Privacy Policy
This privacy policy informs you about the processing of your personal data in connection with our CPTx website.
Name and contact details of the controller
The responsible data controller is CPTx GmbH (hereinafter referred to as “CPTx” or just “we”, “us”, etc.).
Our contact details are:
• Semmelweisstr. 1, 82152 Planegg, Germany
• info@cptx.bio
CPTx’ processing of your personal data is regulated by the European Union’s General Data Protection Regulation (“GDPR”).
General information on processing of personal data
We collect and process personal data in different ways. The personal data is voluntarily provided by the website user when creating and / or changing a user account, or when interacting with us using the website or by email communication. This includes the following information: name, email address, quotes requested, orders placed, parts or our website visited, browser type, IP address.
For what purposes do we process your personal data?
a) Technical operation of the website
If you use our website, we process technical data about your use, namely
• the pages of our website being accessed,
• information about the type of browser and the browser version,
• the user’s operating system,
• the user’s internet service provider,
• the user’s IP address,
• date and time of access,
• referring websites, if any.
We use these data to operate the website, to identify and solve potential technical problems, and to further improve the functionality of the website. Latest one week after your use of the website these data will be deleted or anonymised.
The legal bases for this processing are Art. 6(1)(f) GDPR (balancing of interests, based on our legitimate interest to provide you with the functions of the website) and Art. 6(1)(b) GDPR (contract initiation and contract fulfillment).
b) Account registration
When you create an account, we collect your name, your email address, your password, and any additional information you may provide via the website while you are logged in.We use your personal data to provide our services, and for communication purposes relating to your requests for a quote and/or orders. The legal bases for this customer service are Art. 6(1)(f) GDPR (balancing of interests, based on our legitimate interest to provide you with the functions of the website) and Art. 6(1)(b) GDPR (contract initiation and contract fulfillment).
c) Quotes and orders
When you request a quote or place an order via the website we process your name and contact data as well es your quotation or order data to offer, and if ordered to provide, our products and services. The legal basis for this processing is Art. 6(1)(b) GDPR (contract initiation and contract fulfillment)
d) Marketing
We may use your contact information and quotation or order history to send you general information about the products and services we offer. You can unsubscribe from these notifications at any time. The legal basis for this processing is Art. 6(1)(f) GDPR (balancing of interests, based on our legitimate interest to advertise our products and services).
e) Compilation of statistical data
We use your personal data in an anonymous and aggregated form to monitor which functions of the website are used most, to analyse usage patterns and to determine how the website might be improved. The legal basis for this processing is Art. 6(1)(f) GDPR (balancing of interests, based on our legitimate interest to improve our website and our associated services).
f) Google Analytics
We may use the analytics tool “Google Analytics” to help us better understand how Users interact with the App/Webshop. Google Analytics is a service provided by Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA, hereinafter referred to as “Google”).Google Analytics transmits information on your App usage to Google servers in the USA, where they are stored for up to 14 months.
Currently there is no decision of the EU Commission that the USA generally provide an adequate level of protection for personal data. Google undertakes, however, to comply with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks (DPF) and the UK Extension to the EU-U.S. DPF as set forth by the US Department of Commerce regarding the collection, use and retention of personal information from the EEA, Switzerland and the UK, respectively (see https://policies.google.com/privacy/frameworks?hl=en). Data transmitted to the USA in connection with Google Analytics are further protected by the fact that the data are – if they are personal data at all – pseudonymous data which cannot be easily attributed to your person.
More information on the handling of user data within Google Analytics is available in Google’s privacy notice at https://support.google.com/analytics/answer/6004245?hl=enThe legal basis for this processing is Art. 6(1)(a) GDPR (consent).
You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
g) No obligation to provide personal data
You are not obliged to provide your personal data. Without your personal data, however, we cannot provide our services to you.
External service providers
We may use various external services providers to operate the website. To the extent it is necessary these service providers also process personal data. We diligently select and supervise our service providers. They process the data only in accordance with our instructions and are also bound by this privacy statement.
One of these external service providers is Webflow, Inc., located at 398 11th Street, San Francisco, CA 94103, USA ("Webflow"), which we use to operate this website. You can find additional information on how Webflow processes your personal data at https://webflow.com/legal/privacy.
Information about your right to object in accordance with article 21 GDPR
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR, including profiling based on those provisions. We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. If you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
Your other rights
Upon request, we will inform you if and which data we have stored about you. If the legal requirements are met, you have the right to correct, block, or delete these data. You also have the right to receive from us a copy of the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format. You have the right to transmit (or have transmitted) those data to another controller. You also have the right to lodge a complaint with a supervisory authority for data protection matters.
Data retention
Unless otherwise stated in this privacy policy, we will store your data until you terminate and delete your website account. If you would like to delete your website account or request that we no longer use your data, please contact us at the address given above. If your data are not necessary to comply with legal obligations or to settle disputes, we will delete your personal data after deleting your account.