Thank you for visiting our website and for your interest in our company DR. KADE. The protection of your personal data is an important concern for us and we want you to feel safe when you visit our website. Here, we explain what information we collect when you visit our website and how this information is used.
Provision of our website
In order to enable the proper functioning of our website, data transmitted by your browser is processed during your visit. This includes your IP address, the date and time of the request, the time zone difference to Greenwich Mean Time (GMT), the content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, website (from which the request comes) browser, operating system and its interface, and language and version of the browser software.
If you send us inquiries via our contact forms on the website, we process the data you provide in order to be able to answer your inquiry.
You can register on our website and create a user account. Some of the services we offer may only be available to registered users. We collect the data you provide for this purpose in order to complete the registration process. The extent of the data depends on your information and is determined by the input windows.
Google Tag Manager
This website uses the Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personal information. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If disabled at the domain or cookie level, it will remain disabled for all tracking tags implemented with Google Tag Manager.
DR. KADE pages on FACEBOOK
Facebook Ireland Ltd. (hereafter “Facebook”), 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, is therefore responsible alongside DR. KADE for the data collected when using the Facebook pages.
The extent to which Facebook uses the data for itself is listed below.
The data that DR. KADE receives from Facebook is evaluated anonymously so that no conclusions can be drawn about individual users. In addition, access to individual user profiles by DR. KADE is not possible. Also for reasons of data protection, the statistics can only be accessed from 30 fans upwards, as with a small number of users it would be possible to trace which actions the individual users have taken on the fan page.
All user-related evaluations and data remain with Facebook, but can also be used by Facebook for actions, e.g. advertising, on behalf of DR. KADE.
DR. KADE uses the data we receive from Facebook Insights about the so-called “fan page” and its use to improve the pages on an ongoing basis and to adapt the content, e.g. to the regional distribution of users, to evaluate the range of posts (What did you like? What does hardly anyone read...), how high are the numbers of visitors and on which days the pages will be more visited etc. These are important criteria to evaluate the success and value of the advertising on the pages. The number of “likes” is also important for this.
The legal basis for the processing of this data by DR. KADE is our legitimate interest (Art. 6 para. 1 lit. f GDPR) to display and share images, texts and other offers with others and at the same time to receive feedback on the manner and frequency of use of individual elements on the pages.
Page Insights are aggregated statistics generated from specific events logged by Facebook servers when people interact with websites and their associated content. Such “events” include, for example, viewing a website, post, video, story, or other content associated with a website; interacting with a story; subscribing to or unsubscribing from a web page; marking a page or post with “I like” or “I don’t like it anymore”; recommend a page in a post or comment; commenting, sharing, or responding to a post (including the type of response); hiding a post or reporting it as spam; moving your mouse over a link to a page or over the name or profile picture of a page to preview the page content; clicking the website, phone number, “plan route” button or any other button on a page; viewing a page’s event; responding to an event (including the type of response); clicking on an event ticket link; starting a messenger conversation with the page; viewing or clicking items in a website’s online shop.
In the process, this or some of this information is then collected about the action and about the person who performed the action: Date and time of the action; country/city (estimated from the IP address or imported from the user profile for logged in users); language code (from the browser HTTP header and/or language setting); age/gender group (from the user profile, only for logged in users); previously visited websites (from browser HTTP header); whether the action was taken on a computer or on a mobile device (from browser user agent or from app attributes); Facebook user ID (for logged in users only)
DR. KADE has no access to the personal data that is processed in this way, but only to the summarised page views. Events used to create Page Insights do not store IP addresses, cookie IDs or other identifiers associated with individuals or their devices, other than a Facebook user ID for individuals logged into Facebook.
The events that Facebook logs to create Page Insights are determined solely by Facebook and cannot be set up, modified or otherwise influenced by DR. KADE.
DR. KADE and Facebook Ireland Limited are jointly responsible for the processing of this personal data in Page Insights events (“Insights data”) in accordance with Article 26 GDPR. The joint responsibility includes the creation of these events and their consolidation into Page Insights, which are then provided by DR. KADE. The Parties agree that Facebook and, if applicable, DR. KADE, remain separate and independent controllers of any other processing of personal data related to a website and/or its associated content for which no joint decision is made as to the purposes and means.
