Controller for data processing in the sense of data protection law is:
ShipStock GmbH („we“, „us“, „our“)
Tel.: +49 (0) 152 318 431 61
2. Personal Data
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
3. Purposes and Legal Basis of the Data Processing
We undertake to comply with all data protection regulations when handling the data of visitors to our website. We process data exclusively to the extent necessary and permitted by data protection law in order to make a visit to the website possible.
a. Informational Use of the Website
You can visit our website without providing any personal information. If you use our website for information purposes only, we do not collect any personal data. An exception is made for data transmitted by your browser to enable you to visit the website and for information transmitted to us by the cookies we use.
aa. Technical Provision of the Website
For the purpose of technically providing the website, we may need to process certain automatically submitted information from you in order for your browser to display our website and for you to use the website. This information is automatically collected each time you visit our website and stored in server log files. These log files contain, inter alia, the following information: IP address, date and time of the server request, pages accessed (URL and request parameters), referrer-URL (the previously visited page). The log files are automatically deleted after one week.
The legal basis for the temporary storage of data and log files is Art. 6 para. 1 lit. f GDPR.
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this the IP address of the user must remain stored for the duration of the session. The data is stored in log files to ensure the functionality of the website. In addition, the data serves us to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context. Our legitimate interest in data processing pursuant to Art. 6 para. 1 lit. f GDPR also lies in these purposes.
The collection of data is mandatory for the operation of the website. Consequently, there is no possibility of objection.
|Cookie Name||What it does/Information stored|
|_shipstock_session||Allow submitting of forms and store the login state of a user. It expires immediately when the browser session ends.|
|_gid||Distinguish visitors of our website from oneanother. It expires 24 hours after it is created. (Google Analytics)|
|_ga||Distinguish visitors of our website from oneanother. It expires 2 years after it is created. (Google Analytics)|
|_gat||Throttle the request rate for Google Analytics. It expires 1 minute after it is created. (Google Analytics)|
Your information, collected by us through the aforementioned cookies, will not be used by us to create user profiles or to evaluate your browsing behavior.
We process your personal data for the technical provision of our website on the following legal basis:
for the fulfilment of a contract or for the implementation of pre-contractual measures pursuant to Art. 6 para. 1 letter b GDPR, provided you visit our website to obtain information about our services; and
to protect our legitimate interests pursuant to Art. 6 para. 1 letter f GDPR in order to make the website technically available to you. Our legitimate interest is to offer you an appealing, technically functioning and user-friendly website.
b. Statistical Analysis of Website Usage and Range Increase
For the purpose of statistical analysis of the use of our website, we use Google Analytics and thus cookies, which enable an analysis of your browsing behaviour. This enables us to improve the quality of our website and its content. We learn how the website is used and can thus continuously optimize our offer.The information obtained in the context of the statistical analysis of our website will not be merged with your other data collected in the context of the website.
We process your personal data for statistical analysis of the use of our website on the following legal basis:
Your consent pursuant to Art. 6 para. 1 letter a GDPR.
On our website we use Google Analytics, a web analysis service of Google LLC. Google Analytics uses so-called "cookies": text files placed on your computer, enabling an analysis of the use of the website by you. The information generated by the cookie about your use of our website is usually transferred to a Google server in the USA and stored there. However, if IP anonymisation is activated on our website, Google will shorten your IP address within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activities and to provide the website operator with other services relating to website and internet use. The IP address transmitted by your browser in the context of Google Analytics is not merged with other Google data.
On our website we use Google Analytics with the extension "_anonymizeIp()". This arranges for IP addresses to be further processed in abridged form, a direct relation to a per-son can be ruled out.
You can prevent the collection of data generated by the cookie and relating to your use of our website (including your IP address) and the transmission to Google as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de
As an alternative to the browser plugin, you can click this link to prevent Google Analytics from collecting data about our website in the future. An opt-out cookie is stored on your device. If you delete your cookies, you must click the link again.
bb. When Creating a User Account
We offer you the possibility of creating a user account in order to take advantage of our services. The creation of a user account is required for the use of our services. The following personal data is required for registration on our website:
first and last name;
name of your company.
You can voluntarily provide us with your telephone number.
We use the so-called double opt-in procedure for registration, i.e. your registration is not complete until you have confirmed your registration by clicking on the link contained in a confirmation e-mail sent to you for this purpose. After successful registration you can perform certain activities through your user account, such as changing your personal data.
We process your data for the above purposes on the following legal basis:
for the performance of a contract or for the implementation of pre-contractual measures pursuant to Art. 6 para. 1 letter b GDPR, provided that you register to use the user account and the services offered in this context; and
to safeguard our legitimate interests pursuant to Art. 6 para. 1 letter f GDPR, in order to make the website technically available to you. Our legitimate interest is to be able to provide you with an appealing, technically functioning and user-friendly website.
c. Legal Compliance
We also process your personal data in order to fulfil other legal obligations that we are subject to in connection with the provision of our services to you. These include in particular retention periods under commercial, trade or tax law.
We process your data for the above purposes on the following legal principles:
to fulfil a legal obligation to which we are subject pursuant to Art. 6 para. 1 letter c GDPR in connection with commercial, industrial or tax law, insofar as we are obliged to record and store your data.
d. Law Enforcement
We also process your personal data in order to assert our rights and enforce our legal claims. We also process your personal data in order to be able to defend ourselves against legal claims. Finally, we process your personal data to the extent necessary to defend against or prosecute criminal offences.
