Bonsy App Privacy Policy

Click here to access the German version of the Bonsy App privacy policy.


1. Who are we? (responsible person)

Collapse

The person responsible in terms of data protection law is marktguru Deutschland GmbH, Sendlinger Straße 23, 80331 Munich, office@marktguru.de, hereinafter “marktguru” or “we” or “us”.

Exceptions are explained in this privacy policy.

Our contact details and that of our data protection officer can be found in section 15 Contact”.

2. Which categories of personal data do we process?

Collapse

2.1 General

Personal data is any information relating to an identified or identifiable natural person. When we process personal data, this means that we collect, store, use, transfer or delete it to others, for example.

The categories of personal data we process about you depend on how you use our online offering. We have listed the possible categories for you below.

2.2 Categories of personal data

Master data: When you register for our online offer, we process the following data: Name, address, email address, password, opt-out status.

contact details: When you contact us (e.g. via a form or by e-mail), we process the data you provide (this is usually first and last name, email address and/or telephone number, content of your request) and the subsequent communication.

Purchasing data: When you upload your shopping vouchers to us, we process the purchase data (such as store, discounts) and product data provided to us (like EAN/GTIN code on a receipt line).

App configuration data: When you use our contractual services (e.g. set the language, color display of the app, (purchase) categories, label, country), we process the data required for the respective service or the respective configuration of the app.

Other data that is part of uploaded receipts: If further data (such as delivery address, membership number, contact details, etc.) is visible on the uploaded receipt, we collect this together with the purchase data.

Manual spending (data related to manual spending): When you manually enter your spending in the app, this information is processed.

Direct marketing consent forms: If you have given us appropriate consents, we process your declarations of consent for direct marketing (e.g. consent to newsletters, consent to other forms of direct marketing via electronic mail, consent to personalize newsletters and other direct marketing).

Push message data: User ID, device information, consent status, or information as to whether push messages are allowed.

InApp message data: User ID, device information, messages sent.

Competition data: If you participate or have participated in one of our competitions using another MarktGuru service and have agreed that we may use this data for further, specified purposes, we process appropriate data such as participation information.

Socio-demographic data: When you participate in a voluntary survey or market survey, we process the information you provide, such as age group, gender, level of education, household size, household income, citizenship, employment status, primary household earner.

Studiendaten: Wenn Sie an einer unserer Studien (User Interviews, Gruppendiskussionen, Befragungen) teilnehmen, verarbeiten wir die in deren Rahmen erhobenen Daten.

Log data for surveys by third parties: If you participate in a market survey arranged by us by a third party, we will receive information from the third party as to whether the survey has been completed (but we will not receive any information about the information you provided in the market surveys).

Chat-Daten: Wenn Sie unseren KI-Assistenten verwenden, werden Ihre Prompts und der Verlauf verarbeitet.

Online usage data: Every communication via the Internet generates online usage data. This includes data such as IP address, search request, retrieval time stamp, browser information, device information, app identifier, device ID, referrer URL, geo-location/location data, user ID, click path.

Log files: Each time you use an online service, your device automatically transmits so-called online usage data. These are temporarily stored in so-called log files to ensure technical safety and functionality. The IP address is also processed to determine the country code and is not stored together with user IDs.

Adblocker data: Information about whether an ad blocker is available.

2.3. Data that is processed in connection with app identifiers

In connection with app identifiers and similar technologies (“app identifiers”), we process the following data:

  • Online usage data and email address
  • Consent to the use of app identifiers (and in related data processing operations)

3. Who receives your personal data and why?

Collapse

3.1 Transfer of data to third parties

In principle, we will only share your personal data with third parties insofar as this is necessary to fulfill the contract, we or the third party has a legitimate interest in sharing it, has your consent to do so, or if this is necessary to fulfill a legal obligation.

Details of the third parties are set out in Section 4 below “What do we process your personal data for, on which legal basis, what are our legitimate interests, who receives your personal data? ”.

In particular, we may disclose personal data to a third party

  • if we should be obliged to do so in individual cases due to legal requirements or by an enforceable administrative or court order;
  • in connection with legal disputes (against courts or our lawyers) or tax audits (against auditors);
  • in connection with possible criminal offences against the competent investigative authorities;
  • in the event of a sale of the business (to the acquirer and his legal and tax advisors).

In the case of transmission based on consent, the explanation can also be provided when consent is obtained.

3.2 Transfer of data to service providers

We reserve the right to use service providers when collecting or processing data. Service providers only receive the personal data from us that they need for their specific activity. For example, your email address may be passed on to a service provider so that they can deliver a newsletter you have ordered. Service providers can also be commissioned to provide server capacities. Service providers are usually involved as so-called contract processors who may only process the personal data of users of this online service in accordance with our instructions.

Details of the service providers we use are set out in Section 4 below”What do we process your personal data for, on which legal basis, what are our legitimate interests, who receives your personal data? ”.

4. What do we process your personal data for, on which legal basis, what are our legitimate interests, who receives your personal data?

