privacy policy

Privacy declaration

Responsible Authority

We are happy about your visit to our website. We would like to introduce ourselves as the responsible authority within the meaning of data protection law:

Navina Baur
Placa de la Quartera 3
07002 Palma
Phone: +4916099114866
E-mail: hello@navinabaur.com

General Information

Pursuant to our statutory obligations, we would like to inform you about the collection and use of your personal data.

When you use our website, personal data about you will be collected. This may happen by you entering the data yourself, for example your e-mail address. But our system also collects your data automatically, for example whenever you visit our website. This happens irrespective of the device or the software that you use to visit our website.

All data that you enter in our app is provided voluntarily; there are no disadvantages to you if you do not provide data. But without certain data, we are unable to provide services or to conclude contracts. Whenever such information is necessary, we will point it out to you.

On this website, the user’s personal data is only collected within the framework of the existing data-protection law, in particular the General Data Protection Regulation (GDPR). The legal terms used in the text are defined in Art. 4 of the GDPR.

The GDPR allows data processing in three cases in particular:

in accordance with Art. 6 para. 1 (a) and 7 GDPR, when you have consented to us processing your data; in this Privacy Policy and in the cases of consent pursuant to Art. 4 no. 11 GDPR, we will inform you in detail and each time for what purposes and under what circumstances your data will be processed by us;
in accordance with Art. 6 para. 1 (b) GDPR, when processing your personal data is necessary for negotiating, concluding or performing a contract;
in accordance with Art. 6 para. 1 (f) GDPR, if the balancing of interests leads to the conclusion that the processing is necessary to protect our legitimate interests; this means in particular our interests to analyse, optimise and secure the offers on our website – meaning primarily the analysis of user behaviour, setting up profiles for advertisement purposes and storage of access data as well as the use of third-party providers.
Inventory Data

We collect inventory data as far as it is necessary to establish, negotiate or amend a contract (including one without remuneration) between us and the user. This can be: customer data (for example name, address), contact data (for example e-mail address, phone number), service data (for example services ordered, duration, payment). Upon establishing the user relationship, we will ask you for this data (for example name, address and e-mail address) and will also tell you which of the information is required to establish the user relationship.

Usage Data

We also collect usage data to allow users to use the services on our website. These may consist of: usage information (for example visited websites or parts, duration of visit, interest in services), content data (for example data, text, images, sounds, videos entered or uploaded by you), meta data (for example identity of your device, location, IP address).

We will only combine usage data if and insofar as it is necessary for billing purposes. Otherwise, we will only put together usage data pseudonymously and only insofar as you have not objected. You may send this objection to the address indicated in the “About Us” section or the responsible authority indicated in this Privacy Policy at any time.

The legal basis for this data processing are our legitimate interests pursuant to Art. 6 para. 1 (f) GDPR in analysing the website and your use, possibly also the statutory permission to store data as part of the negotiation of a contract pursuant to Art. 6 para. 1 (b) GDPR.

Furthermore, our provider stores information, the so-called server log files, each time the website is used; this is information which is automatically transferred by your browser. In detail, this data consists of:

your IP address
type and version of your browser
host name
time of visit
the page from which you came to our page
name of the page opened
exact time of usage as well as
the amount of data transferred

This data will only be used for statistical purposes and do not allow us to identify you as a user.
Advertisements

Before sending you advertisements, we will ask for your explicit consent pursuant to Art. 4 no. 11 GDPR, except in cases of advertisements for similar products to the one you already acquired. This will happen in particular when you grant us consent to mail our newsletter or when you fill out a contact form.

You may withdraw your consent at any time in accordance with the subsequent section “Consent”.