Data subjects can and should therefore also contact Facebook directly. If data subjects exercise their rights under the GDPR with regard to the processing of Insights data against DR. KADE, DR. KADE is obliged to inform Facebook immediately and Facebook undertakes to respond to requests from data subjects in accordance with the obligations incumbent on Facebook under the Pages Insights supplement.
DR. KADE pages on INSTAGRAM
Instagram is a product and service of Facebook Ireland Ltd. (hereinafter “Instagram”), 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Instagram, or Facebook, alongside DR. KADE, is responsible for the data collected when using the Instagram pages.
Instagram is one of the Facebook companies that share technology, systems, “Insights” features and user data.
The extent to which Instagram uses the data for its own purposes is outlined below.
The data that DR. KADE receives from Instagram is evaluated anonymously, so that no conclusions can be drawn about individual users. In addition, access to individual user profiles by DR. KADE is not possible.
All user-related evaluations and data remain with Instagram, but can also be used by Instagram for actions, e.g. advertising, on behalf of DR. KADE.
DR. KADE uses the data we receive from Instagram Insights via DR. KADE pages on Instagram and their usage to improve the pages on an ongoing basis and to adapt the content, e.g. to the regional distribution of users, to evaluate the reach of the articles (What did you like? What does hardly anyone read...), what are the visitor numbers and on which days will the pages be visited more, etc. These are important criteria to evaluate the success and value of the advertising on the pages. The number of Likes is also important.
The legal basis for the processing of this data by DR. KADE is our legitimate interest (Art. 6 para. 1 lit. f GDPR) to present and share pictures and stories with others and at the same time to receive feedback on the way and frequency of use of individual offers on the pages.
Page Insights are aggregate statistics generated from specific events logged by Instagram’s servers when people interact with pages and their associated content. Such “events” include, for example, viewing a page, post, video, story or other content associated with a page, interacting with a story, subscribing to a page, subscribing or unsubscribing, marking a page or post with “I like” or “I don’t like it anymore”, recommending a page in a post or comment, commenting on, sharing or responding to a page post (including the type of response); clicking the website, phone number button or other button on a page; clicking a link; viewing or clicking on items in a website’s online shop, etc.
In the process, this or some of this information is then collected about the action and about the person who performed the action: Date and time of the action; country/city (estimated from the IP address or imported from the user profile for logged in users); language code (from the browser HTTP header and/or language setting); age/gender group (from the user profile, only for logged in users); previously visited websites (from browser HTTP header); whether the action was taken on a computer or on a mobile device (from browser user agent or from app attributes); Instagram user ID (for logged in users only)
DR. KADE has no access to the personal data that is processed in this way, but only to the summarised page views. Events used to create Page Insights do not store IP addresses, cookie IDs, or any other identifiers associated with individuals or their devices other than an Instagram user ID for individuals logged into Instagram.
The events that Instagram logs to create Page Insights are determined solely by Instagram and cannot be set up, modified or otherwise influenced by DR. KADE.
DR. KADE and Facebook Ireland Limited are jointly responsible for the processing of this personal data in Page Insights events (“Insights data”) in accordance with Article 26 GDPR. The joint responsibility includes the creation of these events and their consolidation into Page Insights, which are then provided by DR. KADE. The parties agree that Instagram and, if applicable, DR. KADE, remain separate and independent controllers of any other processing of personal data related to a website and/or its associated content for which no joint decision is made as to the purposes and means.
Data subjects can and should therefore also contact Instagram directly. If data subjects exercise their rights under the GDPR with regard to the processing of Insights data against DR. KADE, DR. KADE is obliged to inform Instagram immediately and Instagram undertakes to respond to requests from data subjects in accordance with Instagram’s obligations under the Pages Insights supplement.
The legal basis for data processing is Art. 6 para. 1 lit. a GDPR.
On our website and in social media, we offer you the possibility to subscribe to our newsletter. If you have decided to receive the newsletter, we use the data you provide during registration, i.e. name, e-mail address, possibly other contact data such as the address, for sending information about our company and products, advertising, promotions, competitions and news, as well as for customer satisfaction surveys. Registration for the newsletter applies to all companies of the DR. KADE corporate group.
