Privacy Policy at SOFORT GmbH

With this general privacy statement, SOFORT GmbH, Theresienhöhe 12, 80339 München, would like to inform you which personal data SOFORT GmbH collects, processes and uses, when you browse our website at www.sofort.com, (e.g. to obtain information on our products and services).

If you use one of our (payment) services (e.g. SOFORT or SOFORT Ident), supplementary privacy statements will apply. Specific reference to their applicability will be made to you prior to the use of the respective service.

1. Use of the software Google Analytics

We use the software "Google Analytics", a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google“). Google Analytics uses a tracking cookie to recognise a user that already visited our website in the past. The cookie is a small text file placed on your computer which allows analysing the history of visits on our website (so-called user profiles). The tracking cookie has a lifetime of 2 years (default setting). The information generated by the cookie about your use of our website (including your IP address) will be transmitted to and stored by Google on a server in the United States. We would like to point out that on this website, Google Analytics has been extended with the code "gat._anonymizeIp ();" to guarantee anonymous collection of IP addresses (IP masking).

Your IP address (the number allocated to your computer by your Internet provider) will therefore be shortened first by Google within the member states of the European Union or in countries which are contracting parties to the Agreement on the European Economic Area. The user profiles generated by Google Analytics are thus anonymised to prevent IP addresses from being traced to a specific user. Only in exceptional cases, the full IP address will be transmitted to a Google server in the United States and shortened there.

The user profiles for example contain information on the amount of time you spend on the website, geographical origin, source of visitor traffic, exit pages, and processes of use. Google will use this information to evaluate your use of our website, to compile reports for us about the website activities, and to provide other services associated with website use and internet use.

The IP address transmitted by your browser will not be associated with any other data held by Google. This data will only be passed on to third parties on the basis of statutory regulations or within order data processing. In no case, Google will link your data with other data stored by Google.

Through the use of our website, you consent to the processing of the data raised about you through Google, in the manner as described before, and to the purpose as given before. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. In addition, you can avoid the collection of data created by the Cookie, and data related to the use of the website (including your IP-address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en. As an alternative to the browser add-on or in browsers on mobile devices, you can refuse the use of Google Analytics by clicking the following link (insert link). An opt-out cookie will be set which prevents the future collection of your data when visiting this website. Google Analytics deactivate.

Detailed information on Google Analytics and data privacy can be found at http://tools.google.com/dlpage/gaoptout?hl=en or http://www.google.com/intl/en/policies/privacy/.

2. Use of cookies

In addition to cookies Google Analytics (see point 1), we use a session cookie and (for merchants who access us through a sales campaign) a partner cookie:

The session cookie contains a random code and is needed to allocate successive page views to individual users who simultaneously visit our site. The session cookie is deleted as soon as you close the browser window.

In the partner cookie, we save a code which identifies our sales partners. With the help of the partner cookie, we can ascertain which sales partner brought a merchant to us who later registers for one of our services. The partner cookie has a service life of 90 days.

All cookies are only visible to our server, not to third party websites which you visit later.

You can deactivate cookies being saved in your browser, limit them to specific websites or set your browser in such a way that it informs you as soon as a cookie is to be saved. You can also delete cookies subsequently from your PC.

3. Google Tag Manager

This website uses Google Tag Manager, a cookie-less domain which does not collect personal data.

This tool allows "website tags" (i.e. keywords which are integrated in HTML elements) to be implemented and managed using an user interface. By means of auto-event tracking, we are able to see which button, link or personalised picture you actively clicked to determine which contents of our website are of particular interest to you.

Additionally, the tool causes other tags to be activated which may, for their part, collect data under certain circumstances. Google Tag Manager does not access this information. If recording has been deactivated on domain or cookie level, this setting will remain in place for all tracking tags implemented with Google Tag Manager.

4. Use of share buttons of social networks

On our website we use so-called "share buttons" of the social networks Facebook, Google+, Twitter, YouTube, LinkedIn and Xing. Using these share buttons you can share contents of our Internet presence with others. The share buttons on our site can be recognized by the respective logos of the social networks.

To ensure the best possible protection of your data when visiting our website, the share buttons are integrated into our page in such a way that when a page containing such buttons is called, no connection to the servers of the social networks is made yet. Only when you activate the share buttons by clicking on the respective logos of the social networks and thereby give your consent to the transmission of data, does your browser establish a direct connection to the respective social network.