INSOFAR AS WE USE YOUR PERSONAL DATA FOR DIRECT MARKETING, YOU MAY ALSO OBJECT TO THE USE OF YOUR DATA FOR THAT PURPOSE AT ANY TIME. THIS MAY BE DONE THROUGH ANY OF OUR MEANS OF CONTACT, PARTICULARLY BY E-MAIL TO THE E-MAIL ADDRESS LISTED IN THE “LEGAL NOTICE” SECTION WITHOUT ANY FORMAL REQUIREMENTS. WE WILL THEN NO LONGER USE YOUR DATA FOR DIRECT MARKETING.
First Contact through Electronic Request

If you contact us in electronic form (for example by mail, fax, phone, messenger, etc.), we store and process the data which you have given us (for example name, contact information, content of the request). This is based on our legitimate interest in an effective communication with customers in accordance with Article 6 para. 1 (a) GDPR and, as far as it concerns a request to enter into or to perform a contract, also with Article 6 para. 1 (b) GDPR.
We will only pass on this data to third parties as far as required for the performance of the contract (in accordance with Article 6 para. 1 (b) GDPR), by the overwhelming interest in effective services (in accordance with Article 6 para. 1 (f) GDPR) or based on your consent (in accordance with Article 6 para. 1 (a) GDPR) or if there is another legal permission or obligation.
You may ask us at any time and without any cost to provide information about the purpose of the processing, the origin and the recipient, if any, of your data. You may also request that we correct, delete or limit the processing of your personal data. You may object against the (further) processing of your data at any time and you have a right for the data to be made transferable as well as the right to file a complaint with the competent supervisory agency.
In general, your data will only remain stored as long as required by the purpose of the respective data processing. A longer storage is an option, in particular when required in order to pursue our rights, for other legitimate interests of ours or when there is a statutory duty to keep the data longer (for example record-keeping under tax law, statute of limitations).

Consent

Whenever we ask you for your consent for the processing of your data, we will inform you in clear language and in an easily accessible way about the cases for which you will be granting your consent. Any consent that we ask you for is voluntary. Any advantage that you wish to gain by granting consent is also available without consent; simply ask us.

Regarding any consent, you have the right to revoke any consent given to us for the processing of your personal data at any time. You just need to contact us without any particular formal requirement, for example through our contact form, an e-mail to the e-mail address indicated in the “About Us” section or a link to unsubscribe (if offered by us). Your withdrawal has no effect on the legality of the data processing carried out up to that point.

Storage Period

Generally, your data will only remain stored as long as required by the purpose of the respective data processing. Storage beyond that is possible in particular if it is still required for pursuing our rights or for other legitimate interests of ours.
For your inventory data which were necessary to perform a contract (including one without remuneration), this means that we store this data until the complete performance or termination of the contractual relationship plus the limitation period (which is generally 2 or 3 years) plus an adequate extra time for potential interruptions of the limitation period.
For your usage data which was collected in the course of your use of the website, this means that we will store it only for the time still required for the proper functionality of our website and as long as we still have a legitimate interest. Statistical information will be primarily stored by us in pseudonymous form.
Beyond that, we still store your data for as long as we are required to do so by law. This concerns in particular the tax-law requirements to keep records, usually for 6 or even 10 years.

Cookies

Cookies

Based on our legitimate interest in a flawlessly functioning online offer and its economic and efficient design and optimization according to Article 6 para. 1 (f) GDPR, our website uses cookies in order to allow you to use our offer better, more effectively and in a more secure way. Cookies are text files that are stored on your computer and which store certain data about your user behavior on our page, so that certain features or offers can be made available to you based on your previous use. These can be “session cookies”, which are automatically deleted when you leave our website. Other cookies are stored on your computer permanently until you delete them. That allows us to recognize your browser when you visit our website again and to provide you with features or offers according to your previous usage.
Your browser allows you to prevent the use of cookies in general or in specific cases. Please check the instructions for your browser to find out more about this. You can also delete cookies following these instructions which we have listed for you:

for Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en
for Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
for Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
for Edge: https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies
for Internet Explorer: https://support.microsoft.com/en-gb/help/278835/how-to-delete-cookie-files-in-internet-explorer

Blocking cookies may limit the functionality of our website and of other websites visited by you.
More information on this topic, in particular how you can administer, limit or completely disable third-party cookies and technologies with a similar purpose, can be found at:
http://www.aboutads.info/choices
http://www.youronlinechoices.eu
http://www.networkadvertising.org/choices

Users‘ Rights

You may request us anytime to provide information about the personal data stored about you free of charge. To avoid misuse, this will require personal identification.