With your consent, we also record your usage behaviour (click and purchase behaviour) based on the newsletter on our websites. The evaluation of your usage behaviour includes in particular the links you have clicked. Personalised user profiles are created with the help of technical identification data (IP addresses, newsletter cookie) and the assignment to your person and/or e-mail address. The purpose of this data is the personalised, promotional approach, in particular in the form of newsletters and print advertising, in order to be able to better align these with your personal interests.
The legal basis for the above mentioned data processing is your consent according to article 6 paragraph 1 letter a) GDPR.
In order to ensure that no mistakes were made when entering your e-mail address and to be able to verify your identity, we use the so-called double opt-in procedure: after you have entered your e-mail address in the registration field, we will send you a confirmation link. Only when you click this confirmation link will your e-mail address be added to our distribution list.
You can withdraw your consent to receive the newsletter and to the creation of personalised user profiles at any time with effect for the future, e.g. by sending an e-mail to datenschutz(at)kade.de, by clicking the unsubscribe link in the newsletter, or by using the contact data from the legal notice on our websites. By unsubscribing, we regard your consent to the creation of your personalised user profile and/or the receipt of newsletters based on it as having been revoked.
Deletion of data: Your data will be deleted by us immediately after you unsubscribe from the newsletter, if you wish to do so and explicitly state this when unsubscribing. Otherwise, your email address will continue to be stored after you unsubscribe to ensure that no more newsletters are sent to you. This cannot be ruled out if the email address is deleted at your request. Likewise, your data will be deleted by us immediately in case of an uncompleted registration. We reserve the right to delete your data without giving reasons and without prior or subsequent information.
When you participate in competitions, we use your data for the purposes stated in the respective competition.
We provide social plugins from the social network Instagram on our website. The Instagram service is one of the Facebook products provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. You can recognise the plugins by the respective logos of the companies. You can use these plugins to link, share or otherwise be active directly on the respective network.
Social plug-ins, tools from service providers
Our websites may also contain offers from third parties. If you click such an offer, we transfer data to the respective provider to the required extent (e.g. the information that you have found this offer with us and, if applicable, further information that you have already provided for this purpose on our websites). In particular for so-called “social plug-ins”, i.e. the links visible as buttons or graphic symbols to social networks such as Facebook, Twitter, Xing, or Google+ or providers such as Spotify, we integrate as follows:
When you visit our websites, the social plug-ins are not yet activated. If you want to use one of the networks, click the respective social plugin to establish a direct connection with the respective network. The link leads to the website of another provider, usually directly to the social network. If you have a user account with the network and are logged in at the moment the social plug-in is activated, the network can assign your visit to our websites to your user account. If you want to avoid this, please log out of the network before activating the social plug-in. When you activate a social plug-in, the network transmits the content that becomes available as a result directly to your browser, which embeds it in our websites. This may also transfer data initiated and controlled by the respective social network, in particular via additional cookies from this social network.
The social plug-in remains active until you deactivate it or delete your cookies. If you click the link to an offer or activate a social plug-in, it is possible that personal data may be transferred to providers in countries outside the European Economic Area which, from the point of view of the European Union (“EU”), do not guarantee an “adequate level of protection” for the processing of personal data that meets EU standards.
Please note, therefore, that your connection to the social network, the data transfers taking place between the network and your computer or cell phone and your interactions on this platform are governed exclusively by the data protection regulations of the respective network.
Processing within the framework of the customer relationship
Within the context of a customer relationship, we process the personal data that we have received from you in the course of the business relationship. On the other hand, we process personal data that we have obtained and are permitted to process from publicly accessible sources (registers and directories on the internet). As a rule, this is the name of the contact person, the address and other contact data. This data is used to fulfil contractual obligations (such as sample delivery, order processing, marketing support) and for advertising purposes. This may include the transfer of the data to other companies in the DR. KADE corporate group. Your data will be stored for the duration of the business relationship. For your further rights, please refer to the information in the “Your rights” section.
