systems will only be stored and processed in Germany and, if permitted, in the European Union.
Our website only has Font Awesome from Google as a tool from companies based in the USA or other third countries that are not secure from a data protection point of view. This tool is active to optimize the way text is displayed on the page and can forward your personal data (IT-based user data that the device you are logged in on transmits). We would like to point out that a level of data protection comparable to that of the EU cannot be guaranteed in these countries. For example, US companies are obliged to disclose personal data to security authorities without you as a data subject being able to take legal action. It therefore cannot be ruled out that US authorities (e.g. intelligence services) process, evaluate and permanently store your data located on US servers for surveillance purposes. We have no influence on these activities.

Withdrawal of your consent to data processing

Many data processing activities are only possible with your explicit consent. You can withdraw your consent at any time. The lawfulness of the data processing carried out up to the withdrawal remains unaffected by the withdrawal.
Users can revoke their consent to data processing mandatory for using the portal at any time with effect for the future by deleting their personal portal access. Please let us know by email (datenschutz@pension-it.de) or by letter using the contact details provided at the beginning of the terms and conditions.
Note: Deletion of your personal portal access does not mean a termination of the business relationship with all providers mentioned in the imprint and the data stored there. If you would like your data to be deleted not only from your personal portal access but also from the providers themselves, please contact your employer [ag-name] for more information. As a website operator we cannot provide any information on your rights that go beyond the use of this portal offering.

Right to object to the collection of data in special cases and to direct marketing purposes

(Art. 21 GDPR) IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, INCLUDING PROFILING BASED ON THESE PROVISIONS. YOU CAN FIND THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (WITHDRAWAL ACCORDING TO ART. 21(1) GDPR). IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING, WHICH INCLUDES PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEN NO LONGER BE USED FOR THE PURPOSES OF DIRECT MARKETING (WITHDRAWAL ACCORDING TO ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of an infringement of the GDPR, every data subject has the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

Right to data portability

You have the right for data that we process automatically on the basis of your consent or in performance of a contract to be handed over to you or a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place where technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transfer of confidential content such as orders and requests that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser’s address line changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is enabled the data you transfer to us cannot be read by third parties.

Access, erasure and rectification

As part of the applicable legal provisions, you have the right to request, free of charge at any time, information on your stored personal data, its source and recipient, and the purpose of data processing, and, if applicable, a right to have this data rectified or deleted. You can contact us at any time to discuss this and any questions regarding personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. To do this, you can contact us at any time. The right to restriction of processing applies in the following cases:

  • If you contest the accuracy of your personal data stored with us, we usually need time to verify this. During verification you have the right to request the restriction of the processing of your personal data.
  • If processing of your personal data happened/is happening unlawfully, you may request the restriction of data processing instead of erasure.
  • If we no longer need your personal data but you need it for establishing, exercising or defending legal claims, you have the right to request restriction of the processing of your personal data instead of erasure.
  • If you have objected according to Art. 21(1) GDPR, a balance must be struck between your interests and our interests. As long as it has not yet been determined whose interests outweigh the other’s, you have the right to request restriction of the processing of your personal data.

If you have restricted processing of your personal data, this data, with the exception of its storage, may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a member state.

3. Data collection on this website

Cookies

Some of the website pages make use of “cookies”. Cookies do not harm your computer and do not contain viruses. Cookies help to make using our services more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and also stored by your browser.

Most of the cookies we use are “session cookies”. These are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser the next time you visit.

You can make settings in your browser to notify you about cookies, to allow cookies only in specific cases, to reject cookies either outright or in certain cases, and to activate automatic deletion of cookies when the browser is closed. Disabling cookies may limit the functionality of this website.

Cookies that are needed to carry out electronic communications or to provide certain functions that you wish to use (the shopping cart for example), are stored in accordance with Art. 6(1)(f) GDPR. The website operator has a legitimate interest in storing cookies to ensure smooth and optimized delivery of their services. If other cookies are stored (such as cookies for analyzing your surfing behavior), these will be treated separately in this Privacy Policy.

Server log files

The website provider automatically collects and stores information in so-called server log files which your browser automatically forwards to us. This information comprises the following:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of server request
  • IP address

Data will not be collated with any other data sources.

The basis for data processing is Art. 6(1)(f) GDPR which allows the processing of data for the performance of a contract or pre-contractual measures.

Contact form

If you send us requests via the contact form your details from the form including the contact details you provide there will be stored by us for the purpose of processing the requests and answering any follow-up questions. We will not pass on this data without your consent.

The data entered on the contact form will be processed on the basis of legitimate interest (Art. 6 (1)(a) GDPR). You can withdraw your consent at any time. An informal message to us by email is sufficient. The legality of the data processing activities carried out up to withdrawal remains unaffected by the withdrawal.

The data entered by you in the contact form remains with us until you request its deletion, revoke your consent to storage or the purpose for processing the data no longer applies (on completion of your request, for example). Mandatory statutory provisions – in particular those relating to retention periods – remain unaffected.