Collapse

We process your data for the following purposes and on the basis of the above legal bases. Explanations of the data categories can be found in Section 2”What categories of personal data do we process”. In the event that data processing is based on the legal basis of legitimate interest, we will also explain to you our legitimate interest, which we pursue with the processing. In addition, we show which recipients or categories of recipients we share your personal data with

4.1 General purposes of processing:

1. Provision of this online offer. In particular, this includes:

1.1. Enabling registered users to use the login area of the online service to fulfill the contract in accordance with our Terms and conditions (such as saving scanned invoices, automatic and manual management of the cash book)

  • Categories of personal data: Master data, contact details, purchase data, other data that is part of uploaded receipts, manual issues, log files, app configuration data
  • Legal basis of processing: Contract performance (Art. 6 para. 1 lit. b DSGVO); legitimate interest (Art. 6 para. 1 lit. f DSGVO): If further data (such as delivery address, membership number, contact details, etc.) is visible on the uploaded receipt but is not required to fulfill the contract, we collect this together with the purchase data for economic and technical reasons. We have a legitimate interest in giving our users the opportunity to upload receipts in various formats so that they have a better overview of their household expenses on the one hand and can also find their receipts in the Bonsy app at any time.
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (receipt scanner), EU/EEA area, USA
      • IT-Dienstleister (KI-Kassenbonscanner), EU/EWR-Raum, USA
      • IT-Dienstleister (technischer Support), EU/EWR-Raum, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (product support), Armenia

1.2. Continuous automated evaluation of output behavior (across mobile devices)

  • Categories of personal data: Log files, master data, purchase data, other data that is part of uploaded receipts, manual expenditure
  • Legal basis of processing: Contract performance (Art. 6 para. 1 lit. b DSGVO); legitimate interest (Art. 6 para. 1 lit. f DSGVO): If further data (such as delivery address, membership number, contact details, etc.) is visible on the uploaded receipt but is not required to fulfill the contract, we collect this together with the purchase data for economic and technical reasons. We have a legitimate interest in giving our users the opportunity to upload receipts in various formats so that they have a better overview of their household expenses on the one hand and can also find their receipts in the Bonsy app at any time.
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (product support), Armenia

1.3. Linking of several user accounts (“My household”) so that invoices from several users can be taken into account together when keeping the cash book and evaluating spending behavior

  • Categories of personal data: Log files, master data, purchase data, other data that is part of uploaded receipts, manual expenditure
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a DSGVO); legitimate interest (Art. 6 para. 1 lit. f DSGVO): If further data (such as delivery address, membership number, contact details, etc.) is visible on the uploaded receipt but is not required to fulfill the contract, we collect this together with the purchase data for economic and technical reasons. We have a legitimate interest in giving our users the opportunity to upload receipts in various formats so that they have a better overview of their household expenses on the one hand and can also find their receipts in the Bonsy app at any time.
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (product support), Armenia

1.4. Provision of a contact option and answering sent inquiries

  • Categories of personal data: contact data, log files
  • Legal basis of processing: Contract performance (Art. 6 para. 1 lit. b DSGVO); legitimate interest (Art. 6 para. 1 lit. f DSGVO): We have a legitimate interest in answering customer and contact inquiries.
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • customer support (email), EU/EEA area
      • customer support (ticket system), Israel, EU/EEA area, USA

1.5. Identification of the country of receipt

  • Categories of personal data: Log files (IP address)
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f GDPR): The allocation of receipts to a country is necessary for the correct classification, analysis and presentation of country-specific market information. It makes it possible to improve the regional relevance of content and evaluations in the app and thus serves to tailor the service and to ensure quality.
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (geolocation), EU/EEA area, USA

1.6. Bereitstellung eines interaktiven KI-Assistenten („Bonsy Assistent“) zur Auswertung des Ausgabeverhaltens, Budgetberatung und Kategorisierung

  • Kategorien personenbezogener Daten: Chat-Daten, App-Konfigurationsdaten, Einkaufsdaten, weitere Daten, die Bestandteil hochgeladener bzw. eingescannter Kassenbons sind, manuelle Einträge, Ausgabenanalysen, Log-Dateien
  • Rechtsgrundlage der Verarbeitung: Die Verarbeitung der Daten erfolgt auf Grundlage von:
    • Nutzung des interaktiven KI-Assistenten: Einwilligung (Art. 6 Abs. 1 lit. a DSGVO); 
    • begrenzte Speicherung der Chat-Daten: berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO) an der Qualitätskontrolle und -optimierung unseres KI-Assistenten
  • Empfänger bzw. Kategorien von Empfängern:
    • Auftragsverarbeiter:
      • IT-Dienstleister (KI-Infrastruktur-Anbieter), EU/EWR-Raum, USA
      • IT-Dienstleister (Anbieter von Nutzungsanalyse- & Service-Verbesserungs-Tools), EU/EWR-Raum, USA  
      • IT-Dienstleister (technischer Support), EU/EWR-Raum, USA
      • IT-Dienstleister (Hosting), EU/EWR-Raum, USA
      • IT-Dienstleister (Produktsupport), Armenien

2. Consent and opt-out management

  • Categories of personal data: Master data, declarations of consent for direct marketing, consent to the use of app identifiers
  • Legal basis of processing: Fulfilment of a legal obligation (Art. 6 para. 1 lit. c GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (CMP provider), EU/EEA area
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA

3. Direct marketing, surveys, market surveys and in-app/ push messages

3.1 Sending messages such as email newsletters or other direct marketing via electronic mail (e.g. email, SMS, MMS, messenger message)

  • Categories of personal data: Contact details, declarations of consent direct marketing
  • Legal basis of processing:
    • If the conditions for contacting existing customers without consent are met: Art. 13 (2) ePrivacy Directive in conjunction with Section 7 (3) UWG 2021 (Art. 95 GDPR);
    • in all other cases: Art. 13 (1) ePrivacy Directive in conjunction with Section 7 (2) UWG (Article 95 GDPR) (consent)
    • Please note your right to object when processing data for direct marketing purposes or for personal reasons (see Section 14.7 “Your right to object to direct marketing” and section 14.8 “Your right to object for personal reasons”).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (email delivery) EU/EEA area, USA
      • customer support (email, phone), EU/EEA area, USA

3.2. Sending informational emails and messages

  • Categories of personal data: contact details
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f GDPR): We have a legitimate interest in sending important information to app users (e.g. on unwanted data and other topics in need of clarification).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (email delivery) EU/EEA area, USA
      • customer support (email, phone), EU/EEA area, USA

3.3. Sending push messages

  • Categories of personal data: Push message data
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (push notifications), EU/EEA area

3.4. Sending InApp messages

  • Categories of personal data: InApp messages data
  • Legal basis of processing: Contract performance (Art. 6 para. 1 lit. b GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia

3.5. Conducting surveys, including collecting feedback.
We can also invite users to participate in the survey by electronic mail (e.g. email, SMS, MMS, messenger message) if we have received separate consent to do so.