Other external services and contents on our website
In addition to those already mentioned, we include other external services or content on our website. If you use such a service or third party content is displayed to you, there will be a technically induced exchange of communication data between you and the respective provider. We have configured services or content from providers who are known to process data for their own purposes to the best of our knowledge and belief so that either communication for purposes other than to display the content or services on our website is not possible, or communication only takes place when you actively decide to use the service. We have no influence on the data collected by the third parties and its processing. For more information about the purpose and scope of processing your data, please refer to the data protection notices of the respective providers:
- Youtube (videos, link: policies.google.com/privacy)
- KlickA, Aponow (ordering medicines, link: www.aponow.de/datenschutz)
Content Delivery Network
We use a Content Delivery Network (CDN) provided by Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA (Cloudflare). Cloudflare is certified under the Privacy Shield Agreement (privacyshield.gov). In addition, we have entered into a contract with Cloudflare for order processing to ensure the security of your data.
A CDN is a service, with whose help contents of our website, especially large media files, such as graphics or scripts using distributed servers, are delivered faster and the loading times of our website are optimised. For this purpose, the requests of the visitors are first forwarded to Cloudflare. By Cloudflare, these inquiries are analysed in order to recognise potential threats for our website by malware at an early stage and to optimise the loading times of our website. In addition, we receive statistical evaluations from Cloudflare, which enables us to constantly optimise our website.
Your data is processed solely for the above-mentioned purposes and to maintain the security and functionality of the CDN. The use is based on our legitimate interests according to art. 6 paragraph 1 lit. f. GDPR. Our interest lies in a secure and efficient provision, analysis and optimisation of our online services.
Cloudflare has committed itself to deleting your data automatically after 4 hours. Further information about our CDN can be found on the website of our service provider: cloudflare.com/security-policy.
Social media buttons with Shariff
Sometimes we use (for example on riopan.de) the Shariff method to integrate the social media buttons. The social buttons used establish direct contact between the social network and visitors only when the latter actively clicks the share button.
We use the tool from URLgenius on Facebook and Instagram. URLgenius links embedded browsers, including those used by Facebook, Instagram and other applications, directly into other apps. The URLgenius platform is designed to work with any embedded browser that can receive and interpret URL schemes. URLgenius tracks clicks, app requests, device, platform, referring URL and location, if available. URLgenius does not collect personally identifiable information or sell data to third parties. URLgenius does not create device profiles or data pools for retargeting purposes. The IP address is used for fraud prevention purposes only. Your data will not be passed on or sold to third parties. The use of the tool is based on our legitimate interests in accordance with Art. 6 para. 1 lit. f. GDPR. Our interest lies in a secure and efficient provision, analysis and optimisation of our online services.
Podigee podcast hosting
We use the podcast hosting service Podigee from the provider Podigee GmbH, Ritterstraße 2A, D-10969 Berlin, Germany. The Podcasts are loaded thereby by Podigee or transferred via Podigee. The use is based on our legitimate interests, i.e. interest in a secure and efficient provision, analysis and optimisation of our podcasts according to Art. 6 para. 1 lit. f. GDPR.
Passing on of data
Deletion of data
As far as your data is no longer required for the mentioned purposes, it will be deleted. Please note that with each deletion, the data is initially only blocked and then finally deleted after a time delay in order to prevent accidental deletion or possible intentional damage. For technical reasons, data may be duplicated in data backup files and service mirrors. Such copies are also deleted after a technical delay.
Our contact details
DR. KADE Pharmazeutische Fabrik GmbH
D-12277 Berlin, Germany
Tel.: 030 – 720 82 – 0
Telefax: +49 (30) 200 95-1200
Data Protection Officer:
MKM DATENSCHUTZ GmbH
Äußere Sulzbacher Str. 124a
D-90491 Nuremberg, Germany
You have the right to demand information, correction, deletion or restriction of your personal data according to the legal regulations. We will also provide you with your data in a structured, common and machine-readable format, if we are legally obliged to do so. If we use your data on the basis of your consent (e.g. when you register for our newsletter), you can revoke your consent at any time. After revocation, we will not use your data in the future. Should we pursue a legitimate interest in processing your data, you can contact us with an objection. Independent of this, you can always contact the responsible supervisory authorities.