4.1. Facebook

Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook").

When you click the Facebook share button on our page, your browser establishes a direct connection to the servers of Facebook. The content of the share button is transferred from Facebook directly to your browser, which then embeds it into the website. Thus Facebook receives the information that you have accessed the corresponding page of our Internet presence. If you are logged into Facebook, Facebook can link the visit on our page to your Facebook account.

Please see Facebook's privacy policies for the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your rights and setting options to protect your privacy: https://www.facebook.com/about/privacy/.

4.2. Google+ and YouTube

Google+ and YouTube are operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

When you click the Google+ and/or YouTube share button on our page, your browser establishes a direct connection to the servers of Google. The content of the share button is transferred from Google directly to your browser, which then embeds it into the website. Thus Google receives the information that you have accessed the corresponding page of our Internet presence. If you are logged into Google, Google can link the visit on our page to your Facebook account.

Please see Google's privacy policies for the purpose and scope of data collection and the further processing and use of data by Google, as well as your rights and setting options to protect your privacy: http://www.google.com/intl/de/policies/privacy/.

4.3. Twitter

Twitter is operated by Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA ("Twitter").

When you click the Twitter share button on our page, your browser establishes a direct connection to the servers of Twitter. Thus Twitter receives the information that you have accessed the corresponding page of our Internet presence. If you are logged into Twitter, Twitter can link the visit on our page to your Twitter account.

Please see Twitter's privacy policies for the purpose and scope of data collection and the further processing and use of data by Twitter, as well as your rights and setting options to protect your privacy: https://twitter.com/privacy.

4.4. LinkedIn

LinkedIn is operated by LinkedIn Corporation 2029 Stierlin Court, Mountain View, CA 94043, USA ("LinkedIn").

When you click the LinkedIn share button on our page, your browser establishes a direct connection to the servers of LinkedIn. The content of the share button is transferred from LinkedIn directly to your browser, which then embeds it into the website. Thus LinkedIn receives the information that you have accessed the corresponding page of our Internet presence. If you are logged into LinkedIn, LinkedIn can link the visit on our page to your LinkedIn account.

Please see LinkedIn's privacy policies for the purpose and scope of data collection and the further processing and use of data by LinkedIn, as well as your rights and setting options to protect your privacy: https://www.linkedin.com/legal/privacy-policy.

4.5. Xing

Xing is operated by XING AG, Gänsemarkt 43, 20354 Hamburg ("Xing").

When you click the Xing share button on our page, your browser establishes a short-term connection to the servers of Xing, with which the "Xing share button" functions (in particular the calculation/display of the counter value) are performed. Xing does not store any personal data from you about the call of this website. In particular, no IP addresses are stored by Xing. There is also no analysis of user behaviour about the use of cookies in connection with the "Xing share button". The current data protection information on the "Xing share button" and additional information are available on our website: https://www.xing.com/privacy.

4.6.

If you do not want the social networks to assign the data collected via our website presence directly to your profile in the respective network, you must log out of the respective provider before activating the share button. If you do not want that social networks can collect information on you via active buttons, you can
•    select the function block third-party cookies in your browser settings. In this case, when there is embedded content, the browser does not send cookies to the respective server of other providers. However, the use of our website and services may then only be possible to a limited extent;
•    completely prevent the loading of buttons with add-ons for your browser.

5. Log files

When you visit individual pages, as a standard practice web servers save the name of the file which was queried in a log file, as well as the date and the time it was queried, the data volume transferred, any error messages and possibly the operating system and the browser software of your computer, as well as the website from which you visit us. We save the log file data for the purposes listed under point 1 and to safeguard the system security and protect against abuse (e.g. recognition of and defense against hacker attacks).

6. Contact form

We save and use the data you enter in the contact form such as your name, email, reference and message to communicate with you individually and to process your request. Your data is transferred from your browser to our server using an encrypted SSL connection.

7. Hosting

We run (host) our websites on our own servers. These are located in a data center in Germany certified to ISO 27001.

8. Contact

Should you have any questions about data protection at SOFORT GmbH or if you would like to know which of your personal data we have stored, please contact dataprotection@sofort.com or write to SOFORT GmbH, Dataprotection, Theresienhöhe 12, 80339 München, Germany.

Version 1.8, Date of application: 12.07.2017