  • Categories of personal data: Depending on the survey/feedback: personal data (e.g. name, email address, if provided by you), responses to surveys and feedback, online usage data (e.g. IP address, device information, browser type, access times), log files; app configuration data, socio-demographic data
  • Legal basis of processing: The data is processed on the basis of:
    • For contact by electronic mail: Art. 13 para. 1 ePrivacy Directive in conjunction with Section 7 Paragraph 2 No. 2 UWG (Art. 95 DSGVO) (consent)
    • To process the surveys:
      • legitimate interest (Art. 6 para. 1 lit. f GDPR), as we have a legitimate interest in carrying out and evaluating surveys to improve our offerings (e.g. to optimize our apps based on user interactions and develop new services), or
      • Consent (Art. 6 para. 1 lit. a GDPR)
    Please note your right to object when processing data for direct marketing purposes or for personal reasons (see Section 14.7 “Your right to object to direct marketing” and section 14.8 “Your right to object for personal reasons”).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (survey tool), EU/EEA area, USA
      • IT service provider (email delivery), EU/EEA area, USA
      • customer support (email, telephone, EU/EEA area, USA)

3.6. Carrying out market surveys:
Market surveys are carried out by us in the app. We can also invite users to participate in the market survey by electronic mail (e.g. email, SMS, MMS, messenger message) if we have our separate consent. We may also invite you to participate in market surveys by third parties; in this case, you will be redirected via a link to a page of the third party who is solely responsible for carrying out the market survey. We use log data for surveys by third parties for billing purposes.

Market surveys are used to measure customer sentiments/satisfaction, to adjust marketing strategies based on customer feedback or to enable marketing strategies to be adjusted based on emerging trends.

During market surveys carried out by us, we provide third parties (product manufacturers, retailers, etc.) Data is only available in anonymized form in a controlled self-service environment for market research and statistical purposes.

  • Categories of personal data: Master data, socio-demographic data, purchase data, log files, app configuration data; log data for surveys by third parties, competition data, online usage data
  • Legal basis for processing: The data is processed on the basis of:
    • For contact by electronic mail: Art. 13 para. 1 ePrivacy Directive in conjunction with Section 7 Paragraph 2 No. 2 UWG (Art. 95 GDPR) (consent),
    • For the processing of market surveys:
      • Consent (Art. 6 para. 1 lit. a GDPR) insofar as master data, competition data, online usage data or socio-demographic data are also processed
      • Legitimate interest (Art. 6 para. 1 lit. f GDPR) with the exclusive use of purchase data, app configuration data and log data for surveys by third parties: We have a legitimate economic interest in expanding our product portfolio for further customers so that they can statistically understand the buying behavior of defined consumer groups, assess supply gaps or effects of price changes and thus make product and service improvements.

        Processing continues to serve the legitimate business interests of product customers in constantly adapting their product placement to the needs of consumers, which at the same time meets economic interests of market efficiency. In addition, we have a legitimate interest in billing market surveys arranged by us on a performance-based basis.

        You have the right to object to the processing of your personal data at any time and without giving reasons; please use the contact details in section 15.

        Due to the significantly reduced processing of personal data, the exclusively anonymized provision of this data (see purpose 5.2 below) and the unconditional right of objection granted, we have come to the conclusion that your interests do not prevail.

        In addition, please note your right to object when processing data for direct marketing purposes or for personal reasons (see Section 14.7 “Your right to object to direct marketing” and section 14.8 “Your right to object for personal reasons”).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (survey tool), EU/EEA area, USA
      • IT service provider (email delivery) EU/EEA area, USA

3.7. Personalization of communications, including newsletters and other electronic mail, including analysis of interaction with the message (e.g. opening rate, clicks on links)

  • Categories of personal data: Master data, contact details, online usage data
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA
      • IT service provider (email delivery), EU/EEA area, USA

3.8. User Interviews: Anmeldung zum Interview und Terminkoordination, Durchführung des Interviews inkl. Interviewaufzeichnung bzw. Transkription, Auswertung der Interviewergebnisse zur Verbesserung unserer Produkte

  • Kategorien personenbezogener Daten: Kontaktdaten (Terminkoordination), Studiendaten
  • Rechtsgrundlage der Verarbeitung: Einwilligung (Art. 6 Abs. 1 lit. a DSGVO); berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO), da wir ein berechtigtes Interesse an der Einladung unserer Appnutzenden zu Interviews zur Verbesserung unserer Angebote haben.
  • Empfänger bzw. Kategorien von Empfängern:
    • Auftragsverarbeiter:
      • IT-Dienstleister (technischer Support), EU/EWR-Raum, USA
      • IT-Dienstleister (Hosting), EU/EWR-Raum, USA
      • IT-Dienstleister (E-Mail-Versand, Online Meeting, Transkription), EU/EWR-Raum, USA
      • IT-Dienstleister (Ablagetool), EU/EWR-Raum, USA
      • IT-Dienstleister (Product Support), Armenien