Deletion, Correction, Limitation

You may at any time demand from us that we correct (or complete) incorrect data as well as a limitation of the processing of data or deletion of your data. This applies in particular if the reason for processing the data is no longer valid, if a required consent has been revoked and there is no other legal basis or if our data processing is unlawful. We will then correct, block or even delete your personal data without delay as far as permitted by law.

Objection

The right to object to advertisement is governed by our text regarding consent:

Regarding any consent, you have the right to revoke any consent given to us for the processing of your personal data at any time. You just need to contact us without any particular formal requirement, for example through our contact form, an e-mail to the e-mail address indicated in the “About Us” section or a link to unsubscribe (if offered by us). Your withdrawal has no effect on the legality of the data processing carried out up to that point.
Data Transfer

You may request us to transfer the data stored about you in machine-readable form.

Complaint

If you feel that our data processing has violated any of your rights, you may file a complaint with the competent regulatory agency (here you find a list of the agencies).

Changes to the Privacy Policy

If and when factual or legal reasons will compel us to amend the Privacy Policy, we will update this page accordingly. This will not change the consent provided by the user.

Data Entry

Encryption of Data Entry

When you enter data on our website, whether in a contact form, during the registration process, when you log in or for payment purposes, the website, where you enter the data, is encrypted. Thus, third parties can not read what you enter. You will recognise the encryption by the lock symbol in your browser and by the URL beginning with “https“ instead of “http“.

Contact Forms

General contact form

When you fill out a contact form or when you send us an e-mail or another electronic message, your information will be stored for the processing of the request, for possible follow-up questions or for other related questions and will only be used to follow up with the request.

Your data will be transferred in an encrypted manner, preventing third parties from reading your data while it is being entered.

Basis for this storage is your consent pursuant to Art. 6 para. 1 (a) GDPR, which you grant us by filling in the contact form or by your other requests. You may revoke this consent at any time, you just need to contact us without any particular formal requirement (for example in the contact form or by e-mail). This withdrawal has no effect on the legality of the data processing that has occurred up to that point.

Your data remains stored for as long as the processing of the request requires, in particular as long as the storage is still necessary to perform the contract, to pursue our rights or for our other legitimate interests or we are compelled by law to keep your data stored (for example based on tax-law requirements to maintain files).

Shop

On our shop page, you find a contact form, through which you may request a specific offer for our services. We will ask for your e-mail address, your company name and the scope of your business, so we can prepare an offer that will serve your specific interests.

Your data will be entered in an encrypted manner, so that third parties cannot read your data while being entered.

The legal basis for this storage is our legitimate interest in communication with interested users in accordance with Art. 6 para. 1 (f) GDPR and in case of contractual requests also the storage of contractual data in accordance with Art. 6 para. 1 (b) GDPR.

These data remain saved until you will terminate your access by sending an e-mail to the e-mail address listed in the "About Us" section. After that, they will remain stored in connection with the necessary performance of the contract (see the section on user/contract data).

Return Call

On our service page, you can ask for a call from one of our customer service agents.
We will ask for
– your first name, because we like to address your personally,
– your phone number, so we can call you, and
– your e-mail address, because we will e-mail you to confirm your request.

Your data will be entered in an encrypted manner, so that third parties cannot read your data while being entered.

The legal basis for this storage is our legitimate interest in communication with interested users in accordance with Art. 6 para. 1 (f) GDPR and in case of contractual requests also the storage of contractual data in accordance with Art. 6 para. 1 (b) GDPR.

We will only use this data for your specific request and will save it for 6 months after the request has been completed, so we can refer to the results already achieved in the case of subsequent service requests.

Online calendar

Calendly

Based on our legitimate interest in a technologically perfect online offering and its design and optimization in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR, we use the calendar of Calendly https://calendly.com/de, a service offered by Calendly LLC, 1315 Peachtree St NE, Atlanta, GA 30309, USA, to make appointments.

