Skip to content Skip to footer

Privacy Policy

General Information

We appreciate your visit to our website and your interest in the topic of data protection. In order to inform you about when we collect which personal data and how we use such data, please take note of the following general information.

Data Controller

The controller pursuant to Art. 4 para. 7 of the EU General Data Protection Regulation (GDPR) is:

Gustoso Gruppe GmbH
Fürstenfelder Straße 9
80331 Munich, Germany
Phone: +49 (0)89 2080480000
Email: office@gustoso-gruppe.de

Managing Director: Dr. Nico Engel
Authorized Officers: Philipp Münster (sole power of attorney), Nicole Lernhard (joint power of attorney)

Collection, Processing and Use of Personal Data

The legal bases for the collection, storage and processing of personal data are, in particular, the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data refers to information relating to an identified or identifiable natural person (Art. 4 no. 1 GDPR). This includes in particular names, address data, telephone numbers or email addresses. Information about preferences, memberships or previously visited websites may also constitute personal data.

Contact

If you contact us (e.g. by email or via our contact form), the data you provide will be stored for the purpose of processing your inquiry and for handling any follow-up questions. The legal basis for processing is the necessity for the implementation of pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR. We delete the data incurred in this context once storage is no longer necessary, or restrict processing if statutory retention obligations apply.

Disclosure to Third Parties

We transmit your personal data to third parties insofar as this is necessary for the execution of orders (e.g. transmission of address data to delivery partners) or for the processing of payments. The legal basis for the transfer is the necessity for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR. Personal data will not be passed on to third parties for marketing or advertising purposes without your express consent.

Your Rights

Under the conditions of the GDPR, you as a data subject have the following rights:

  • Right of access pursuant to Art. 15 GDPR to the personal data stored about you, including meaningful information about the details of processing and a copy of your data;
  • Right to rectification pursuant to Art. 16 GDPR of inaccurate or incomplete personal data stored by us;
  • Right to erasure pursuant to Art. 17 GDPR, unless processing is required for exercising the right of freedom of expression and information, compliance with a legal obligation, reasons of public interest, or for the establishment, exercise or defense of legal claims;
  • Right to restriction of processing pursuant to Art. 18 GDPR, if the accuracy of the data is contested, the processing is unlawful, we no longer need the data but you require it for legal claims, or you have objected pursuant to Art. 21 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR, provided you have supplied us with personal data based on consent (Art. 6 para. 1 lit. a GDPR) or a contract (Art. 6 para. 1 lit. b GDPR) and the data is processed by automated means;
  • Right to object pursuant to Art. 21 GDPR, insofar as processing is based on Art. 6 para. 1 lit. e or f GDPR and grounds exist arising from your particular situation or the objection concerns direct marketing;
  • Right to withdraw consent pursuant to Art. 7 para. 3 GDPR with effect for the future;
  • Right to lodge a complaint pursuant to Art. 77 GDPR with a supervisory authority.

Contact Details of the Data Protection Officer

Our Data Protection Officer can be reached at:

FX DATA UG (haftungsbeschränkt)
Verhoevenstrasse 4
81739 Munich, Germany
Phone: +49 89 21111 890
Email: gustoso@fx-data.de

How Is My Data Processed in Detail?

Below we inform you about the individual processing operations, scope and purpose of data processing, legal basis, obligation to provide data and respective storage periods. No automated decision-making, including profiling, takes place.

Provision of the Website

Type and Scope of Processing

When you access and use our website, we collect personal data that your browser automatically transmits to our server. The following data is stored temporarily in log files:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the retrieved file
  • Referrer URL
  • Browser type and operating system, including access provider

Our website is hosted by a service provider who processes the above data on our behalf pursuant to Art. 28 GDPR.

Purpose and Legal Basis

Processing is carried out to safeguard our overriding legitimate interest in displaying the website and ensuring its security and stability pursuant to Art. 6 para. 1 lit. f GDPR. Data collection and log file storage are necessary for website operation. There is no right to object pursuant to Art. 21 para. 1 GDPR. If further storage is legally required, processing is based on Art. 6 para. 1 lit. c GDPR.