3.9. User Studies (Befragungen, Einzelinterviews, Gruppendiskussionen): Anmeldung zu User Studies und Terminkoordination, Durchführung von User Studies inkl. Aufzeichnung bzw. Transkription, Auswertung der Studienergebnisse zur Verbesserung unserer Produkte (inkl. der Anonymisierung der Studiendaten vor der Auswertung)

  • Kategorien personenbezogener Daten: Einkaufsdaten, App-Konfigurationsdaten; Stammdaten, Kontaktdaten (Terminkoordination), soziodemographische Daten, Studiendaten
  • Rechtsgrundlage der Verarbeitung: Einwilligung (Art. 6 Abs. 1 lit. a DSGVO); berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO), da wir ein berechtigtes Interesse an der Einladung unserer Appnutzenden zu User Studies zur Vermarktung und Verbesserung unserer Angebote haben.
  • Empfänger bzw. Kategorien von Empfängern:
    • Auftragsverarbeiter:
      • Dienstleister (Durchführung und Auswertung von User Studies), EU/EWR-Raum
      • IT-Dienstleister (technischer Support), EU/EWR-Raum, USA
      • IT-Dienstleister (Hosting), EU/EWR-Raum, USA
      • IT-Dienstleister (E-Mail-Versand, Online Meeting, Transkription), EU/EWR-Raum, USA
      • IT-Dienstleister (Ablagetool), EU/EWR-Raum, USA

4. Sign-in services

4.1. Provision of a login via third-party providers (sign-in services)

  • Categories of personal data: Log files, master data obtained from the third party provider used
  • Legal basis of processing: Fulfilment of contract (Art. 6 para. 1 lit. b GDPR) ‍
  • Recipients or categories of recipients:
    • Third party:
      • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour 2 Dublin, Ireland
      • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
      • Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Irland
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA

5. Market research, personalization

5.1. Processing pseudonymous user profiles:
Combining the data collected during product use to create pseudonymous user profiles, on the basis of which target group segments can be formed and used for market research and statistical purposes. This also includes the anonymization of this data and its subsequent exclusively anonymized transfer to third parties for the purposes mentioned above.

“Target group segments” are subgroups of a larger target group that are formed on the basis of common characteristics such as demographics (age, gender), interests or behavior (usage behavior, shopping history) in order to be able to gain insights that are as specific as possible.

“Pseudonymized” means that your data has been modified in such a way that it can no longer be attributed to you without the use of additional information. This additional information is stored separately so that your data is particularly protected.

“Anonymized” means that your data has been changed in such a way that it is no longer possible to draw any conclusions about you.

  • Categories of personal data: Master data, socio-demographic data, shopping data, competition data, log data for surveys by third parties; app configuration data; online usage data
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA

5.2. Insofar as you have not given us consent to the data processing referred to in 5.1, the following processing takes place:
Reduced merging of data collected during product use to create pseudonymous user profiles, for market research purposes and for statistical purposes.

In the case of market research, we provide third parties (product manufacturers, retailers, etc.) with a reduced data set in anonymized form in a controlled self-service environment for market research and statistical purposes.

  • Categories of personal data: Purchase data, app configuration data; log data for surveys by third parties
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO):
    We have a legitimate economic interest in expanding our product portfolio for further customers so that they can statistically understand the buying behavior of defined consumer groups, assess supply gaps or the effects of price changes and thus make product and service improvements.

    In particular, our legitimate interest lies in generating new sources of revenue through the new product and positioning ourselves more broadly in the market by expanding our product portfolio.

    Processing continues to serve the legitimate business interests of product customers in constantly adapting their product placement to the needs of consumers, which at the same time meets economic interests of market efficiency.

    You have the right to object to the processing of your personal data at any time and without giving reasons; please use the contact details in Section 15.

    As a result of the significantly reduced processing of personal data, the exclusively anonymized provision of this data and the granted unconditional right of objection, we have come to the conclusion that your interests do not prevail.

    In addition, please note your right to object when processing data for direct marketing purposes or for personal reasons (see Section 14.7”Your right to object to direct marketing” and section 14.8”Your right to object for personal reasons”).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA

5.3. If you have given us consent to carry out market surveys (see purpose 3.6) and to process pseudonymous user profiles (see purpose 5.1), we will, where appropriate, make the data processed through this consent available in anonymized form to third parties (market research companies, product manufacturers, retailers, etc.) for market research and statistical purposes.

  • Categories of personal data: Purchasing data, socio-demographic data
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO):
    We have a legitimate economic interest in expanding our product portfolio for further customers so that they can understand the buying behavior of defined consumer groups, assess supply gaps or the effects of price changes and thus carry out market research.

    In particular, our legitimate interest lies in generating new sources of revenue through the new product and positioning ourselves more broadly in the market by expanding our product portfolio.

    Processing continues to serve the legitimate business interests of market research companies and, directly or indirectly, product manufacturers to conduct market research, which at the same time meets economic interests of market efficiency.

    You have the right to object to the processing of your personal data at any time and without giving reasons; please use the contact details in section 15.

    As a result of the exclusively anonymized provision of a subset of the data processed with consent and the unconditional right of objection granted, we have come to the conclusion that your interests do not prevail.

