Data protection

 

We collect and use your personal data exclusively within the framework of the data protection regulations of the Federal Republic of Germany. In the following, we inform you about the nature, scope and purposes of the collection and use of personal data. You can access this information at any time on our website.

  1. Data Protection at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our data protection declaration listed below this text.

Data Collection on Our Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by LABCON-OWL Analytik, Forschung und Consulting GmbH. Our contact details can be found in the imprint of this website.

How do we collect your data?

Some of your data is collected when you provide it to us. This may include data you enter into a contact form, for example.

Other data is collected automatically by our IT systems when you visit the website. This primarily includes technical data (e.g., internet browser, operating system, or time of page view). This data is collected automatically as soon as you enter our website.

What do we use your data for?

We use data from the contact form to process your inquiries.

Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right at any time to receive free information about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction, blocking, or deletion of this data. For this and other questions on the subject of data protection, you can contact us at any time at the address given in the imprint, or at ( datenschutz@labcon-owl.de ). Furthermore, you have a right to lodge a complaint with the competent supervisory authority.

Analysis Tools and Third-Party Tools

When you visit our website, your surfing behavior can be statistically evaluated. This is mainly done with cookies and so-called analysis programs. The analysis of your surfing behavior is anonymous; your surfing behavior cannot be traced back to you.

  1. General Information and Mandatory Disclosures

Data Protection

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission over the Internet (e.g., when communicating by email) can have security vulnerabilities. Complete protection of data from access by third parties is not possible.

Note on the Responsible Party

The responsible party for data processing on this website is:

Prof. Dr. Carsten Tiemann

Siemensstraße 40
32105 Bad Salzuflen

Data Protection Officer

Creditreform Compliance Services GmbH
Hammfelddamm 13
41460 Neuss

E-Mail: datenschutz@labcon-owl.de

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. An informal notification by email to us ( datenschutz@labcon-owl.de ) is sufficient for this. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of data protection law, the data subject has a right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the State Data Protection Officer of the federal state in which our company has its registered office. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to yourself or to a third party in a common, machine-readable format.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as inquiries you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, Blocking, Deletion

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipient, and the purpose of data processing and, if applicable, a right to correction, blocking or deletion of this data. For this and for further questions on the subject of personal data, you can contact us at any time at the address given in the imprint.

Objection to Promotional Emails

We hereby object to the use of contact data published within the scope of the imprint obligation for sending unsolicited advertising and information material. We expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, for example by spam e-mails.

  1. Data Collection on Our Website

Cookies

The internet pages sometimes use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser the next time you visit.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.

Cookies that are required for the electronic communication process or to provide certain functions you desire (e.g., shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g., cookies for analyzing your surfing behavior) are stored, these are treated separately in this data protection declaration.

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

This data will not be merged with other data sources.

The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and for the event of follow-up questions. The data entered into the contact form is therefore processed exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time. An informal notification by email to us is sufficient for this. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.

The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage ceases to apply (e.g., after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.

Processing of Data (Customer and Contract Data)

We collect, process, and use personal data only insofar as it is necessary for the establishment, content design, or amendment of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We collect, process, and use personal data about the use of our website (usage data) only insofar as this is necessary to enable the user to use the service or to bill for it.

The collected customer data will be deleted after the completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.

In the case of identity verification and paternity tests, the following data is necessary for contract fulfillment and is collected at the point of sample collection: name, address, date of birth, distinguishing marks, telephone number, ID number and validity, copy of ID, fingerprint or footprint for infants, and whether a stem cell transplant, blood transfusion, or therapy with blood products has been performed.

  1. Analysis Tools and Advertising

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.
Google Analytics uses so-called "cookies". These are text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

IP Anonymization
On this website, we have anonymized IP addresses. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser Plugin
You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de

Objection to Data Collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set that prevents the collection of your data on future visits to this website:

Deactivate Google Analytics

More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de

Google Web Fonts

This site uses so-called web fonts provided by Google for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.

For this purpose, the browser you are using must connect to Google's servers. This gives Google knowledge that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offers. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

If your browser does not support web fonts, a standard font from your computer will be used.

Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.

