On data protection in detailed form:
I. What is personal data?
II. How is the data of website visitors or users of TOBIS services used? Does automated decision-making (profiling) take place?
III. Which third-party services and offers (cookies, Google Analytics, social plugins) are integrated on the website?IV. How is data used on Facebook pages (Facebook pages)?
V. Is data passed on to third parties?
VI. Is data transmitted or transferred outside the European Union (EU)?
VII. Your rights: information, revocation, changes, corrections and updates, deletion, restriction of processing, data portability, right of complaint
VIII. Data security, scope, contact person
I. What is personal data?
Personal data is information that can be used to identify a person, therefore information that can be traced back to a person. This includes, for example, name, email address or telephone number, but also data about hobbies, memberships or which websites were viewed by someone count as personal data. Personal data is only collected, used and passed on by us if this is permitted by law or the users consent to the data collection.
II. How is the data of website visitors or users of TOBIS services used? Does automated decision-making (profiling) take place?
Visiting the website
We (or the web space provider) collect data about each visit to our website (so-called server log files) ("access data"). The access data includes:
Name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.
and additionally when using a mobile terminal:
Country code, language, device name, operating system name and version
We only use this access data for statistical evaluations for the purpose of the operation, security and optimisation of the website. However, we reserve the right to check this access data retrospectively if there is a justified suspicion of unlawful use on the basis of specific indications. The data processing is carried out on the legal basis of Art. 6 (1) f. GDPR, whereby our legitimate interests (or the legitimate interests of third parties commissioned by us) of quality assurance or fraud prevention are pursued.
Contact
When contacting us (e.g. by email), your details will be stored for the purpose of processing the enquiry and in the event that follow-up questions arise. This is done on the basis of your consent (Art. 6 (1) a. GDPR) or for the purpose of processing your enquiry (Art. 6 (1) b. GDPR).
Press service
As a press representative or cinema operator, you have the opportunity to register on our website for our press service, through which you can obtain information material and other digital content (photos/videos) about our films. To register, you must provide us with the data marked as mandatory in the application form. In addition to your name, address, e-mail address and telephone number, we record in particular the medium for which you work and the distribution districts in which your film theatres are located. The last-mentioned data serves as a basis for our decision-making with regard to your eligibility for registration. The data processing is based on your consent (Art. 6 (1) a. GDPR). Furthermore, the processing serves to initiate or execute the contract of use (legal basis Art. 6 (1) b. GDPR).
Newsletter; use of Mailchimp
With the email newsletter we inform you about us and our services. Only your email address is required to register for the newsletter. If you register for the newsletter, your email address will be transferred to us (or to Mailchimp) and stored there. After registration, the user receives an email to confirm the registration ("double opt-in"). With the registration for the newsletter, the IP address, the device name, the mail provider as well as the first and last name and the date of registration are stored with us. This storage is solely for the purpose of providing evidence in the event that a third party misuses an email address and registers to receive the newsletter without the knowledge of the authorised person. The data processing for sending the newsletter is based on your consent (legal basis Art. 6 (1) a. GDPR).
For the purpose of sending newsletters, we use the "Mailchimp" service of Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, which processes the IP address, device name, the mail provider as well as the first and last name and the date on Mailchimp's servers in the USA for this purpose.
We would also like to point out that automated decision-making ("profiling") may take place when Mailchimp is integrated. We use the Mailchimp service to analyse the behaviour of users, for example whether they open the email sent or click on certain links in emails. When the newsletter is opened, the information contained (so-called web beacon) connects to Mailchimp's servers in the USA in order to analyse the user's behaviour. For this purpose, further technical information is collected, such as the IP address, browser type and operating system. The data processing is carried out on the legal basis of Art. 6 (1) f. GDPR, whereby our legitimate interests (or the legitimate interests of third parties commissioned by us) of quality assurance or marketing are pursued. You can find the privacy policy of Mailchimp here: https://mailchimp.com/legal/terms/.
After the ECJ declared the EU-US Privacy Shield Agreement invalid, the USA is an insecure third country in which there is no level of data protection comparable to EU standards. There is therefore a risk that government agencies may access your personal data through the transfer without you having any effective legal protection options. Your data will therefore only be transferred with your explicit consent.
Revocation of consent / objection: The user can revoke his/her consent to the processing of data for the purpose of sending the newsletter or evaluation by Mailchimp/us at any time. The revocation can be made via a link in each newsletter or by sending a message to us.
Automated decision-making ("profiling")
When using the offer, no "profiling" or automated decision-making by us takes place; however, such profiling may take place in individual cases through third-party providers used by us, and we refer to this in this privacy policy where possible. Profiling means any type of automated processing of personal data that consists of using that personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or change of location. Examples of such profiling include the analysis of data (e.g. based on statistical methods) with the aim of displaying personalised advertising to the user or providing shopping tips. The data subject has the right not to be subject to a decision based solely on automated processing - including profiling - which produces legal effects concerning him or her or similarly significantly affects him or her. This does not apply if the decision (i) is necessary for the conclusion or performance of a contract between the data subject and the controller, (ii) is authorised by the EU or a Member State law to which the controller is subject and that law contains suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or (iii) is made with the data subject's explicit consent. In such exceptional cases, the controller shall take reasonable steps to safeguard the data subject's rights and freedoms and legitimate interests, including at least the right to obtain the intervention of a data subject on the part of the controller, to express his or her point of view and contest the decision.
III. Which third-party services and offers (cookies, analytics, social plugins) are integrated on the website?
Cookies
Cookies are small files that make it possible to store specific, device-related information on the user's access device (PC, smartphone or similar). On the one hand, they serve the user-friendliness of websites and thus you (e.g. storage of login data). On the other hand, they serve to collect statistical data on website use and to be able to analyse it for the purpose of improving the website.
When you visit the website, so-called session cookies are used, which are automatically deleted from the user's hard drive as soon as you close the browser window. The session cookies are needed to assign successive page requests to the respective users who access the website at the same time. In addition, we use the following third-party providers that set persistent cookies, i.e. cookies that are permanently stored on your end device.
We only set cookies that are not essential for the use of the website with your explicit consent, which we obtain via the cookie banner when you visit our website for the first time. If you wish to make changes to the choices you have made, adjust or withdraw the consent you have given, click hier.
On our website, we use the consent management tool "tarteaucitron" by the developer Amauri Champeaux, based in France. If you give your consent to the use of cookies, a cookie is set that stores your selection. This cookie is technically necessary and is set on the basis of Art. 6 para. 1 lit. f GDPR to document your consent. If you delete your cookies, we will ask you for your consent again when you visit the site at a later date.
Objection: You can influence the use of cookies. Most browsers have an option to restrict or completely prevent cookies from being stored. You can still manage many online ad cookies from companies via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/uk/your-ad-choices/. However, it should be noted that the use and in particular the user comfort is restricted without cookies.