Data privacy policy by eXXcellent solutions according to art. 13 and 14 GDPR.
We, eXXcellent solutions GmbH (hereinafter "eXXcellent solutions" or "we" or "us"), take the protection of your personal data very seriously and respect the rules provided by the data privacy laws.
The protection of your personal identifiable data that we gather, process and use due to your visit of our website www.easy-ssp.com (orchideo | easySSP) is an important matter to us. Your data is protected within the framework of existing legislation. Subsequently, you will find information on which data is gathered during your visit and how it is used.
The responsible authority in terms of data privacy law is:
eXXcellent solutions GmbHE-mail: Datenschutz@exxcellent.de
CEO: Dr. Martina Burgetsmeier, Gerhard Gruber, Wilhelm Zorn
Office and register court: Ulm, HRB-Nr. 4309
The operational appointed data privacy officer of eXXcellent solutions GmbH, Mr. Brauch, is available under the above mentioned address and via e-mail at Datenschutz@eXXcellent.de.
Personal data consists of all information related to an identified or identifiable natural person that is an expression of a person's identity, including but not limited to names, addresses, phone numbers, e-mail addresses, contract accounting and payment data.
We collect, process and use personal data (including IP addresses) only when there is either a statutory legal basis to do so or if you have given your consent to the processing or use of personal data concerning this matter, e.g. by means of registration.
When visiting our website www.easy-ssp.com your browser will gather and transfer the following information automatically to the server. If you use the website without registration, only the following personal data will be stored.
This data is required for a proper performance of services. Storage takes place exclusively in a server log file for own security purposes (e.g. identification of DOS attacks) and for a maximum duration of 3 months.
The legal basis for data processing is art. 6 GDPR. Our valid interest ensues from the above listed purposes for data gathering. Data gathered will not be used to identify the person in any way.
In the case of registration, further data such as the user's name and e-mail address are collected. This data is required for a functional registration.
If a chargeable service is used, further data such as company information (e.g. the company name) and necessary information regarding the payment method are stored.
We, as well as the service providers commissioned by us, process your personal data for the following processing purposes:
This website uses cookies. Cookies are small text files containing user-specific data and settings that are stored on your device. On the one hand, they serve the purpose of user friendliness, and on the other hand, they are used for statistical evaluation of site usage. The data processed by cookies are necessary for the aforementioned purposes to protect our legitimate interests as well as those of third parties in accordance with art. 6 GDPR. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or a notice always appears before a new cookie is created. Nevertheless, the complete deactivation of cookies may result in restrictions of the use of our website.
You can edit your cookie choices at any time in the cookie settings.
These cookies are essential in order to enable you to navigate the website and use its features, such as setting your privacy preferences, logging in or filling in forms. Without these cookies, services requested through usage of our website cannot be properly provided. Strictly necessary cookies do not require consent from the user under applicable law.
These cookies allow the website to remember choices you make or information you enter (such as
your username, language or the region you are in) and provide enhanced, more personal features.
They are also used to enable requested functions such as playing videos.
To the extent that information processed with regards to functional cookies should, in a given
case, qualify as personal data, the legal ground for that processing is the user’s consent.
These cookies collect information about how visitors use a website, for instance which pages
visitors go to most often, and how visitors move around the site. They help us to improve the
user friendliness of our website and therefore enhance the user’s experience.
Further information collected by performance cookies may include e.g.: internet browser and
operating system used, the domain name of the website which you previously visited, the number
of visits, average duration of visit, and which pages were visited.
The information collected by these cookies is aggregated and normally cannot be linked to a
specific natural person. To the extent that information processed in connection with performance
cookies should, in a given case, qualify as personal data, the legal ground for that processing
is the user’s consent.
Marketing cookies (also referred to as targeting or advertising cookies) are used to deliver
adverts on third party websites more relevant to you and your interests. They are also used to
limit the number of times you see an advertisement as well as help measure the effectiveness of
an advertising campaign.
Legal basis for the processing of personal data in connection with marketing cookies (if any) is
the user’s consent.
We use Google Analytics to collect data and track how the user interacts with our website. We use this data to
improve the design and usability of our web services. We will provide more information about Google Analytics in a
following chapter.