Legal

Contact

LABCON-OWL Analytik, Forschung und Consulting GmbH
Siemensstr. 40
32105 Bad Salzuflen
05222/8076-192
info@labcon-owl.de
datenschutz@labcon-owl.de

Mandatory information according to Art. 13 (data collection directly from the data subject) and Art. 14 (data collection from third parties) of the General Data Protection Regulation (GDPR):

  1. Information on the Controller

Responsible for data collection is:

LABCON-OWL Analytik, Forschung und Consulting GmbH

Prof. Dr. rer. nat. Carsten Tiemann
Siemensstraße 40
32105 Bad Salzuflen

Tel.         05222 8076-192
Fax          05222 8076-253
E-Mail:   info@labcon-owl.de
Website: www.labcon-owl.de

  1. Information on the Data Protection Officer

Creditreform Compliance Services GmbH
Hammfelddamm 13
41460 Neuss

E-Mail: datenschutz@labcon-owl.de

  1. Information on the Supervisory Authority

The competent supervisory authority for data protection in our company is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestr. 2-4
40213 Düsseldorf

Tel. 0211 384 24-0
Fax 0211 384 24-10
E-Mail: poststelle@ldi.nrw.de

  1. Purposes and Legal Bases of Processing

Legal bases for data processing are:

  • Processing based on consent, Art. 6 para. 1 lit. a GDPR
    Insofar as the data subject has given the company consent for data processing for specific purposes (e.g., ordering self-collection kits via Labdoc.de), this personal data may be used lawfully within the scope of the consent.
  • Processing for the fulfillment of contracts concluded with MVZ Labor Krone GbR , pursuant to Art. 6 para. 1 lit. b GDPR
    If personal data is collected and processed for the purpose of carrying out pre-contractual measures or on the basis of a contract, this data will be used for the conclusion of the contract, the execution of the contractual relationship, and, if applicable, its termination. This includes communication with business partners regarding products, services, and projects, e.g., to process inquiries from the business partner. Furthermore, data processing serves the planning, execution, and administration of the business relationship between the company and the business partner, e.g., to process service orders, for accounting purposes, and billing.
  • Processing to safeguard legitimate interests, pursuant to Art. 6 para. 1 lit. f GDPR
    It may happen that data is processed to safeguard legitimate business interests of Labcon-OWL Analytik, Forschung und Consulting GmbH or, if applicable, those of third parties. This may be necessary, for example, to ensure IT security and IT operations, to prevent and investigate criminal offenses/regulatory offenses, or to secure domiciliary rights.
  • Processing for the fulfillment of legal obligations, Art. 6 para. 1 lit. c GDPR
    Data processing may ultimately be necessary for the fulfillment of legal obligations, such as reporting obligations according to § 7 Infection Protection Act, retention periods according to the German Commercial Code, etc.

Legal bases for the processing of health data (special categories of personal data):

The processing of health data is carried out on the basis of Art. 9 para. 2-4 GDPR in conjunction with §§ 22 BDSG. This specifically applies to:

  • Processing of special categories of personal data based on consent, Art. 9 para. 2 lit. a GDPR
    Insofar as the data subject has given the company consent for data processing for specific purposes (e.g., sending and analyzing self-collection kits, performing an individual health service (IGEL)), this personal data may be used lawfully within the scope of the consent.
  1. Categories of Data We Collect (Art. 13 GDPR and Art. 14 GDPR)

When ordering self-collection kits via www.labdoc.de, the following data categories are collected:

  • General personal data (name, first name, address data (both for delivery and, if applicable, different billing address), email address)
  • Bank details (depending on the payment method)
  • Online data (IP address, browser type, cookies, see above under information on website usage)

When registering received self-collection kits at https://www.selbstlabor.de, the following data categories are collected:

  • General personal data (name, first name (if applicable, alias), email address, date of birth)
  • Assigned barcodes of the test kits plus security codes in conjunction with registration data
  • GUID (Globally Unique Identifier), which is automatically generated from the provided data and is required to retrieve the analysis results (on https://mein-laborergebnis.de)
  • Online data (IP address, browser type, cookies, see above under information on website usage)

We do not process data that we collect from third parties.

The laboratory results can be retrieved via the website https://mein-laborergebnis.de which is provided by iTech Laborlösungen GmbH. Access to the laboratory results from iTech is not possible due to technical and organizational measures.

 

 

  1. Sources (Third Parties) from which Personal Data is Obtained

Labcon-OWL Analytik, Forschung und Consulting GmbH processes personal data insofar as this data has been provided or transmitted by the data subjects themselves. 

After ordering the self-collection kits via the website www.labdoc.de and receiving the test kit, it is necessary to register them on the website https://www.selbstlabor.de.

  1. Recipients or Categories of Recipients of Personal Data

At Labcon-OWL Analytik, Forschung und Consulting GmbH and MVZ Labor Krone GbR (as the performing medical laboratory for the analysis of test kits), only those persons who need access to personal data for the respective lawful fulfillment of tasks receive it.