    In addition, please note your right to object when processing data for direct marketing purposes or for personal reasons (see Section 14.7”Your right to object to direct marketing” and section 14.8”Your right to object for personal reasons”).
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA

5.4. Provision of personalized content and offers on our own channels (own portals, newsletters, other communication channels), personalization of surveys and our advertising activities on third-party sites

  • Categories of personal data: Master data, socio-demographic data, shopping data, competition data, app configuration data; log data for surveys by third parties, online usage data, log files
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia
      • IT service provider (provider of usage analysis technical monitoring tools), EU/EEA area, USA

6. IT security

6.1. Identification and, if necessary, blocking of users who have installed a so-called ad blocker and are thus blocking advertising

  • Categories of personal data: log files, ad blocker data
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in making our fully or partially ad-financed offers available only to users who do not block advertising
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA

6.2. Identifying faults and ensuring system security, including detecting and tracking illegal accesses and attempts to access our web servers

  • Categories of personal data: log files, online usage data
  • Legal basis of processing: Fulfilment of our legal obligations (Art. 6 para. 1 lit. c DSGVO) to comply with data security and legitimate interest (Art. 6 para. 1 lit. f DSGVO) in resolving faults, ensuring system security and detecting and tracking unauthorised access attempts or accesses
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA
      • IT service provider (hosting), EU/EEA area, USA
      • IT service provider (product support), Armenia

7. Legal

7.1. Compliance with legal storage obligations and other legal obligations (e.g. in connection with tax audits)

  • Categories of personal data: master data
  • Legal basis of processing: Fulfilment of our legal obligations (Art. 6 para. 1 lit. c GDPR), in particular with regard to the storage of certain information and in connection with tax audits; legitimate interest (Art. 6 para. 1 lit. f GDPR) in creating the conditions for compliance with legal obligations
  • Recipients or categories of recipients:
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA

7.2. Safeguarding and defending our rights

  • Categories of personal data: Details of litigation in which you are involved, information required to process the litigation
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in asserting and defending our rights
  • Recipients or categories of recipients:
    • Third party:
      • Our legal advisors (EU/EEA area, UK), courts, authorities
    • Contract processor:
      • IT service provider (technical support), EU/EEA area, USA

7.3. Sale of all or part of the business

  • Categories of personal data: all information relevant to the sale, e.g. registration data, declarations of consent, direct marketing
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f GDPR) in transferring customer data to the acquirer in connection with the sale of our business operations; as a rule, this requires that customers have agreed to a transfer of contract or have not objected to a transfer after sufficient information
  • Recipients or categories of recipients:
    • Third party:
      • Our legal advisors (EU/EEA area, UK), (potential) acquirers of (part of) business
    • Contract processor:
      • IT service provider (technical support), EU/EEA area
      • IT service provider (hosting), EU/EEA area, USA

4.2 Purposes of processing in connection with app identifiers

Processes based on app identifiers are integrated into this online offering. We participate in the “IAB Europe Transparency & Consent Framework” and comply with its specifications and guidelines. Below you will find information about the purposes for which we or our partners use app identifiers. You can find out more about this in our CMP, which can be found in the Bonsy app under “Privacy Settings”.

1. Store and/or retrieve information on a device

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (§ 25 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

2. Select simple ads. Ads can be shown to you based on the content you watch, the application you're using, and your approximate location or device type.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in displaying advertisements that are as interesting as possible for our users and therefore offer them added value; or consent
    (Art. 6 para. 1 lit. a GDPR); the specific legal basis used can be found in our CMP.
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

3. Create a personalized ad profile A profile can be created about you and your interests in order to show you personalized ads that are relevant to you.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

4. Select personalized ads. Personalized ads can be shown to you based on a profile created about you.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

5. Create a personalized content profile A profile can be created about you and your interests to show you personalized content relevant to you.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

6. Select personalized content. Personalized content can be shown to you based on a profile created about you.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

7. Measure display performance. The performance and effectiveness of ads that you see or interact with can be measured.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in the efficient display and billing of advertisements; or consent (Art. 6 para. 1 lit. a GDPR); the specific legal basis used can be found in our CMP.
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

8. Measure content performance. The performance and effectiveness of content that you see or interact with can be measured.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in displaying content that is as interesting as possible for our users and therefore offers them added value; or consent
    (Art. 6 para. 1 lit. a GDPR); the specific legal basis used can be found in our CMP.
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

9. Use market research to gain insights about target groups. Market research can be used to learn more about audiences who use services or applications and look at ads.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in better understanding target groups and optimising our own offering; or consent (Art. 6 para. 1 lit. a GDPR); the specific legal basis used can be found in our CMP.
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

10. Develop and improve products. Your data can be used to improve existing systems and software and develop new products.

  • Categories of personal data: Online usage data
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f DSGVO) in developing and improving our offering
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

11. Ensure security, prevent fraud, and fix errors. Your information can be used to identify and prevent fraudulent activity, and to ensure that systems and processes operate properly and securely.

  • Categories of personal data: Online usage data
  • Legal basis of processing: legitimate interest (Art. 6 para. 1 lit. f GDPR) in ensuring security, preventing fraud and eliminating errors
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

12. Provide advertisements or content technically. Your device can receive and send information that is necessary for you to see and use content and ads.

  • Categories of personal data: Online usage data, socio-demographic data
  • Legal basis of processing: Contract performance (Art. 6 para. 1 lit. b DSGVO): Provision of content; legitimate interest (Art. 6 para. 1 lit. f GDPR) in providing advertisements
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

13. Connect different devices. For use for one or more processing purposes, it can be determined whether different devices belong to you or your household.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

14. Receive and use automatically sent device properties for identification. Your device can be differentiated from other devices based on information that it automatically sends, such as an IP address or browser type.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

15. Use accurate location data. Your exact location data can be used for one or more processing purposes. This means that your location can be determined precisely down to a few meters.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

16. Actively query device properties for identification. Your device can be identified by querying its specific characteristics.

  • Categories of personal data: Online usage data, consents to the use of app identifiers
  • Legal basis of processing: Consent (Art. 6 para. 1 lit. a GDPR)
  • Recipient:
    Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details about the recipients of personal data. Under “Provider”, you will find information about which of our providers receive your personal data for this purpose.

