top of page

Data Privacy

1. Privacy Policy Overview

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data includes all data that can personally identify you. Detailed information on data protection can be found in our privacy policy below.

Data Collection on Our Website

Who is responsible for data collection on this website?

  • The data processing on this website is carried out by the website operator. You can find the operator's contact details in the "Responsible Party" section of this privacy policy.

  • How do we collect your data?
    Your data is collected in two ways:
    1. Data you provide to us – This includes data that you enter into a contact form, for example.
    2. Automatically collected data – When you visit the website, certain data is automatically collected or recorded with your consent by our IT systems. This includes technical data such as your internet browser, operating system, or the time of page access. This data is collected automatically as soon as you enter our website.

  • Wofür nutzen wir Ihre Daten?
    Some data is collected to ensure the website functions correctly. Other data may be used to analyze user behavior. If transactions can be initiated or completed through the website, transmitted data will also be processed for contract offers, orders, or other inquiries.
     

  • Welche Rechte haben Sie bezüglich Ihrer Daten?
    You have the right to receive free information about the origin, recipient, and purpose of your stored personal data at any time. You also have the right to request correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time. Additionally, under certain circumstances, you can request that we restrict the processing of your personal data. You also have the right to file a complaint with the relevant regulatory authority.

For questions regarding data protection, you may contact us at any time.

Analysis Tools und Third-Party Tools

When you visit this website, your browsing behavior may be analyzed statistically. This happens mainly through analytics programs. Detailed information on these analytics programs can be found in the privacy policy below.

​​

2. Hosting

We host our website with the following provider:

WIX
The provider is Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel (hereinafter referred to as “WIX”). WIX is a tool for creating and hosting websites. When you visit our website, WIX analyzes user behavior, visitor sources, visitor locations, and visitor numbers.

WIX stores cookies on your browser, which are necessary for the website display and security (essential cookies). The data collected through WIX may be stored on various servers worldwide, including in the USA.

 

For more details, please refer to WIX's privacy policy:

https://de.wix.com/about/privacy.

According to WIX, data transfers to the USA and other third countries are based on the EU Commission’s Standard Contractual Clauses (SCCs) or comparable guarantees under Art. 46 DSGVO. More information: https://de.wix.com/about/privacy-dpa-users.

The use of WIX is based on Art. 6 Abs. 1 lit. f DSGVO – we have a legitimate interest in a reliable website display. If consent has been requested, processing occurs based on Art. 6 Abs. 1 lit. a DSGVO and § 25 Abs. 1 TDDDG. Insofar as the consent includes the storage of cookies or access to information on the end device of the user (e.g., device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.

WIX is certified under the EU-US Data Privacy Framework (DPF), which ensures compliance with European data protection standards for processing data in the USA. More information:
https://www.dataprivacyframework.gov/participant/5626
 

Data Processing Agreement (DPA)We have entered into a Data Processing Agreement (DPA) with WIX to ensure that personal data of our website visitors is processed strictly in accordance with our instructions and in compliance with the DSGVO.​

3. General Information and Mandatory Disclosures

 

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy. When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. The present privacy policy explains which data we collect and what we use them for. It also explains how and for what purpose this happens. We point out that data transmission on the internet (e.g., when communicating via email) can have security vulnerabilities. A seamless protection of data from access by third parties is not possible.

​​

Responsible Party

The party responsible for data processing on this website is: 

Bonanso Change Collective GmbH

Lohmühlenstraße 65

12435 Berlin

​E-Mail: annsophie@changepath.ai

Phone Number: +49 151 27001257

​​​

Storage Duration

Unless otherwise specified within this privacy policy, your personal data remains with us until the purpose for data processing ceases. If you request deletion or revoke consent, your data will be deleted unless legally permitted reasons require storage (e.g., tax or commercial retention obligations). In such cases, deletion will occur once the legal retention period expires.

​​

General Information on the Legal Bases for Data Processing on This Website

If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a DSGVO or Art. 9 para. 2 lit. a DSGVO, insofar as special categories of data are processed in accordance with Art. 9 para. 1 DSGVO. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 para. 1 lit. a DSGVO.