We process your data for the above purposes on the following legal basis:
to protect our legitimate interests pursuant to Art. 6 para 1 letter f GDPR, insofar as we assert legal claims or defend ourselves in legal disputes or we prevent or clarify criminal offences.
4. Right to Object pursuant to Art. 21 GDPR
You have the right to object at any time to processing of your personal data which is based on the legitimate interests pursued by us or a third party, on grounds relating to your particular situation or if the objection is directed against general or direct advertising tailored to you. In the latter case, you have a general right of objection, which we will implement without specifying a particular situation.
If you wish to exercise your right of objection, please send us an e-mail to email@example.com or contact us by other means (cf. no. 1).
5. Disclosure of Personal Data to Third Parties / Recipients of Data
We do not pass on your personal data to third parties. For the provision of our services we can use technical service providers by way of order processing in accordance with Art. 28 GDPR, e.g. we use the services of Heroku Inc. and Amazon Web Services Inc. for hosting our website.
6. Transfer of Personal Data to a Third Country
We use Amazon Web Services Inc. (“AWS”), 410 Terry Avenue North, Seattle 98109, United States to host our website on servers located in the U.S. If you are a non-U.S. resident, this means that your personal information will be transferred to the U.S.
For the United States, there is no adequacy decision of the EU Commission; however, your Data will be processed in accordance with European / national data protection regulations either on the basis of the standard contractual clauses (Commission decision of 5 February 2010 on standard contractual clauses for the transfer of personal data to processors established in third countries un-der Directive 95/46/EC of the European Parliament and of the Council, 2010/87/EU) that can be agreed with AWS or on the basis of the Privacy Shield under which AWS is certified:
For more information about privacy on AWS, please visit:
We further use Heroku Inc. to host our website on servers located in the U.S. Heroku Inc. is certified under the EU-US Privacy Shield:
As part of the use of Google tools, we transfer your shortened IP address to the USA. Google LLC is certified under the EU-US Privacy Shield:
The data transfer to the USA is based on the EU Commission implementing decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EG of the European Parliament and of the Council on the adequacy of the protection provided by the EU-US data privacy shield.
7. Duration of Storage
a. Informational Use of the Website
Your personal data stored in logfiles will be deleted one week after your visit. Cookies installed by us are usually also deleted after leaving our website. You also have the option to delete installed cookies yourself at any time.
b. Active Use of the Website
If you actively use our website, we initially store your personal data for the duration of responding to your inquiry or for the duration of our business relationship. This also includes the initiation of a contract (pre-contractual legal relationship) and the execution of a contract.
In addition, we will store your personal data until any legal claims arising from the relationship with you become time-barred, in order to use them as evidence if necessary. The limitation period is generally between 12 and 36 months, but can also be up to 30 years.
Upon expiry of the limitation period, we delete your personal data, unless there is a legal obligation to store such data, for example from the German Commercial Code (sec. 238, 257 para. 4 HGB) or from the Tax Code (sec. 147 para. 3, 4 AO). These retention obligations can last from two to ten years.
8. Rights of the Data Subjects
Under the legal provisions you are entitled to the following rights as data subject, which you can assert against us:
Right to information: You are entitled to request confirmation from us at any time within the scope of Art. 15 GDPR as to whether we are processing personal data relating to you; If this is the case, you are also entitled under Art. 15 GDPR to receive information about such personal data as well as other specific information (inter alia, processing purposes, categories of per-sonal data, categories of recipients, planned storage period, the origin of the data, the use of automated decision-making and, in the case of transfers to third countries, the appropriate guarantees) and a copy of the data.
Right to correction: According to Art. 16 GDPR, you are entitled to demand correction of the personal data stored about you if it is inaccurate or incorrect.
Right to deletion: You are entitled, under the conditions of Art. 17 GDPR, to request from us the deletion of personal data relating to you without delay. Among other things, there is no right of deletion if the processing of personal data is necessary for (i) the exercise of the right to freedom of expression and information, (ii) the fulfilment of a legal obligation to which we are subject (e.g. statutory retention obligations) or (iii) the assertion, exercise or defence of legal claims.
Right to limitation of processing: Under the conditions of Art. 18 GDPR you are entitled to request from us the limitation of the processing of your personal data.
Right to data transferability: You are entitled, under the conditions of Art. 20 GDPR, to request from us the provision to you of the personal data relating to you that you have submitted to us in a structured, current and machine-readable format.
Right of revocation: You have the right to revoke your consent to the processing of personal data at any time with effect for the future without incurring any costs other than the transmission costs according to the basic rates.
Right to objection: You are entitled to object to the processing of your personal data under the conditions of Art. 21 GDPR, meaning that we have to terminate the processing of your personal data. The right of objection exists only within the limits provided for in Art. 21 GDPR. In addition, our interests may prevent the processing from being terminated, so that we are entitled to process your personal data despite your objection.
Right of appeal to a supervisory authority: You are entitled to file a complaint with a supervisory authority, in particular in the Member State of your place of residence, work or suspected infringement, under the conditions laid down in Article 77 GDPR, if you believe that the processing of personal data concerning you infringes the GDPR. The right of appeal is not prejudicial to any other administrative or judicial remedy.
The supervisory authority responsible for us is:
However, we recommend that you always address a complaint to us first.
9. Scope of Your Obligations to provide Data
You are under no legal or contractual obligation to provide us with your data. Please note, however, that the provision of some data is necessary in order to provide you with the services offered on the website.
10. Automated Decision-making/Profiling
We do not use automated decision making or profiling (an automated analysis of your personal circumstances).
11. Links to other websites