4.3 Push messages

You may receive so-called push messages from us, even if you are not currently using this online offer. This may include messages that we send you as part of the performance of the contract (e.g. notice of service failure due to maintenance work), but also promotional information. You will only receive push messages of any kind if you have expressly consented to them. You can prevent receiving push messages at any time via the device settings on your device.

4.4 InApp messages

You may receive so-called in-app messages from us, but only if you use the app. This may include messages that we send you as part of the performance of the contract (e.g. notice of service failure due to maintenance work), but also promotional information. If you do not want to receive InApp messages, you should not use the app.

5. Note on data processing by app store operators

Collapse

Before you can install this app, you may need to conclude a user agreement with an app store operator (e.g. Google, Apple) for access to their portal (e.g. Google Play, App Store). In connection with the use of the app store, the app store operator collects and processes data such as user name, email address and individual device ID as the person responsible. We are not a party to the user agreement with the app store operator and have no influence on their data processing. In this respect, the privacy policy of the respective app store operator applies.

6. When do we transfer data to countries that are not part of the European Economic Area?

Collapse

We also share personal data with third parties or contract processors based in countries outside the European Economic Area (EEA).
Before such a transfer, we ensure that the recipient has an appropriate level of data protection — for example by:

  • eine Appropriateness decision by the EU Commission (Art. 45 GDPR),
  • the conclusion of EU standard contractual clauses (Art. 46 GDPR, module 1 or 2), with the implementation of so-called Transfer impact assessments (TIA) and, if applicable, Implementation of additional technical or organizational protective measures.

As far as possible, we specifically select providers who operate data centers in the EU or in the EEA to process and store personal data.

These are third parties or contract processors in the following countries: USA; Israel; Armenia.

For the USA, the European Commission has come to the conclusion that there is an appropriate level of data protection there, provided that the data recipient participates in the Data Privacy Framework (DPF) and has current certification for this purpose. Insofar as the recipients of your personal data are based in the USA and participate in the DPF, we therefore rely on this adequacy decision (Art. 45 GDPR).

To which countries outside the European Economic Area (if you are in the EEA) do we share data?

We disclose personal data to third parties or contract processors in the following countries where there is an adequate level of data protection under applicable law: USA (if the recipient is certified under the EU-U.S. Data Privacy Framework).

We also disclose personal data to third parties or contract processors in the following countries where there is no adequate level of data protection under applicable law. The transfer or notification is based on the respective security measure or exemption provision: USA (based on standard contractual clauses, unless the processor is certified in accordance with the U.S. Data Privacy Framework), Israel (Data Processing Addendum), based on standard contractual clauses), Armenia (standard contractual clauses).

We can provide you with an overview of recipients in third countries and a copy of the specifically agreed regulations to ensure an appropriate level of data protection. Please use the information in section 15 Contact”.

7. How long do we store your data?

Collapse

We store your data for as long as is necessary to provide our online offering and associated services or as long as we have a legitimate interest in continuing to store it. In all other cases, we delete your personal data with the exception of data that we must continue to keep in order to comply with legal (e.g. tax or commercial) retention periods (e.g. invoices).

We will block data that is subject to a storage period until the period expires.

Specifically, the following retention periods apply to personal data processed as part of this online offering:

  • Provision of the online offer: For the duration of registration; if the user requests that the user account be deleted, it will be permanently deleted within 10 days; any legal storage periods will be met.
  • Identification of the country of receipt: The data required for this (IP addresses) is stored by our service provider 14 days after transmission and then deleted. We only store information about the country together with the receipt.
  • Provision of contact options, informational emails and messages: Until the communication is completed and then for a further three years, starting at the end of the calendar year.
    It is no longer necessary to achieve the purpose of the collection and there are no legal storage requirements.
    In the context of contact requests that have not led to a contractual relationship, this is generally the case if the circumstances show that the specific issue has been finally dealt with.
  • Bereitstellung des KI-Assistenten: 90 Tage nach Abschluss des Chat-Verlaufs zur Fehleranalyse und Qualitätskontrolle
  • Sending newsletters and in-app/push messages: Storage until the data is no longer required to achieve the purpose and there are no legal storage requirements.
    As part of sending the newsletter, this is usually the case if you withdraw your consent or object to processing.
  • Carrying out surveys or collecting feedback: Until the survey is completed and then for a further six months, starting at the end of the calendar year (in the case of consent-based processing, maximum until consent is withdrawn).
  • Carrying out market research and market surveys:
    • When we Your consent have received:
      • Storage until the data is no longer required to achieve the purpose and there are no legal storage requirements.
        As part of carrying out market research and market surveys, this is usually the case if you withdraw your consent or object to processing.
    • When we use pseudonymous data due to our legitimate interest process:
      • We store this data in pseudonymous form for a maximum of 2 years. We also store this data in anonymized form in order to evaluate it for internal, statistical purposes.
  • IT security: Log files: depending on the system (7 days to 13 months) and as long as there was no security incident that requires longer storage.
  • Legal: Storage until the data is no longer required to achieve the purpose and there are no legal storage requirements.
    In the context of legal disputes, this is the case when the legal disputes have been finally settled.
  • Consent to the use of app identifiers (and related data processing processes): Our CMP, which can be found in the Bonsy app under “Privacy Settings”, contains details on the storage periods of personal data. Under “Provider”, you will find information on how long the personal data collected will be stored.

8. Are you required to provide us with personal data?

Collapse

In principle, you are not required to provide us with your personal data. However, the use of certain services on this online offering may require the provision of personal data, e.g. registration. If this is the case, we will let you know. Mandatory fields are regularly marked with an *. If you do not wish to provide us with the necessary data, you will unfortunately not be able to use the corresponding services.

9. App Identifier

Collapse

This online offer uses app identifiers.