We may share personal data with:

  • Business partners where data transfer is necessary for task fulfillment, such as payment service providers/banks, postal/parcel services, etc.
  • Debt collection agencies to collect outstanding debts
  • Authorities for fulfilling statutory reporting obligations (e.g., health authorities)

If commissioned external service providers receive personal data for these purposes, we ensure that appropriate technical and organizational measures are implemented and necessary agreements are concluded to ensure that the processing complies with applicable data protection regulations and safeguards the rights of the data subject.

For the retrieval of the analysis results of the test kits, the date of birth and the generated GUID are forwarded to our processor itech Laborlösungen GmbH. The company has no access to the laboratory results but only provides the platform. An agreement on data processing exists, of course.

  1. Intention to Transfer to a Third Country or an International Organization

There is no transfer of personal data (and no dispatch of test kits) to a third country (states outside the European Union or the European Economic Area) or an international organization.

  1. Duration of Storage or Criteria for Determining the Duration

Personal data will only be stored for as long as permitted by the applicable legal basis, in particular for as long as it is necessary to fulfill the contractual purposes for which the personal data was collected. Storage and retention will take place for as long as it is necessary to fulfill retention obligations or for predominantly legitimate interest, or until the data subject revokes their consent on which the data processing was based.

  1. Rights of Data Subjects

When your personal data is collected, you have the following rights:

  • Right to information, Art. 15 GDPR: The data subject has the right, according to Art. 15 Para. 1 GDPR, to demand confirmation as to whether personal data concerning them is being processed. If this is the case, they also have the right to information about this personal data and to further information according to Art. 15 Para. 1 lit. a to h GDPR.
  • Right to rectification, Art. 16 GDPR: Should the personal data be inaccurate or incomplete taking into account the purposes of processing, there is a right to demand rectification or completion of the personal data in accordance with Art. 16 GDPR.
  • Right to erasure, Art. 17 GDPR: According to Art. 17 Para. 1 GDPR, there is a right to request the erasure of personal data if the processing of personal data is unlawful for one of the reasons mentioned in this provision. However, erasure cannot be requested if further processing is necessary in the cases of Art. 17 Para. 3 GDPR, e.g., to comply with legal obligations.
  • Right to restriction of processing, Art. 18 GDPR: Under the conditions of Art. 18 Para. 1 lit. a to d GDPR, the data subject has the possibility to request the restriction of processing (blocking).
  • A right to data portability in accordance with Art. 20 GDPR: Data subjects have the right to receive their personal data, which they themselves have provided to Labor Krone and which is processed automatically by Labor Krone based on consent or a contract, in a common machine-readable format. This right is subject, among other things, to what is technically feasible.
  • Right to object, Art. 21 GDPR: Data subjects have the right to object to the processing of their personal data, which is processed on the basis of a balancing of interests (Art. 6 para. 1 lit. f GDPR), taking into account the provisions of Art. 21 GDPR.
  • If your objection is directed against direct marketing, for example, no further data processing will take place for this purpose. In other cases, processing may only continue despite an objection if there are compelling legitimate grounds for processing that override the interests, rights, and freedoms of the data subject or if the processing serves the assertion, exercise, or defense of legal claims.
  1. Right of Withdrawal in Case of Consent

In addition, granted consent can be changed or completely revoked at any time with effect for the future and without giving reasons. The revocation does not affect the legality of the data processing carried out based on your consent until any revocation.

You can send us your written revocation/objection as follows:

by mail to:

Labcon-OWL Analytik, Forschung und Consulting GmbH
Datenschutz
Siemensstraße 40
32105 Bad Salzuflen

by email to: datenschutz@labcon-owl.de

or by fax to: 05222 8076-253

This will not incur any additional costs beyond the basic rates.

  1. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority.

The contact details of the supervisory authority responsible for us can be found under point 3 of this declaration.

  1. Obligation to Provide Personal Data

An obligation to provide certain personal data arises from the concluded or to be concluded contracts, insofar as the contract cannot be executed without the provision of the data. Furthermore, legal obligations may have to be observed, which oblige us to collect/process certain data.

In the case of data required for a contract, if information is missing, the contract cannot be concluded or fulfilled.

If data must be provided due to legal obligations, the associated service cannot be rendered without providing the data.

  1. Automated Decision-Making or Profiling

Automated individual decision-making, including profiling, as defined in Art. 22 GDPR, does not take place at Labcon-OWL Analytik, Forschung und Consulting.