PRIVACY POLICY
We look forward to your visit to our website. Below we would like to inform you about the handling of your personal data according to Article 13 of the General Data Protection Regulation (GDPR).
​
1. Data Controller
Responsible for data collection and processing:
PICANOVA GmbH
HRB 58130
Hohenzollernring 25
​
2. Data Protection Officer
For requests concerning GDPR, please contact: data-protection-officer@tcgroup.com
For further requests, our company data protection officer is at your disposal for information or suggestions concerning data protection:
Datenschutz süd GmbH
Wörthstraße 15
97082 Würzburg, Germany
Email: office@datenschutz-sued.de
50672 Cologne
​
3. Personal Data We Collect
We collect limited personal data when you visit our site:
​
Automatically Collected Data
-
IP address (anonymised for analytics)
-
Browser type and version
-
Operating system
-
Date and time of visit
-
Pages visited on our website
-
Referring website
Voluntary Data
-
Contact information (if you contact us via email or contact forms)
​
4. Purposes and Legal Basis for Processing
We process your personal data for the following purposes:
Purpose: Website functionality and security
Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR)
Data Categories: Technical data, IP address
Purpose: Website analytics and improvement
Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR)
Data Categories: Usage data, anonymised analytics
Purpose: Responding to inquiries
Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR)
Data Categories: Contact information
Purpose: Marketing communications
Legal Basis: Consent (Art. 6(1)(a) GDPR)
Data Categories: Email address (if disclosed), preferences
​
Purpose: Advertising and tracking
Legal Basis: Consent (Art. 6(1)(a) GDPR)
Data Categories: Behavioural data, cookie identifiers
Purpose: Legal compliance
Legal Basis: Legal obligation (Art. 6(1)(c) GDPR)
Data Categories: All relevant data
​
Legitimate Interests Assessment
​
Our legitimate interests include:
-
Ensuring website security and functionality
-
Improving user experience through analytics
-
Responding to visitor inquiries
-
Maintaining business operations
We have assessed that these interests do not override your fundamental rights and freedoms.
​
5. Consent Management and Cookie Policy
We only use non-essential cookies and tracking technologies after you provide explicit consent. Your consent is:
-
Freely given - you have a genuine choice
-
Specific - separate consent for different purposes
-
Informed - you understand what you're consenting to
-
Unambiguous - clear positive action required
Cookie Categories
Essential Cookies (No Consent Required)
-
Purpose: Enable basic website functionality and security
-
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR)
-
Examples: Session management, security features, load balancing
-
Status: Always active - cannot be disabled
Performance and Analytics Cookies (Consent Required)
-
Purpose: Analyse website usage and improve performance
-
Legal basis: Consent (Art. 6(1)(a) GDPR)
-
Status: Only activated after explicit consent
-
Control: Can be withdrawn at any time
Advertising Cookies (Consent Required)
-
Purpose: Deliver targeted advertisements and measure effectiveness
-
Legal basis: Consent (Art. 6(1)(a) GDPR)
-
Status: Only activated after explicit consent
-
Control: Can be withdrawn at any time
​
6. Google DoubleClick
Important: Google DoubleClick cookies are only activated after you provide explicit consent through our cookie banner. Without your consent, no DoubleClick tracking occurs.
How DoubleClick Works
Once you consent, DoubleClick:
-
Uses cookies to serve relevant ads to users
-
Improves campaign performance reports
-
Prevents duplicate ad displays to the same user
-
Tracks conversions related to ad requests
-
Enables targeted advertising based on your interests
Data Processing (Only With Consent)
When you consent and visit our website:
-
Your browser establishes connection to Google servers
-
Google receives information that you have visited our website
-
If you're registered with Google services, your visit may be associated with your account
-
Even without Google registration, your IP address may be stored
DoubleClick Floodlight Cookies (Consent Required)
These cookies help us understand (only after consent):
-
Whether you perform actions on our website after viewing our ads
-
Content you interact with on our website
-
Effectiveness of our advertising campaigns
This enables targeted advertising to be sent to you later.
