Privacy policy of the SOLIT Group

A. Responsibility for data processing

The party responsible for the processing of personal data in accordance with the General Data Privacy Regulation (GDPR) is:

SOLIT Management GmbH
Borsigstraße 18
65205 Wiesbaden
Germany
E-mail: info@solit-kapital.de
Phone: +49 (0)61 22 58 70-70
Fax: +49 (0)61 22 58 70-77

Controller for the retrieval, processing and use of personal data: datenschutz@solit-kapital.de

With this privacy policy, we inform you about the extent of our processing of your personal data (hereafter referred to as “data”)

B. Data processing

We collect and process data to ensure full functionality of our website. The processing of data includes their disclosure due to transmission.

For the transmission of data to the U.S., the European Commission has established an adequacy determination, the EU-U.S. Privacy Shield Framework. The European Commission confirmed that the Privacy Shield Framework is a valid legal mechanism to comply with EU requirements when transferring personal data from the EU to the United States. To the extent that we transmit data to the U.S., we have marked the participation of our service providers in the EU-U.S. Privacy Shield Program.

In the following, please find a list of specifications regarding the types of data, processing purposes, legal basis, recipients and transmissions into third countries:

a) Log files

We register when a data subject calls up our websites. We process the following data: name of the accessed file, the date and time of access to the Internet site, the data volume transmitted, the browser types and versions used, the operating system used by the accessing system, the website from which an accessing system reaches our website (referrer), the Internet protocol address (IP address) and the Internet service provider of the accessing system. We process the data in accordance with our legitimate interest pursuant to Art. 6 (1) (f) GDPR, to ensure security of our online services. The log files will be deleted after seven days, unless they are required to verify or prove an alleged illegal use of the website services, which has become known during the data safekeeping period.

b) Hosting

In the context of hosting this website, we store all data processed in connection with its operation. This is necessary to operate this website. All data is processed based on our legitimate interests in accordance with Art. 6 (1) (f) GDPR. To provide our online services, we use the services of web hosting providers, to whom we transfer the aforementioned data.

c) Contacting us

If a data subject contacts us, his or her data (name and contact details, if specified) and message will be processed solely for the purposes of dealing with the request. All these data, which are required to handle your request, are processed in accordance with Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR.

Certification under: https://www.privacyshield.gov/participant?id=a2zt0000000KzLyAAK&status=Active
For additional information regarding data privacy please visit: https://www.salesforce.com/company/privacy/

d) Processing of contracts and applications

If a data subject contacts us via the contact form or per e-mail, his or her name, first name, e-mail address, telephone number (if provided) and the message will be stored to process and execute the request. In addition, we process data to mail brochures and/or application forms ordered by the data subject. These data are processed based on your consent in accordance with Art. 6 (1) (a) GDPR or to fulfil our pre-contractual or contractual duties pursuant to Art. 6 (1) (b) GDPR.

If a data subject submits a legally binding offer (e.g. via our online application registration or a printed application) to enter into a contract for a SOLIT Precious Metal Depot, a SOLIT SECURE STORAGE account or any other service offered by us, TRESTA Treuhandgesellschaft mbH, An der Werft 5, 21680 Stade will collect, process and use all data of this data subject which is required to execute the contract and fulfil the legal and contractual obligation of the SOLIT Management GmbH. Additional information is available at https://www.tresta-stade.de.

Data, which are transmitted to the service provider Salesforce.com, inc. in connection with the execution of the contract and application, will be saved on the Salesforce servers in Frankfurt am Main, Germany. For back-up purposes, a mirror backup of all data is regularly transmitted to Paris, France.

Certification under: https://www.privacyshield.gov/participant?id=a2zt0000000KzLyAAK&status=Active
For additional information regarding data privacy please visit: https://www.salesforce.com/company/privacy/

e) Newsletter

We offer our customers the option of receiving a newsletter so that we can regularly share information with them about our organisation and our offers.

If a data subject signs up for the newsletter, we will process the data he or she provided (e-mail address or any other optional information submitted). The mailing of newsletters following registration takes place based on your consent pursuant to Art. 6(1) (a) GDPR.

Signing up to our newsletter is based on what is referred to as the double opt-in method. To prevent misuse, once customers have signed up, we will send them an e-mail asking them to confirm their subscription. The sign-up of our data subjects is logged so that we can prove that the subscription process complies with the legal requirements. The log entry records the time and date of their initial sign-up and confirmation, along with their IP address. For sending out the newsletter, we use service providers to whom we pass on the aforementioned data.

These data are transferred to the servers of the following service providers in the USA:

Mailchimp: Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308

Certification under: https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active
For additional information regarding data privacy please visit: https://mailchimp.com/legal/privacy/

f) Customer account

By opening a customer account, the data subject consents to his or her basic data (name, address, e-mail address, bank details) and user data (user name, password) being stored. This allows us to identify the data subject as a customer and lets us manage his or her orders. These data will be processed on the basis of the data subject’s consent pursuant to Art. 6(1) (a) GDPR.

g) Webinars

If data subjects participate in one of the webinars we organise, their participation data are processed for this purpose. These data are processed based on their consent in accordance with Art. 6(1) (a) GDPR or to fulfil our pre-contractual or contractual duties pursuant to Art. 6(1) (b) GDPR. To provide our online services, we use the services of webinar suppliers in Germany to whom we transmit the above-mentioned data.

h) Website analysis and marketing

We use cookies to enable the use of certain functions. Cookies are small data packages that are stored on the data subject’s device and exchanged with other providers. Some of the cookies we use are deleted as soon as data subjects close their browser (session cookies). Others remain on the device, enabling us to recognise a particular data user’s browser the next time he or she visits (persistent cookies).