App identifiers are randomly generated identifiers that are assigned by the operating system of your device. They are shared with the servers of our apps that you use to enable your device to be recognized.

Detailed information about app identifiers can be found in our Consent Management Platform (CMP), which can be found in the Bonsy app under “Privacy Settings”. Insofar as personal data is processed in connection with processes based on these technologies, you will also find more detailed information on the purposes pursued there.

In some cases, app identifiers are absolutely necessary so that we can securely provide our online offering in the way you want. In this case, we may use the app identifier without your consent. For all other uses of app identifiers, we ask for your consent in our CMP. You can issue this via our CMP and revoke it at any time with effect for the future by adjusting the saved settings. You can delete app identifiers in the settings of your device. Please note that without the use of app identifiers, this online offer may not work or may only work to a limited extent.

If you use our online offer as a registered user while logged in, we will adopt your privacy settings, which are stored in your user profile. This data comes from your CMP settings before you log in to one of our services for the first time and is updated when the privacy settings in the respective CMP are logged in. Please note that additional services will only be updated after the respective online offer has been reloaded, e.g. opening the app. Please also note that a consent decision that you have submitted while logged out is only valid when logged out, as we are unable to assign it to your user profile. If you would like to change your privacy settings in your user profile, we therefore ask you to log in first.

10. Share features

Collapse

Your mobile device allows you to share content from the app with third parties (e.g. via email, SMS or via the share functionalities of social networks). We have no influence on the associated processing of data, e.g. by providers of social networks. The respective third party providers are solely responsible for this.

11. Registration/login via 7Pass

Collapse

Wir bitten Ihnen die Möglichkeit, unser Online-Angebot sowohl ohne Registrierung (im „Gast-Modus“) als auch durch die Erstellung eines persönlichen Nutzerkontos zu nutzen.

Bei einer Nutzung ohne Nutzerkonto werden Ihre erfassten Kassenbondaten und Statistiken technisch lediglich mit der individuellen Kennung Ihres Endgeräts verknüpft. Dies bedeutet, dass Ihre Daten lokal an das jeweilige Endgerät gebunden sind. Im Falle eines Gerätewechsels oder einer Neuinstallation des Online-Angebots können diese Informationen nicht auf ein neues Gerät übertragen werden, da für unser System in diesem Fall ein neues, technisch nicht zuordenbares Profil entsteht. Eine Wiederherstellung Ihrer Daten ist im Gast-Modus daher nicht möglich.

Durch die Registrierung eines Benutzerkontos werden Ihre Daten hingegen Ihrem Nutzerkonto zugeordnet. Dies bietet Ihnen den Vorteil, Ihre Kassenbons und Statistiken bei einem Gerätewechsel einfach zu übernehmen und geräteübergreifend zu synchronisieren. Darüber hinaus profitieren Sie als registrierte:r Nutzer:in von einem erweiterten Funktionsumfang.

Nähere Informationen zu den Funktionen des Online-Angebots finden Sie in den FAQ: https://www.bonsy.com/faq

12. Sign-in services (login via third party provider)

Collapse

12.1 Registration/login via Facebook (Facebook login)

We offer you the option to register or log in to us using your Facebook account. If you make use of this, we receive the data required for registration or login from Meta Platforms, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, 2 Dublin Ireland (“Facebook”) (e.g.. email address, name).

We have no influence on the amount of data collected by Facebook via the Facebook login. If you do not want Facebook to collect data about you in connection with your use of our online offering and use it for its own purposes, you should not use the Facebook login.

Further information about the purpose and scope of the collection and the further processing and use of your data by Facebook as well as about your rights and settings options to protect your data can be found in the Privacy notices from Facebook.

12.2 Registration/login via Google

We offer you the option to register or log in to us using your Google account. If you make use of this, we receive the data required for registration or login from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) (e.g. email address, name).

We have no influence on the amount of data collected by Google using the Google login. If you do not want Google to collect data about you in connection with your use of our online offering and use it for its own purposes, you should not use the Google login.

Further information about the purpose and scope of the collection and the further processing and use of your data by Facebook as well as about your rights and settings options to protect your data can be found in the Privacy notices from Google.

12.3 Registrierung/Anmeldung über Apple („Sign in with Apple“)

Wir bieten Ihnen die Möglichkeit, sich über Ihre Apple ID bei uns zu registrieren bzw. anzumelden. Wenn Sie hiervon Gebrauch machen, erhalten wir die für die Registrierung bzw. Anmeldung benötigten Daten von der Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Irland („Apple“) (z. B. Name, E-Mail-Adresse).

Apple bietet Ihnen im Rahmen dieses Dienstes die Funktion „E-Mail-Adresse verbergen“ an, mit der Sie eine eindeutige, zufällige E-Mail-Adresse erstellen können, sodass Ihre persönliche E-Mail-Adresse privat bleibt.

Wir haben keinen Einfluss auf den Umfang der von Apple mittels dieses Dienstes erhobenen Daten. Wenn Sie nicht möchten, dass Apple im Zusammenhang mit Ihrer Nutzung unseres Online-Angebots Daten über Sie erhebt und für eigene Zwecke nutzt, sollten Sie den Login über Apple nicht verwenden.

Weitere Informationen über Zweck und Umfang der Erhebung sowie die weitere Verarbeitung und Nutzung Ihrer Daten durch Apple sowie zu Ihren Rechten und Einstellungsmöglichkeiten zum Schutz Ihrer Daten finden Sie in den Datenschutzhinweisen von Apple: https://www.apple.com/de/legal/privacy/data/de/sign-in-with-apple/.