Thus, the data you enter while making an appointment will be passed to Calendly. Your data will be transmitted to the USA in that process. But Calendly has subjected itself to the Privacy Shield framework. You can find more information about your rights thereunder at http://ec.europa.eu/justice/data-protection/document/citizens-guide_en.pdf .
You can find more information about the privacy policy of Calendly at https://calendly.com/de/pages/privacy. We have also entered into a contract on data processing with Calendly, according to which Calendly will only process your data according to our instructions.

In order to arrange an appointment, we ask for the data requested in the Calendly form and we collect your IP address at the time of entry. This data will not be passed to third parties by us or by Calendly and only serves statistical purposes and for arranging appointments. Data entry will be encrypted, preventing third parties from reading your data while you enter it. You will find more information about the data collected by Calendly and how they process your data in the privacy policy of Calendly .

Your data will remain stored as long as the reason for the appointment is still relevant, in particular as long as the storage is still necessary to perform the contract, to pursue our rights or for other legitimate interests of ours or as long as we are required by law to keep your data stored (for example by tax-law requirements on the keeping of records). If the appointment passes without any consequences, your data will be deleted.

Newsletter

Mail Chimp

If you subscribe to the newsletter offered on our website, we will inform you in detail about the information you will receive, which of your data will be stored and what it will be used for. We will not pass on your data to third parties and we will only use it to mail the newsletter.

We will only mail you the newsletter if you have given us your prior permission. To that purpose, you will receive an e-mail from us with a link and further instructions and our request for your consent. By clicking on this link, you declare your consent to receiving the newsletter and our advertising.

Because we are legally obligated to record your permission as part of the so-called double opt-in, your order of the newsletter, the mailing of our e-mail of consent and your consent by clicking on the link will be recorded and saved with location and time as well as with your IP address.
The basis for the storage is your consent pursuant to Art. 6 para. 1 (a) GDPR, which you grant to us by registering for the newsletter. You may revoke this consent at any time, you just need to contact us without any particular formal requirement (for example through the contact form or an e-mail or the unsubscribe button in each e-mail). This withdrawal has no effect on the legality of the data processing that has occurred until that point.

For mailing the newsletter, we use (based on our legitimate interest in a technologically perfect processing of our customer information and analysis) the provider MailChimp (Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA) from the USA.
This means, your data will be exportet to the USA, but MailChimp is registered with Privacy Shield and must adhere to EU data protection rules.

In our newsletter, we will also explicitly ask you to provide your consent to transferring data to MailChimp and to the USA. You will declare that consent by clicking on the link, but you may revoke it at any time. For the handling of your data at MailChimp, we refer you to the Privacy Policy of MailChimp at: https://mailchimp.com/legal/privacy/.
MailChimp will only use your data for mailing the newsletter and for evaluating that mailing on our behalf. In addition to that, MailChimp will only use your data to improve their own service. But MailChimp will not use the data to contact you directly or to pass on your data to third parties.

The mails used by MailChimp contains a “web beacon“, which will inform MailChimp about the opening of the newsletter and/or the clicking on a link contained therein by you. As part of that process, information regarding your browser, your location and your IP address will be transmitted to MailChimp. This information will be used to optimise our communication with you.

Our newsletter provider will also use this data for purposes of analysis and optimisation of their own service, but only in pseudonymised form (meaning that your identification is not possible). But your data will not be used by the provider to contact you directly.

Your data will remain stored for as long as you are stored in our mailing list, the storage is required to enforce our rights or it is necessary for our legitimate interest or we are required by law to keep your data.

Social Media

Social Media Links

General Information

We refer with links to our social media presences. When you follow any such link to the social media site, your data will be broadcasted to that site. The social media site will normally store a cookie in your browser and to your account information there, especially, if you are logged into your social media account on the site. The social media site can analyse your use of the platform and your browsing habits and will use these for targeting advertisements based on your interests. That can lead to ads being shown to you when browsing in- and outside of the social media site. Please inform yourself about the use of your data on these sites and use them only, when you agree to that use of your data, that happens on that social media site, in particular, when you are not using that social media site for the first time. We have added links to all the privacy policies of the social media site for your information.