If you have consented to the storage of cookies or access to information on your end device (e.g., via device fingerprinting), data processing additionally takes place on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time.

If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b DSGVO. Furthermore, we process your data if this is necessary for the fulfillment of a legal obligation on the basis of Art. 6 para. 1 lit. c DSGVO. Data processing may also take place on the basis of our legitimate interest in accordance with Art. 6 para. 1 lit. f DSGVO. The relevant legal bases applicable in each individual case are explained in the following sections of this privacy policy.

Recipients of Personal Data

As part of our business activities, we work with various external entities. In some cases, the transfer of personal data to these external entities is necessary. We only pass on personal data to external parties if this is required for contract fulfillment, if we are legally obliged to do so (e.g., transmission of data to tax authorities), if we have a legitimate interest in the transfer according to Art. 6 para. 1 lit. f DSGVO, or if another legal basis permits the transfer of data.

When using data processors, we only pass on personal data of our customers on the basis of a valid data processing agreement. In the case of joint processing, a contract for joint processing is concluded.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke a previously given consent at any time. The legality of data processing carried out before the revocation remains unaffected by the revocation.​

Right to Object to Data Collection in Special Cases and to Direct Advertising (Art. 21 DSGVO)

IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F DSGVO, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS.

The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims (objection under Art. 21 para. 1 DSGVO).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES; THIS ALSO APPLIES TO PROFILING, INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT MARKETING.

If you object, your personal data will no longer be used for direct advertising purposes (objection under Art. 21 para. 2 DSGVO).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the DSGVO, the affected parties have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, their workplace, or the location of the alleged violation. This right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.​

Right to Data Portability

You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to yourself or to a third party in a common, machine-readable format. If you request the direct transfer of data to another responsible party, this will only be done insofar as it is technically feasible.​

Access, Rectification, and Deletion

Within the framework of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of data processing and, if necessary, the right to rectify or delete this data. You can contact us at any time regarding this or other questions on the subject of personal data.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
 

  • If you dispute the accuracy of your stored personal data, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.

  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.

  • If we no longer need your personal data, but you require it for the exercise, defense, or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.

  • If you have lodged an objection pursuant to Art. 21 para. 1 DSGVO, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
     

If you have restricted the processing of your personal data, such data—apart from its storage—may only be processed with your consent or for the assertion, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
​​

4. Data Collection on This Website

Cookies

Our websites use so-called "cookies." Cookies are small data packets and do not cause any damage to your end device. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your end device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or an automatic deletion is carried out by your web browser.

Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies allow the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).

Cookies serve different functions. Numerous cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to analyze user behavior or for advertising purposes.

Cookies that are required for carrying out the electronic communication process, providing certain functions you desire (e.g., for the shopping cart function), or optimizing the website (e.g., cookies for measuring web audience) are stored on the basis of Art. 6 para. 1 lit. f DSGVO, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent for the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively based on this consent (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDDG); consent can be revoked at any time.

You can configure your browser to inform you about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Which cookies and services are used on this website can be found in this privacy policy.

Inquiry by Email, Telephone, or Fax

If you contact us by email, telephone, or fax, your inquiry, including all personal data arising from it (e.g., name, request), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.

The processing of this data takes place based on Art. 6 para. 1 lit. b DSGVO, if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f DSGVO) or on your consent (Art. 6 para. 1 lit. a DSGVO), if requested; consent can be revoked at any time.

The data you send to us via contact inquiries will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions—especially statutory retention periods—remain unaffected.

5. Newsletter

Newsletterversand an Bestandskunden

If you order goods or services from us and provide your email address, this email address may subsequently be used by us to send newsletters, provided that we have informed you about this in advance. In such a case, only direct advertising for our own similar goods or services will be sent via the newsletter.

You can unsubscribe from this newsletter at any time. For this purpose, a corresponding link is included in every newsletter. The legal basis for sending the newsletter in this case is Art. 6 para. 1 lit. f DSGVO in conjunction with § 7 para. 3 UWG.

After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist by us to prevent future mailings to you. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your and our interest in complying with the legal requirements for sending newsletters (legitimate interest in accordance with Art. 6 para. 1 lit. f DSGVO). Storage in the blacklist is not time-limited. You may object to storage if your interests outweigh our legitimate interest.