13. Newsletters and other direct marketing via electronic mail

Collapse

13.1 Newsletter with registration and other direct marketing via electronic mail

We offer you the option to subscribe to a newsletter or to consent to receive other forms of direct marketing via electronic mail (e.g. by email, MMS, messenger message or SMS). You can your The corresponding consent can be withdrawn at any time with effect for the future. For information on this, see”Your right to withdraw consent”.

13.2 Newsletters and other direct marketing via electronic mail without registration

If we receive your email address in connection with the sale of a good or service and you have not objected to this, we reserve the right to send you regular offers for similar goods or services from our portfolio by electronic mail. You can the Disagree anytime, at no cost to you; information on this can be found in the “Your right to object to direct marketing” section.

13.3 Personalized direct marketing

We offer you the option of receiving personalized newsletters or other forms of personalized direct marketing that is specifically tailored to your interests. We obtain your separate consent to process your data for personalization. The categories of data that we want to use for personalization are described in the consent statement. You can your The corresponding consent can be withdrawn at any time with effect for the future. For information on this, see”Your right to withdraw consent”.

14. Your rights (rights of the person concerned)

Collapse

14.1 How can you assert your rights?

Please use the information in section 15 to assert your rights Contact”. Please ensure that we are able to uniquely identify you.

Alternatively, you can also use the settings options in your user account to correct the data you provided during registration or to object to advertising. In addition, you can use the “Unsubscribe” link at the end of each email.

You can adjust your settings for app identifiers and the data processing based on them at any time in our consent management platform, which can be found in the Bonsy app under “Privacy Settings.”

You can also delete your user account yourself by following these steps: In your profile menu, click on the “Account” section to access the account settings. To delete your account, simply click on the red button”Delete user account”.

14.2 Your rights to information and correction

You can request that we confirm to you whether we are processing personal data relating to you and you have a right of access to your data processed by us. If your data is incorrect or incomplete, you can request that your data be corrected or completed. If we have passed on your data to third parties, we will inform them of the correction, insofar as this is required by law.

14.3 Your right to delete

If the legal requirements are met, you can request us to delete your personal data immediately. This is particularly the case when

  • your personal data is no longer required for the purposes for which it was collected;
  • the legal basis for processing was exclusively your consent and you withdrew it;
  • you have objected to processing for advertising purposes (“advertising objection”);
  • you have objected to processing based on the legal basis Legitimate interest for personal reasons and we cannot prove that there are overriding legitimate reasons for processing;
  • your personal data has been processed unlawfully; or
  • Your personal data must be deleted to comply with legal requirements.

If we have passed on your data to third parties, we will inform them of the deletion, insofar as this is required by law.

Please note that your right to delete is subject to restrictions. For example, we do not have to or may not delete any data that we still have to keep due to legal retention periods. Data that we need to assert, exercise or defend legal claims is also excluded from your right of deletion.

14.4 Your right to restrict processing

If the legal requirements are met, you can demand that we restrict processing. This is particularly the case when

  • the accuracy of your personal data is disputed by you, and then until we have had the opportunity to verify the accuracy;
  • the processing is not lawful and you request a restriction of use instead of deletion (see previous section);
  • we no longer need your data for processing purposes, but you need them to assert, exercise or defend your legal claims;
  • You have filed an objection for personal reasons, and then until it is clear whether your interests prevail.

If there is a right to restrict processing, we mark the data concerned to ensure in this way that it is only processed within the narrow limits that apply to such restricted data (namely in particular to defend legal claims or with your consent).

14.5 Your right to data portability

You have the right to receive personal data that you have given us to fulfill the contract or on the basis of consent in a structured, common and machine-readable format. In this case, you can also request that we transfer this data directly to a third party, insofar as this is technically feasible.

14.6 Your right to withdraw consent

If you give us a consent into which If you have given consent to the processing of your data, you can revoke this at any time with effect for the future. The lawfulness of processing your data until you withdraw your consent remains unaffected.

14.7 Your right to object to direct marketing

You can also object to the processing of your personal data for advertising purposes at any time (“advertising objection”). Please note that, for organizational reasons, there may be an overlap between your objection and the use of your data as part of an ongoing campaign.

14.8 Your right to object for personal reasons

You have the right to object to data processing by us for reasons arising from your particular situation, insofar as this is based on legitimate interest. We will then stop processing your data.

14.9 Your unconditional right to object to certain processing activities

Insofar as data processing is based on legitimate interest, you have the right, at any time and without giving reasons, (i) to carry out market surveys (see purpose 3.6 in section 4.1), (ii) to combine your personal data collected when using the product to create pseudonymous user profiles for market research purposes and for statistical purposes (see purpose 5.2 in section 4.1) and (iii) to provide your data, which we provide based on your consent to carry out of market surveys (see purpose 3.6 in section 4.1) and for the processing of pseudonymous user profiles (see purpose 5.1 in section 4.1), to object in anonymized form to third parties for market research purposes and for statistical purposes (see purpose 5.3 in section 4.1).

14.10 Your right to lodge a complaint with a supervisory authority

You have the right to file a complaint with a data protection authority. In particular, you can contact the data protection authority that is responsible for your place of residence or federal state or which is responsible for the place where the violation of data protection law took place. Alternatively, you can also contact the data protection authority responsible for us.

15. contact

Collapse

For information and suggestions on the subject of data protection, we or our data protection officer are available to you at the email datenschutz@bonsy.com gladly available.

You can also contact our data protection officer at the following postal address:

Maximilian Hartung
EDPS — Data Protection Officer
SECUWING GmbH & Co. KG | Datenschutzagentur.de
Frauentorstrasse 9
86152 Augsburg Germany
epost@datenschutz-agentur.de

T +49 (0) 821 90786450

If you would like to get in touch with us by other means, you can also reach us as follows:

marktguru Germany GmbH
Sendlinger Strasse 23
D — 80331 Munich