Facebook

Our website uses links to our presence in the social network of Facebook by Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. It is just a normal link. Thus, when you open our site, Facebook will not learn of your visit to our website. But once you click on the link, you will be led to Facebook, allowing Facebook to learn that you have visited out site.

That way, your data will be transferred to the USA.

The collection and use of your data which is possibly carried out by Facebook after clicking on the link is beyond our knowledge or control. You may find further information in Facebook’s privacy policy at http://de-de.facebook.com/policy.php.

Instagram

Our website uses links to our presence in the social network of Instagram by Instagram LLC, now
Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour.

It is just a normal link. Thus, when you open our site, Instagram will not learn of your visit to our website. But once you click on the link, you will be led to Instagram, allowing Instagram / Facebook to learn that you have visited out site.
That way, your data will be transferred to the USA, but Instagram.

The collection and use of your data which is possibly carried out by Instagram/Facebook after clicking on the link is beyond our knowledge or control. You may find further information in Instagram’s privacy policy at
https://help.instagram.com/155833707900388.

Linkedin

Our page uses links to our presence on the social network LinkedIn, provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, as a subsidiary of LinkedIn Corporation, 2029 Stierlin Ct. Ste. 200 Mountain View, CA 94043, USA.

It is just a normal link, which means that upon opening our page, LinkedIn won't learn anything of your visit to our website. But when you click on the link, you will be taken to LinkedIn, and then LinkedIn will also learn that you visited our page.

Thus, your data may be forwarded to the USA.

We have neither knowledge of, nor any influence on the possible collection and processing of your data by LinkedIn after clicking on the link. Further information can be found in LinkedIn's privacy policy at https://www.LinkedIn.com/legal/privacy-policy?_l=de_DE.

Twitter

Our page uses links to our presence on the social network Twitter, provided by Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 IRELAND
It is just a normal link, which means that upon opening our page, Twitter won't learn anything of your visit to our website. But when you click on the link, you will be taken to Twitter, and then Twitter will also learn that you visited our page.

Thus, your data may be forwarded to the USA.

We have neither knowledge of, nor any influence on the possible collection and processing of your data by Twitter. Further information can be found in the privacy policy of Twitter at https://twitter.com/privacy?lang=en.

Social Media Videos

Vimeo (Two Klick)

Based on our legitimate interest in a technologically perfect online offering and its design and optimisation in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR we use Vimeo, a service provided by Vimeo, Inc., 555 West 18th Street, New York, New York 10011 in order to embed videos.
To protect your data, we have installed a two-click solution. That way, Vimeo won't learn about your visit once you access our website, but only once you actually click the button. If you confirm the plugin while being logged in at Vimeo, Vimeo may attribute your use to your user account.

That way, your data will be transferred to the USA.

The collection and use of your data which is possibly carried out by Vimeo after clicking on the link is beyond our knowledge or control. You may find further information in Vimeo's privacy policy at
https://vimeo.com/privacy.

Regarding the general approach to cookies and their deactivation, we refer you to our general information in this Privacy Policy.

Payment providers

Stripe

If you choose one of the payment options of our partner Stripe, provided by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, the data entered by you when ordering will be sent to Stripe in order to facilitate the contractual payment. Detailed information about this can be found in the privacy policy of Stripe:

https://stripe.com/privacy

The legal basis for passing on your data to Stripe is primarily the processing of your contractual data according to Art. 6 para. 1 (b) GDPR as well as our legitimate interest in a technologically perfect online offering and its design and optimisation in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR.

HubSpot

Based on our legitimate interest in a flawlessly functioning online offer and its economic and efficient design and optimization according to Article 6 para. 1 (f) GDPR, as well as – insofar as it concerns the storage of your contractual data – based on the permission to process contractual data in accordance with Art. 6 para. 1 (b) GDPR, we use the integrated hosting and marketing solution of HubSpot Ireland Limited, 2nd Floor 30, North Wall Quay, Dublin 1, Ireland. HubSpot Ireland Limited is a subsidiary of a company registered in the USA. But the Irish company is the data processor in the EU.

