I. Name and address of the person responsible

The person responsible for the purposes of the data security-basic order and other national data protection act of the member states as well as other data security-juridical regulations is:

DermaSign Cosmeceuticals GmbH

II. Contact details of the data security official

The controller of data protection of the person responsible is:
info@dermasign.de

III. General information on data processing

1. Extent of processing of personal data

We raise and use personal data of our users basically only as far as this is necessary for the provision of a functioning website as well as our contents and services. The collection and use of personal data of our users follows regularly only after approval of the user. An exception is valid in such cases in which prior consent is not possible for actual reasons and the processing of the data is permitted by legal regulations.

2. Legal basis for the processing of personal data

As far as we obtain the consent of the affected person for the processing of personal data, article 6(1)(a) of the EU Data Protection Regulation (DSGVO) serves as the legal basis. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, article 6(1)(b) DSGVO serves as the legal basis. This also applies to processing operations necessary for pre-contractual measures. If processing is necessary for the fulfillment of a legal obligation to which our company is subject, article 6(1)(c) DSGVO serves as the legal basis. If processing is necessary to protect a legitimate interest of our company or a third party and if the interests, fundamental rights, and freedoms of the data subject do not override the former interest, article 6(1)(f) DSGVO serves as the legal basis for processing.

3. Data deletion and storage duration

The personal data of the affected person are deleted or blocked as soon as the purpose of the storage is canceled. In addition, storage may occur if this has been provided for by European or national legislators in union regulations, laws, or other provisions to which the controller is subject. A blockage or deletion of the data also occurs if a storage period prescribed by the aforementioned standards expires, unless there is a necessity for further storage of the data for the conclusion or fulfillment of a contract.

IV. Application and use of Google Maps

This site uses the map service Google Maps via an API. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer. The use of Google Maps is in the interest of an attractive presentation of our online offers and to make it easy to find the places we have indicated on the website. This represents a legitimate interest in the sense of Art. 6(1)(f) DSGVO.

More information on the handling of user data can be found in Google's privacy policy: [Google Privacy Policy](https://www.google.de/intl/de/policies/privacy/).

V. Contact form and e-mail contact

1. Description and scope of data processing

On our website, there is a contact form and login mask that can be used for electronic ordering or contacting. If a user takes this opportunity, the data entered in the input mask will be transmitted to us and stored. These data are:

• Name, first name
• E-mail address
• Messages
• Phone

At the time the message is sent, the following data is also stored:

• The IP address of the user
• Date and time of registration

For the processing of the data, your consent will be obtained during the sending process and reference will be made to this privacy policy.

2. Legal basis for the data processing

Legal basis for the processing of the data is Article 6(1)(a) DSGVO. Legal basis for the processing of the data which is transmitted in the course of a remittance of e-mail is Article 6(1)(f) DSGVO. If the e-mail contact is aimed at the conclusion of a contract, additional legal basis is Article 6(1)(b) DSGVO.

3. Purpose of the data processing

The processing of the personal data from the input mask serves solely for the purpose of contact processing. In the case of contact via e-mail, the legitimate interest lies in processing the data.

4. Storage duration

The data will be deleted as soon as they are no longer necessary for achieving the purpose for which they were collected. For the personal data from the input mask of the contact form and those sent via e-mail, this is the case when the respective conversation with the user is completed. The conversation is terminated when it can be inferred from the circumstances that the matter in question has been conclusively clarified.