6. Plugins und Tools

 

Google Fonts (lokales Hosting)

This website uses Google Fonts for uniform font display. The Google Fonts are installed locally, and no connection to Google servers is established. More information about Google Fonts can be found here:
https://developers.google.com/fonts/faq and in the privacy policy from Google: https://policies.google.com/privacy?hl=de.

Mailchimp

We use Mailchimp, a service provided by Intuit Inc., 2700 Coast Ave, Mountain View, CA 94043, USA, for sending newsletters. Mailchimp stores and processes personal data (e.g., name, email address) on servers in the USA.

  • Purpose of Processing: The sending and analysis of our newsletter is handled via Mailchimp. Mailchimp allows us to analyze user behavior, such as whether an email was opened or a link was clicked.

  • Legal Basis: Processing is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time by clicking the "Unsubscribe" link in our emails.

  • Data Transfer: The transfer of personal data to the USA is based on the EU Commission's Standard Contractual Clauses.

  • More information can be found in the data policy from Mailchimp: https://www.intuit.com/privacy/statement/

Klaviyo

For email marketing and automation, we use Klaviyo, a service provided by Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA 02110, USA.

  • Purpose of Processing: Processing is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO.

  • Legal Basis: Die Verarbeitung erfolgt auf Grundlage Ihrer Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO.

  • Data Transfer: Data processing takes place partially in the USA. Klaviyo ensures compliance with DSGVO, including through Standard Contractual Clauses.

  • More information can be found in the data policy from Klaviyo: https://www.klaviyo.com/privacy

ChatGPT (OpenAI API)

For automated support and responses to inquiries, this website may use ChatGPT, provided by OpenAI, 3180 18th Street, San Francisco, CA 94110, USA.

  • Purpose of Processing: OpenAI processes text inputs to provide personalized information or automated responses to users.

  • Legal Basis: Use is based on our legitimate interest in providing fast and efficient customer service (Art. 6 para. 1 lit. f DSGVO).

  • Data Processing: Interactions with ChatGPT are processed but not permanently stored or personally analyzed.

  • Data Transfer: OpenAI may process data outside the EU. Transfers occur in compliance with Art. 46 DSGVO (Standard Contractual Clauses).

  • More information can be found in the data policy from OpenAI: https://openai.com/privacy

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

 

  • Purpose of Processing: Google Analytics allows us to analyze user behavior on our website to improve user-friendliness and website performance. Google Analytics uses cookies that collect information about the use of our website (e.g., pages visited, time spent on the site, origin of visitors).

  • IP Anonymization: We have activated IP anonymization. As a result, your IP address is shortened by Google within the EU before it is transferred to the USA.

  • Legal Basis: Data processing is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDDG (when using cookies or device fingerprinting). You can revoke your consent at any time via our cookie banner

  • Data Transfer: The transfer of personal data to the USA is based on the EU Commission’s Standard Contractual Clauses.

  • Opt-Out Option: You can prevent the collection of your data by Google Analytics by installing a browser add-on: https://tools.google.com/dlpage/gaoptout.

  • More information can be found in the data policy from Google: https://policies.google.com/privacy

Zapier

We use Zapier, an automation service provided by Zapier Inc., 548 Market St. #62411, San Francisco, CA 94104, USA, to connect various software services and automatically synchronize data.

 

  • Purpose of Processing: Zapier allows us to set up automated workflows between different applications (e.g., automatically transferring contact form inquiries to a CRM system or a newsletter list). In doing so, Zapier may process personal data (e.g., name, email address).

  • Legal Basis: The use of Zapier is based on our legitimate interest in efficient automation of business processes (Art. 6 para. 1 lit. f DSGVO). If consent is required (e.g., for newsletter sign-ups), processing is carried out based on Art. 6 para. 1 lit. a DSGVO.

  • Data Transfer: Since Zapier is a company based in the USA, data may be transferred to the USA. The transfer is based on Standard Contractual Clauses in accordance with Art. 46 DSGVO.

  • More information can be found in the data policy from Zapier: https://zapier.com/privacy

SOURCE: www.erecht24.de

bottom of page