Data subjects can delete all cookies stored on their device and configure commonly used browsers to prevent cookies from being stored. If they do this, they may have to repeat some settings every time they visit this website, and also accept that some functions may be impaired.

We use cookies in connection with the following functionalities:

aa) Google Analytics

The information generated by the cookie about a data subject’s use of this website (including the IP address) is transferred to a Google server in the USA and stored there. We use this information to analyse his or her use of the website in order to compile reports on the website activity for the website operators and to provide other services associated with use of the website. We process the data obtained in this way on the basis of our overriding interest in optimising the marketing of our services in accordance with Art. 6(1) (f) GDPR. Google will never link data subjects’ IP addresses to other Google data.

We would like to point out that this website uses Google Analytics with the “anonymizeIp()” extension. This ensures that IP addresses are truncated before they are transferred to the server in the USA, which normally makes it impossible to directly identify individuals in connection with the stored data. Only in exceptional cases is a full IP address transmitted to a Google server in the United States and truncated there.

Data subjects can opt out of our data collection at any time with future effect by using the browser add-on for deactivating Google Analytics at https://tools.google.com/dlpage/gaoptout?hl=de.

Please also read the following notes on how Google uses data in its partner network: https://www.google.com/intl/de/policies/privacy/partners/

Google is certified under: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For additional information regarding data privacy please visit: https://policies.google.com/privacy/partners?hl=de and https://policies.google.com/privacy?gl=de

bb) Google remarketing/retargeting

We use what is referred to as “tracking cookies” on our website. When a data subject visits our website, information about which of our products he or she looked at and which advertisements and third-party websites took the data subject directly to our website is stored in permanent cookies. If he or she then visits one of our partner websites, we can have personalised advertising displayed based on which of our items were viewed by the data subject.

We process the data obtained in this way on the basis of our overriding interest in optimising the marketing of our services in accordance with Art. 6(1) (f) GDPR. The information generated by the cookie about the data subject’s use of this website (including the IP address) is transferred to a Google server in the USA and stored there.

Google is certified under: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For additional information regarding data privacy please visit: https://policies.google.com/privacy?hl=de&gl=de

i) Integration of external content

We use external dynamic content to optimise the appearance and content of our website. When a data subject visits our website, a request is automatically sent to the server of the relevant content provider via API, transferring certain log data (e.g. the data user’s IP address). The dynamic content is then transferred to our website and displayed there. We use external content in connection with the following functionalities:

aa)  Integration of YouTube videos

We have integrated videos from the YouTube portal operated by YouTube LLC, 901 Cherry Ave. San Bruno, CA 94066, USA (“YouTube”) into our website. When a data user plays back these videos, log data is transferred to YouTube’s servers in the USA. This data is processed on the basis of our overriding legitimate interest in optimising the marketing of our services in accordance with Art. 6(1) (f) GDPR.

YouTube is certified under: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Additional information are available at: https://policies.google.com/privacy?hl=de&gl=de

bb) Google Maps

We use Google’s “Google Maps” on our website to provide data users with an interactive map. When the map is displayed, data including data subjects’ IP addresses and location are transferred to Google’s servers in the USA and stored there. This data is processed on the basis of our overriding legitimate interest in optimising the marketing of our services in accordance with Art. 6(1) (f) GDPR.

Google is certified under: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For additional information regarding data privacy please visit: https://policies.google.com/privacy?hl=de&gl=de

cc) Google Fonts

To make a visit to our website more attractive, we use external fonts provided by Google Fonts. When a data subject visits our website, these are loaded automatically from the servers of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google). During this process, Google stores no cookies in the data subject’s browser. According to our information, the IP address of the end user’s device is transmitted to Google and stored there. This data is processed on the basis of our overriding legitimate interest in optimising the marketing of our services in accordance with Art. 6(1) (f) GDPR.

Google is certified under: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For additional information regarding data privacy please visit: https://policies.google.com/privacy?hl=de&gl=de

C. Duration of data storage

We store personal data only for as long as is necessary for the purposes for which it is being processed or until a data subject withdraws his or her consent. Insofar as statutory retention requirements need to be complied with, the retention period for certain data can be up to 10 years, regardless of the purposes for which it is being processed.

D. Rights of the data subject

a) Right of information

At any time, data subjects are entitled to request free information about all the personal data we stored about them.

b) Rectification, erasure, restriction of processing (blocking), opting out

If a data subject no longer agrees to his or her personal data being stored or if his or her personal data is no longer correct, we will, upon receipt of a corresponding instruction from the data subject, have his or her data erased or blocked or make the necessary corrections (to the extent possible under applicable law). The same applies if a data subject requests us to restrict the processing of his or her data in the future.

c) Data portability

On request we will provide data subjects their data in a commonly-used, structured and machine-readable format, so that they can transfer it to another controller if they wish.

d) Right of complaint

Data users have the right to lodge a complaint with the responsible supervisory authority: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

e) Right to withdraw consent with future effect

Data subjects are entitled to withdraw their consent at any time with future effect. This will not affect the legality of the processing prior to their withdrawal.

f) Restrictions

The above rights do not apply to data where we are not able to identify the data subject, for example if the data has been anonymised for analysis purposes. It may be possible for data subjects to exercise their rights to information/access, erasure, blocking, rectification, or transfer to another organisation in relation to these data, if they provide us with additional information that enables us to identify them.

g) Exercising the rights of data subjects

If data subjects have any questions about the processing of their personal data, or if they wish to exercise their rights to access/information, rectification, blocking, opt-out or erasure of data, or if they wish their data to be transferred to another organisation, they may contact datenschutz@solit-kapital.de.