You may find detailed information about the different cookies (e.g. purpose of the cookie and recipient of the information collected by the cookie) here:
Name | Description | Lifespan | Cookie Host |
---|---|---|---|
AWSALB | Used to direct the user requests to the same target server so that the user authentication mechanism works without errors. | 7 days | AWS |
AWSALBCORS | Used to direct the user requests to the same target server so that the user authentication mechanism works without errors. | 7 days | AWS |
AUTH_SESSION_ID | Used within the user authentication mechanism. | Session | KeyCloak |
AUTH_SESSION_ID_LEGACY | Used within the user authentication mechanism. | Session | KeyCloak |
COOKIE_CONSENT | Used to store that the user has set his cookie preferences. | 1 year | easySSP |
GOOGLE_ANALYTICS_CONSENT | Used to store the users cookie prefference regarding Google Analytics. | 1 year | easySSP |
KC_RESTART | Used within the user authentication mechanism. | Session | KeyCloak |
KEYCLOAK_IDENTITY | Used within the user authentication mechanism. | Session | KeyCloak |
KEYCLOAK_IDENTITY_LEGACY | Used within the user authentication mechanism. | Session | KeyCloak |
KEYCLOAK_SESSION | Used within the user authentication mechanism. | 10h/16h | KeyCloak |
KEYCLOAK_SESSION_LEGACY | Used within the user authentication mechanism. | 10h/16h | KeyCloak |
_oauth2_proxy | Used within the user authentication mechanism. | 2h | OAuth2Proxy |
KEYCLOAK_LOCALE | Used to set the user language on a page. | Session | easySSP/KeyCloak |
Name | Description | Lifespan | Cookie Host |
---|---|---|---|
_ga | Used to distinguish users. | 2 years | easySSPGoogle Analytics 4 |
_ga_"container-id" | Used to persist session state. | 2 years | easySSPGoogle Analytics 4 |
You can revoke your consent at any time with effect for the future by accessing the cookie settings and changing your selection there. The lawfulness of the processing carried out on the basis of the consent until the revocation remains unaffected.
You can also prevent the storage of cookies from the outset by setting your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in a restriction of functionalities on this and other websites.
The following Sections apply to various third-party services and consents that are integrated into our website and web app. Please note that information about cookies (and similar technologies) integrated into our website and services is contained in a separate cookie notice on this website, which is described in more detail in Section 4.
On our website, we integrate third-party content, such as fonts from www.myfonts.com. This always requires that the user's IP address is transmitted to these providers so that the provider can deliver the content to the user. We have no influence if the providers store this IP address and, for example, evaluate it statistically. Insofar as we are aware of this, we inform the users about it.
If you have given your consent, this website uses Google Analytics 4, a web analytics service provided by Google LLC. The responsible party for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
Google Analytics uses cookies that enable an analysis of your use of our websites. The information collected by means
of the cookies about your use of this website is generally transferred to a Google server in the USA and stored
there.
We use the User ID function. User ID allows us to assign a unique, persistent ID to one or more sessions (and the
activities within those sessions) and to analyze user behavior across devices.
Google Analytics 4 has IP address anonymization enabled by default. Due to IP anonymization, your IP address will be shortened by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
During your website visit, your user behavior is recorded in the form of "events". Events can be:On behalf of the operator of this website, Google will use this information to evaluate your use of the website and to compile reports on website activity. The reports provided by Google Analytics serve to analyse the performance of our website.
Insofar as data is processed outside the EU/EEA and there is no level of data protection corresponding to the European standard, we have concluded EU standard contractual clauses with the service provider to establish an appropriate level of data protection. The parent company of Google Ireland, Google LLC, is based in California, USA. A transfer of data to the USA and access by US authorities to the data stored by Google cannot be ruled out. The USA is currently considered a third country from a data protection perspective. You do not have the same rights there as within the EU/EEA. You may not be entitled to any legal remedies against access by authorities.
The data sent by us and linked to cookies are automatically deleted after 2 months. The deletion of data whose retention period has been reached occurs automatically once a month.
The legal basis for this data processing is your consent pursuant to Art.6 para.1 p.1 lit. a GDPR and Art.49a GDPR.
You can revoke your consent at any time with effect for the future by accessing the cookie settings and changing your selection there. The lawfulness of the processing carried out on the basis of the consent until the revocation remains unaffected.
You can also prevent the storage of cookies from the outset by setting your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in a restriction of functionalities on this and other websites. In addition, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google, by
a. not giving your consent to the setting of the cookie orFor more information on Google Analytics' terms of use and Google's privacy policy, please visit https://marketingplatform.google.com/about/analytics/terms/us/ and at https://policies.google.com/?hl=en.
Our Online Offers may contain links to internet pages of third parties, in particular providers who are not related to us. We have no influence on the collection, processing and use of personal data possibly transmitted by clicking on the link to the third party (such as the IP address or the URL of the site on which the link is located) as the conduct of third parties is naturally beyond our control.
Our employees and the companies providing services on our behalf, are obliged to confidentiality and to compliance with the applicable data protection laws.
We are using appropriate technical and organizational security measures to protect your data against accidental and intentional manipulations, partial or complete loss, destruction and unauthorized third party access. Our security measures are continuously improved according to technical developments.
Full data security cannot be guaranteed for e-mail communication, thus we recommend sending confidential information by mail.
Users can contact us based on data privacy law to retrieve free information about personal
identifiable information we store, and request closure and deletion as long as there is no
retention obligation.
You have the right to
If you would like to exercise your rights, e-mail to Datenschutz@exxcellent.de.
This data privacy policy was created based on regulations of different legislations including art. 13/14 EU-GDPR 2016/679. The data privacy policy is currently valid (April 2021) and refers exclusively to the website www.easy-ssp.com and the application contained therein, unless otherwise mentioned.