Processing of data (customer and contract data)

We only collect, process and use personal data if such data is necessary for establishing, amending or adding content to the legal relationship (inventory data). This is based on Art. 6(1)(b) GDPR which allows the processing of data for the performance of a contract or for activities prior to entering into a contract. We only collect, process and use personal data about the use of our internet sites (usage data) if such data is needed to enable the user to use the service or be billed.

The customer data collected will be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.

Data transfer for services and digital content at the time of the contract

We only transfer personal data to third parties if this is necessary for processing the contract – for example to the credit institution handling the payment.

No further data transfer will take place unless you have expressly consented to the transfer. Your data will not be passed on to third parties, for example for advertising purposes, without your express consent.

The basis for data processing is Art. 6(1)(b) GDPR which allows the processing of data for the performance of a contract or for activities prior to entering into a contract.

4. Analysis

Matomo (formerly Piwik)

This website uses the Matomo open-source web analytics service (formerly Piwik). Matomo uses “cookies”. These are text files stored on your computer to enable your use of the website to be analyzed. The information generated by the cookie about the use of this website is stored on our server. The IP address is anonymized before it is stored.

The information generated by the cookie about the use of this website will not be passed on to third parties. You can prevent cookies being stored by making an appropriate setting in your browser software but this would mean you may not be able to use all the functions of this website to their full extent.

If you do not agree to the storage and use of your data, you can deactivate its storage and use here. In this case, an opt-out cookie will be stored in your browser, preventing Matomo from storing usage data. If you delete your cookies, the Matomo opt-out cookie will also be deleted. You will need to reactivate the opt-out when you next visit our site.

Opting out of Matomo

Google Tag Manager

This website uses the Google Tag Manager. Google Tag Manager enables marketers to manage website tags from a single interface. The Tag Manager tool itself (which implements the tags) is a cookie-free domain and does not collect personal data. The tool triggers tags which in turn may collect data. Google Tag Manager does not access this data. Deactivation at domain or cookie level will remain in effect for all tracking tags implemented with Google Tag Manager.

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Usage is based on Art. 6(1)(f) GDPR. Google Analytics uses cookies which are text files stored on your computer to enable your use of the website to be analyzed.

Google Analytics is a web analytics service provided and operated by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States). Google processes the website usage data on our behalf and is contractually obliged to take measures to safeguard the confidentiality of the data it processes.

The data recorded during your visit to the website includes the following:

  • Pages viewed
  • The achievement of “website targets” (such as contact requests and newsletter registrations)
  • Your behavior on the pages (such as clicks, scrolling behavior and dwell time)
  • Your approximate location (country and city)
  • Your IP address (in abbreviated form so that unique identification is not possible)
  • Technical information such as your browser, internet service provider, device and screen resolution
  • Origin of your visit (i.e. the website or advertising medium via which you came to us)

This data is transferred to a Google server in the USA. Google complies with the data protection provisions of the “EU-US Privacy Shield” agreement. IP anonymization is used on this website. The IP addresses of users are shortened within the member states of the EU and the European Economic Area and in the other states party to the agreement. Only in individual cases will the IP address initially be transmitted in full to a Google server in the USA and then abbreviated there. This shortening means you cannot be identified by your IP address. The user’s IP address sent by the browser is not combined with other data stored by Google.
Under the data processing agreement which we as website operator have with Google Inc., Google will use the information it collects to evaluate website usage and website activity and to provide services relating to the use of the internet.
The data collected by Google on our behalf is used to evaluate how our online services are used by individual users so that, for example, reports on website activity can be created which we can then use to improve our online services.

You have the option of preventing cookies from being stored on your device by making appropriate settings in your browser. If your browser does not allow cookies you may not have unrestricted access to all the features of this website.
By installing the browser add-on for deactivating Google Analytics you can prevent the information collected by cookies (including your IP address) from being sent to Google Inc. and being used by Google Inc.
As an alternative to the browser add-on, especially for browsers on mobile devices, you can prevent data collection by Google Analytics by clicking on this link: Google Analytics opt-out[PP1] . An opt-out cookie is set that prevents future collection of your data whenever you visit this website. The opt-out cookie is valid only in this browser and only for our website and is stored on your device. If you delete the cookies in this browser you will need to set the opt-out cookie again.
We continue to use Google Analytics to evaluate data from Google Ads for statistical purposes. If you do not want this to happen you can disable it in the My Ads Center.
For more information about privacy relating to Google Analytics, see Google Analytics Help.

Google Remarketing

We also use Google’s remarketing feature. This enables us to provide you with personalized advertising in suitable advertising spaces on other websites based on the interests you have shown on our website. This option is limited to a maximum of 18 months.
For further information, please see Google’s Privacy Policy. You can prevent interest-based advertising by installing this browser plug-in.

Google Ads Conversion Tracking

We use Google AdWords Conversion Tracking to measure the success of our advertising. On achieving certain targets (“conversions”) on our website – such as completion of an order or registration for our newsletter – these targets are recorded by Google. Google can then measure the number of targets achieved. Google uses cookies previously stored to identify the ads that were clicked on and were therefore crucial in achieving the target. Google processes this data on servers in the United States, but will not associate it with personal data from your Google account.