Privacy Policy
I. Contact details
Jimdo GmbH
Stresemannstraße 375
22761 Hamburg
privacy(at)jimdo.com
II. Data Protection Officer
B³ | Informationstechnologie
Papenbergallee 34
25548 Kellinghusen
datenschutz(at)jimdo.com
III. Data Processing
Provision of the online offer and web hosting
Description: Our website is hosted by a dedicated website hosting provider that uses cloud-based servers located within the EU to provide a stable and secure hosting platform. Our website is distributed using a content delivery network provider with servers located all over the world to ensure a fast and safe delivery of our website.
Types of data processed:Usage data: e.g. web pages visited, access times, all entries made within our online offer or from websites
Communication data: e.g. browser type, operating system or IP addresses
Data subjects: Users (website visitors).
Purpose of processing: Provision of a stable and secure online offer that is easy to use.
Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f. GDPR).
Recipients or Categories of Recipients: Website hosting providers, SSL certificate providers, Content Delivery Network Providers
Data Transfer in Third Countries: We transfer your personal data to processors in the USA for this purpose. Information on the transfer of personal data to third countries can be found in section Transfer to third countries.
Storage Period or criteria on the basis of which the Storage Period is determined: Further information can be found in the section Storage Period.
Collection of log files
Description: We save log files for analyzing and maintaining the technical operation of the servers as well as assisting anti-abuse measures and protecting the security of the hosting platform.
Types of data processed:
Usage data: e.g. web pages visited, access times.
Communication data: e.g. browser type, operating system or IP addresses.
Data subjects: Users (website visitors).
Purpose of processing: Improving the stability and functionality of our website.
Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f. DSGVO). Our legitimate interest is to ensure the stability and functionality of the website.
Recipients or Categories of Recipients: Website hosting providers, website analysis providers
Data Transfer in Third Countries: Your personal data is processed within the EU.
Storage Period or criteria on the basis of which the Storage Period is determined: The log files are stored for 3 months and deleted afterwards.
Website Analytics
Description: If you visit our website, we collect information about your use of our website by means of a web analysis function developed by our website hosting provider and store it in a pseudonymous way. This tool collects your IP address and user agent, merges them, and truncates and stores this data using a so-called hash function. In this way, we generate a visitor identifier that will be encrypted using a random value, the so-called SALT, which changes every 24 hours. This ensures that your IP address cannot be recovered from the visitor identifier we store and that you cannot be identified personally. Furthermore, we do not merge this data with other data and only store it on the server of the website hosting provider. We also process web analytics, HTTP data and web analytics profile data. The web analysis function we use generates and stores the web analysis profile. This includes information about the use of our website, in particular page views, call frequency and dwell time on accessed pages as well as the client user agent of your terminal device.
Types of data processed:
Usage data: e.g. web pages visited, access times
Communication data: e.g. browser type, operating system or IP addresses
Data subjects: Users (website visitors).
Purpose of processing: Analyzing user behavior in aggregated form to improve our website including presentation and content.
Legal basis: Legitimate interest (Art. 6 para. 1 lit. (f) GDPR). Our legitimate interest is to conduct web measurement to improve our products and website.
Recipients or Categories of Recipients: website hosting provider
Data Transfer in Third Countries: Your personal data is processed within the EU.
Storage Period or criteria on the basis of which the Storage Period is determined: Further information can be found in the section Storage Period.
Video Content
Description: We embed videos content on our website to provide you with an appealing presentation of our online offers. After you give consent via the consent layer or the cookie banner, the video content is loaded and data is transferred to the servers of the video hosting provider.
Types of data processed:
Usage data: e.g. web pages visited, access times.
Communication data: e.g. browser type, operating system or IP addresses.
Data subjects: Users (website visitors).
Purpose of processing: Appealing presentation of our online offers by implementation of video content.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR).
Recipients or Categories of Recipients:
YouTube by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, https://policies.google.com/privacy
Data Transfer in Third Countries:
Your personal data is processed within the EU.
Storage Period or criteria on the basis of which the Storage Period is determined: Further information can be found in the section Storage Period.
Automated decision making (including profiling)
Processing of your personal data for the purpose of automated decision-making (including profiling) pursuant to Art. 22 (1) and (4) GDPR does not take place.
IV. Storage Periods
In general, we process and store your personal data for the duration for which the respective purpose of use requires corresponding storage. If applicable, this also includes the periods of the initiation of a contract (pre-contractual legal relationship) and the processing of a contract. On this basis, personal data is regularly deleted as part of the fulfillment of our contractual and/or legal obligations, unless its temporary further processing is necessary for the following purposes:
- Fulfillment of legal retention obligations (commercial or tax law)
- Retention of evidence taking into account the statute of limitations
- assertion, exercise or defense of legal claims or to protect the rights of another natural or legal person
V. Transfer to Third Countries
We ensure that your data is processed in the EU or in the European Economic Area. Should this no longer be possible and data needs to be transferred to a third country, Jimdo will ensure, after prior review, that an adequate level of data protection that meets the requirements of the Court of Justice of the European Union and the EU Commission is adhered to in the country the data is transferred to.
In these cases, the data is transferred on the basis of an Adequacy Decision of the European Commission or the Standard Contractual Clauses for the transmission of personal data to third countries in its currently valid version. These can be accessed here.
Data transmission to a third country may also take place on the basis of your consent. You will be provided with details of this separately, if applicable.
VI. The rights of your visitors and users (Data Subject Rights)
- Access to Information
You can request access to information about your personal data processed by us. - Correction
If your data is not (or no longer) correct, you can request that your data be corrected. If your data is incomplete, you can request that it be completed. - Deletion
You have the right to request the deletion of your data in accordance with applicable data protection laws. Please note that a request for deletion may depend on the existence of a legitimate reason and the absence of a legal reason that oblige us to retain your data. - Restriction of processing
You have the right to request the restriction of the processing of your data. Please note that a request for restriction of processing depends on the existence of a legitimate reason. - Objection
You have the right to object to the processing of your data on grounds relating to your particular situation. In the event of a justified objection, we will no longer process your data. - Objection to the processing of your data for direct marketing purposes
You have the right to object at any time to the processing of your data for direct marketing purposes. This also applies to profiling in connection with direct advertising. You can send your objection form-free to us, preferably to the contact details above, stating the keyword "Objection to the processing of my personal data for advertising purposes". - Right to lodge a complaint
You are entitled to lodge a complaint with a data protection supervisory authority if you do not agree with the processing of your data. - Data portability
You have the right to receive personal data that you have provided to us in an electronic format. - Withdrawal of your consent
You have the right to withdraw your consent that you have given to us at any time. The easiest way to withdraw your consent is to send an email to the contact details above. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal
VII. Change of the privacy policy
Jimdo reserves the right to change this Privacy Policy should this be necessary due to a changed legal situation or due to additional or changed services used or offered by Jimdo. The current version can be found here. If Jimdo intends to process the Jimdo User’s data for purposes other than those for which it was collected, we will notify the Jimdo User of this in advance in compliance with the statutory provisions.