Withdrawing Consent
You can withdraw your consent at any time through:
a) Our Cookie Settings:
-
Use our cookie consent banner
-
Immediate effect upon withdrawal
b) Browser Settings:
-
Adjust your browser to suppress third-party cookies
-
This prevents receiving third-party advertisements
c) Google Ad Settings:
-
Manage your advertising preferences directly
d) Industry Opt-Out Tools:
-
About Ads: http://www.aboutads.info/choices
-
Network Advertising Initiative: http://www.networkadvertising.org
e) Browser Plugin:
-
Permanent deactivation for Firefox, Internet Explorer, or Chrome
Important: After withdrawing consent, DoubleClick tracking stops immediately, but you can still use all essential website features.
Additional Information
-
Google DoubleClick: https://www.google.com/doubleclick
-
Google Privacy Policy: https://policies.google.com/privacy
-
Network Advertising Initiative: http://www.networkadvertising.org
Data Transfers
-
Google participates in the EU-US Data Privacy Framework
-
Data transfers to the United States only occur with your consent
-
Adequate protection ensured through framework certification
Legal Basis: Consent (Art. 6(1)(a) GDPR) - Required before any processing
​
7. Data Sharing and Recipients
We may share your personal data with:
Service Providers (With Appropriate Safeguards)
-
Web hosting providers (for website operation)
-
Analytics services (for website improvement - consent required)
-
Email service providers (for communications)
Legal Requirements
-
Government authorities (when legally required)
-
Law enforcement (in response to valid legal requests)
Third-Party Services (Consent Required)
-
Google (for advertising and analytics services - only with consent)
All service providers are bound by data processing agreements and must implement appropriate security measures.
​
8. International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA):
United States
-
Google services are covered by the EU-US Data Privacy Framework
-
Transfers only occur with your explicit consent
-
Adequate level of protection ensured through framework participation
Other Countries
-
Standard Contractual Clauses used where necessary
-
Appropriate safeguards implemented for all transfers
-
Consent required for non-essential data transfers
​
9. Data Retention
We retain personal data only as long as necessary:
Data Type: Essential website data
Retention Period: Session duration
Justification: Website functionality
Data Type: Consent records
Retention Period: 3 years after withdrawal
Justification: Legal compliance
Data Type: Website analytics
Retention Period: 26 months (with consent)
Justification: Business analysis and improvement
Data Type: Contact inquiries
Retention Period: 3 years
Justification: Customer service and follow-up
Data Type: Marketing data
Retention Period: Until consent withdrawn
Justification: Marketing communications
Data Type: Advertising data
Retention Period: Until consent withdrawn
Justification: Targeted advertising
Data Type: Security logs
Retention Period: 12 months
Justification: Security monitoring
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access (Article 15)
-
Request confirmation of data processing
-
Obtain a copy of your personal data
-
Receive information about processing activities
Right to Rectification (Article 16)
-
Correct inaccurate personal data
-
Complete incomplete data
Right to Erasure (Article 17)
-
Request deletion of your personal data
-
"Right to be forgotten" in certain circumstances
Right to Restriction (Article 18)
-
Limit processing of your data in specific situations
Right to Data Portability (Article 20)
-
Receive your data in machine-readable format
-
Transfer data to another service provider
Right to Object (Article 21)
-
Object to processing based on legitimate interests
-
Object to direct marketing at any time (immediate effect)
Right to Withdraw Consent
-
Withdraw consent at any time for consent-based processing
-
Immediate effect - processing stops immediately
-
Does not affect lawfulness of prior processing
-
Easy withdrawal through our preference centre
How to Exercise Your Rights
-
Cookie preferences: Use our consent management platform
-
Response time: Within 30 days
-
Free of charge (except for excessive requests)
​
11. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority:
-
In your country of residence
-
In your place of work
-
Where the alleged infringement occurred
Find your local authority: https://edpb.europa.eu/about-edpb/board/members_en
​
12. Links to Other Websites
Our website may contain links to other websites. Once you leave our website (recognisable by the changed URL), we are no longer responsible for data protection on those sites.
Each external website has its own privacy policy and cookie practices. We recommend reviewing their privacy practices before providing personal information or accepting their cookies.