One of the objectives of the GDPR is to protect and clarify the data protection rights of EU citizens and users within the EU. This means that you as a user still have various rights with regard to your data, even if you have already given it to us. These rights are described in more detail below.
If you wish to contact us in connection with these rights, please contact our data protection officer (the contact details can be found under number II) or directly at firstname.lastname@example.org. We will aim to answer your request as quickly as possible, in any case within one month (extensions may be applied to which we are legally entitled). Please note that we may keep records of our communications in order to better resolve any problems you raise.
You have the following rights:
a) Right to confirmation
Every user of our website has the right to request confirmation from us as to whether we are processing his personal data. If the user wishes to make use of this right, he can contact our data protection officer at any time or contact us directly at email@example.com.
b) Right to information
Every user has the right to receive information from us at any time, free of charge, about the personal data stored about him/her as well as a copy of this information. Furthermore, the user can obtain information about the following: purposes of processing
- the categories of personal data to be processed
- the recipients or categories of recipients to whom the personal data have been or are still being disclosed,
- if possible, the planned duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration
- the existence of a right of rectification or deletion of personal data concerning him or of a restriction on processing by the responsible party, or of a right of opposition to such processing
- the existence of a right of appeal to a supervisory authority
- if the personal data is not collected from the data subject: All available information about the origin of the data
- the existence of automated decision-making, including profiling in accordance with Article 22 para. 1 and 4 GDPR and, at least in these cases, meaningful information on the logic involved and the scope and intended effects of such processing for the data subject.
Furthermore, the user has the right to information as to whether personal data has been transferred to a third country or to an international organization. If this is the case, the user has the right to obtain information about the appropriate guarantees in connection with the transmission. If a user wishes to make use of this right to information, he or she can contact our data protection officer or contact us directly at firstname.lastname@example.org at any time.
c) Right to rectification
Every user has the right to demand the immediate correction of incorrect personal data concerning him. Furthermore, the user has the right, taking into account the purposes of the processing, to request the completion of incomplete personal data, also by means of a supplementary declaration.
If the user wishes to make use of this right to rectification, he can contact our data protection officer or contact us directly at email@example.com at any time.
d) Right to deletion (right to be forgotten)
Every user has the right to demand from us that the personal data concerning her be deleted immediately, provided that one of the following reasons applies and insofar as processing is not necessary:
- the personal data has been collected or otherwise processed for such purposes for which they are no longer necessary.
- the user withdraws his consent on which the processing was based pursuant to Article 6 para. 1 letter a GDPR or Article 9 para. 2 letter a GDPR, and there is no other legal basis for the processing.
- the user objects to the processing in accordance with Article 21 para 1 GDPR and there are no overriding legitimate grounds for the processing, or the person concerned objects to the processing in accordance with Article 21 para. 2 GDPR.
- the personal data has been processed unlawfully.
- the deletion of personal data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which Subject To Change GmbH is subject.
- the personal data was collected in relation to information society services offered pursuant to Art. 8 para. 1 GDPR.
- If one of the aforementioned reasons applies and a user wishes to have personal data that is stored with us deleted, she can contact our data protection officer or contact us directly at firstname.lastname@example.org at any time.
e) Right to limitation of processing
Every user has the right to request us to limit processing if one of the following conditions is met:
- the accuracy of the personal data is disputed by the user for a period that enables us to verify the accuracy of the personal data.
- the processing is unlawful, the user refuses to delete the personal data and instead requests the limitation of the use of the personal data.
- Subject To Change GmbH no longer needs the personal data for the purposes of processing, but the user needs it to assert, exercise or defend legal claims.
- the user has filed an objection to the processing according to Art. 21 para. 1 GDPR and it has not yet been determined whether Subject To Change GmbH’s justified reasons outweigh those of the user.
- If one of the above conditions is met and the user wishes to request the limitation of personal data stored with us, he can contact our data protection officer or contact us directly at email@example.com at any time.
f) Right to data transferability
Every user has the right to receive the personal data concerning him, which was made available to us by the user, in a structured, current and machine-readable format. Furthermore, she also has the right to transmit this data to another responsible person without our interference, provided that the processing is based on the consent according to Art. 6 para. 1 letter a GDPR, or Art. 9 para. 2 letter a GDPR, or on a contract according to Art. 6 para. 1 letter b GDPR and the processing is carried out using automated procedures, provided that the processing is not necessary for the performance of a task in the public interest or in the exercise of public authority which has been transferred to us.
In addition, when exercising their right to data transferability pursuant to Art. 20 para. 1 GDPR, the user has the right to ensure that the personal data be transferred directly from one responsible party to another responsible party, insofar as this is technically feasible and provided that the rights and freedoms of other persons are not affected by this.
To assert the right to data transferability, the user can contact our data protection officer or contact us directly at firstname.lastname@example.org at any time.
g) Right to object
Every user has the right to object at any time to the processing of personal data concerning her on the basis of Art. 6 para. 1 letter e or f GDPR for reasons arising from her particular situation.
h) Right to revoke consent under data protection law
Every user has the right to revoke his consent to the processing of personal data at any time.
If a user wishes to exercise his right to revoke his consent, he can contact our data protection officer or contact us directly at email@example.com at any time.
i) Right to appeal to a supervisory authority
The user has the right to file a complaint with the competent local supervisory authority. Details on how to contact the authority can be found here:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Tel.: +49 (0)30 13889-0
Fax: +49 (0)30 2155050