More information about the data processing carried out by HubSpot can be found in the privacy policy of HubSpot: https://legal.hubspot.com/de/privacy-policy

A transparent list of the cookies potentially placed by HubSpot can be found here and here

We have also concluded a data processing contract with HubSpot, according to which HubSpot will only process your data on our behalf: https://legal.hubspot.com/de/dpa

HubSpot offers the following features:
Hosting
CMS (Content Management System)
Contact Forms
Newsletter Software
Tracking and Analysis
CRM (Customer Relation Management)
Chat Software
Of these, we use the following features:

HubSpot Hosting / CMS / CMR

Based on our legitimate interest in a technologically perfect online offering and its design and optimization in an economically efficient manner, we use HubSpot for hosting our website. As any other hosting service, HubSpot collects usage data. These are identified and non-identifiable data on the occasion of you accessing our website. These will either be made available to HubSpot or automatically collected when you use HubSpot services (“non-personal data”).

Non-personal data does not allow HubSpot to find out the origin of the data. Non-personal data are technical information and usage information, for example the browsing and click stream behavior of visitors and users of services, session heat maps and scrolls as well as non-identifiable data about the user's or visitor's used device, operating system, browser, screen resolution, language and keyboard settings, internet provider, referral and exit pages, date/time stamp, etc.

As a hosting service, HubSpot also collects data that can identify a person with manageable effort (“personal data”). This personal data generally consists of all data that you enter when using the website. These can be contact data (for example e-mail address or phone number), invoice data (name, billing address, payment method and bank connection), data regarding a browser or user session (IP address, geographic location and/or unique identification of the user's device), data regarding connected accounts of third parties (for example e-mail address or user name for a connected PayPal, Google or Facebook account), scanned identity papers sent to us (for example ID card, driving license, passport or company registration documents), and any other personal data.

HubSpot also undertakes physical, electronic and procedural security measures to protect your personal data. HubSpot has more information about this here: https://legal.hubspot.com/data-privacy?__hstc=230861184.05b1c26761c5da0b5d0ce9ba8c0bc3af.1496406325284.1496406325284.1496406325284.1&__hssc=230861184.1.1496406325285&__hsfp=80863953

Based on contractual data, we use HubSpot for our Customer Relation Management System. Here, we store all data, which you have conveyed to us when entering into a contract, in particular your name, your contact information, payment information and products purchased, if applicable. We will keep this data stored as long as required for the performance of the contract (in particular the warranty period) or as long as we are required by law to keep your data stored (for example the data required for taxation).

HubSpot Contact Form

Based on our legitimate interest in efficient communication with our customers and based on contractual data, we also use HubSpot for contact forms on our website. HubSpot receives all data that you enter in our forms and also collects usage data. For more details, we refer you to our general information about contact forms.

Various

Zoom.us (online webinars)

Based on our legitimate interest in a technologically perfect online offering and its design and optimization in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR, we use the the provider Zoom.us, offered by Zoom Video Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA, for online meetings and webinars.
If you participate in an online meeting, the data you enter upon registration will also be sent to Zoom. But Zoom will not use this data for its own purposes. You will only be reminded of the event for which you registered.
As organizers of the meeting or the webinar, we may make recordings and store them for ourselves. With your registration, you declare your consent to the recording and to our use thereof, but usually no personal data of yours will be revealed (you can also register under a pseudonym). That would only happen if you were to participate with your image. In that case, we would ask for your consent to use your image.
As we pass data to Zoom, the data will be sent to the USA.
We have no knowledge about the possible collection and use of your data by Zoom, nor do we have any influence on that. More information can be found in the privacy policy of Zoom at https://zoom.us/privacy. For the general approach to cookies and about their deactivation, we refer you to our general information about cookies in this privacy policy.

Built with Datenschutz Generator of https://easyrechtssicher.de

This is our current valid privacy policy from 10.03.2020