Storage Duration

The data is stored for the duration of website display and, for technical reasons, for a maximum of 7 days thereafter.

Contact Form

Type and Scope of Processing

Our website provides a contact form. Mandatory fields are required to process inquiries. Additional information may be voluntarily provided. No data is transferred to third parties when using the contact form.

Purpose and Legal Basis

Processing is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR or, if related to a contractual relationship, on Art. 6 para. 1 lit. b GDPR.

Storage Duration

Data is stored for three years from the completion of the inquiry or from the end of the contractual relationship.

Presence on Social Media Platforms

We operate fan pages/accounts to provide information and enable communication.

Data Processed by Us

When contacting us via messenger/direct message, we process your username and message content.

Legal basis: Art. 6 para. 1 lit. f GDPR.

Usage Data from Platforms

We receive aggregated, anonymized statistics (e.g. page views, interactions).

Data Processed by Social Networks

Social networks may process data (including cookies and tracking technologies), possibly outside the EU/EEA. Details are provided in the respective privacy policies.

LinkedIn Page

LinkedIn is operated by LinkedIn Inc., Sunnyvale, California, USA. We process data provided via our company profile for communication and interaction.

Legal basis: Art. 6 para. 1 lit. f GDPR or consent pursuant to Art. 6 para. 1 lit. a GDPR.

We are jointly responsible with LinkedIn for personal data on our page. Rights are best exercised directly with LinkedIn.

Further information:
https://about.linkedin.com
https://www.linkedin.com/legal/privacy-policy
https://de.linkedin.com/legal/cookie-policy

Cookies

Cookies are small text files stored on your device. Technically necessary cookies enable basic functions; non-essential cookies enable analysis and optimization. Details are available in the cookie settings/consent manager.

Cookiebot

Cookiebot (Cybot A/S, Denmark) is used for cookie consent management.

Legal basis: Art. 6 para. 1 lit. c GDPR.
Privacy Policy: https://www.cookiebot.com/de/privacy-policy/

Cookiebot CDN

Used to deliver content securely and efficiently.

Legal basis: Art. 6 para. 1 lit. f GDPR.
Privacy Policy: https://www.cookiebot.com/de/privacy-policy/

Google Analytics

Used for statistical evaluation and website optimization.

Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.

Data transfer to the USA is based on the EU Data Privacy Framework.

Privacy Policy: https://policies.google.com/privacy

Google CDN

Used as a content delivery network.

Legal basis: Art. 6 para. 1 lit. f GDPR.
Privacy Policy: https://policies.google.com/privacy

Google Tag Manager

Used to manage website tags.

Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.

Privacy Policy:
https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/

Google reCAPTCHA

Used to distinguish human from automated requests.

Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.

Privacy Policy:
https://policies.google.com/privacy?hl=en-US

FX Data Privacy Seal

A privacy seal from FX Data UG is integrated. Your IP address is processed for technical delivery of the seal graphic.

Privacy Policy:

Datenschutzerklärung

Applicants, Employees and Interested Parties

This section covers data processing in the context of applications, employment, suppliers and partners.

Application Process

We process personal data provided during applications. If employment results, data is stored in personnel files as required.

Legal bases include:

  • Employment relationship (Art. 6 para. 1 lit. b GDPR)
  • Legal obligations
  • Consent
  • Detection of criminal offenses

Applicants’ data may be stored for up to six months after rejection or longer with consent.

Data Recipients

Internal departments and external processors (e.g. payroll, IT providers) receive data as necessary, subject to contractual safeguards.

Data Transfers to Third Countries

No transfer of personnel data outside the EEA is currently intended.

Automated Decision-Making

No automated decision-making or profiling pursuant to Art. 22 GDPR takes place.

Data Storage and Deletion

Data is stored for as long as necessary for the purpose and in accordance with statutory retention periods (generally 6–10 years under HGB and AO).

Suppliers and Partners

Data is processed to manage business relationships pursuant to Art. 6 para. 1 lit. b GDPR and stored according to statutory retention periods.