General information about the processing of your data

We are legally obligated to inform you about the processing of your personal data (hereinafter "data") when using our website. We take the protection of your personal data very seriously. This privacy notice provides you with details about the processing of your data as well as your related legal rights. For terms such as "personal data" or "processing," the legal definitions from Article 4 of the General Data Protection Regulation (GDPR) apply. We reserve the right to adjust the privacy policy with effect for the future, especially in the case of the website's further development, the use of new technologies, or changes in legal foundations or relevant jurisprudence. We recommend that you read the privacy policy from time to time and keep a printout or copy for your records.

 

Scope

This privacy policy applies to all pages of www.upsellguru.com. It does not extend to any linked websites or online presences of other providers. Controller Responsible for the processing of personal data within the scope of this privacy policy is:

UpsellGuru GmbH
Unterm Hagen 35, 59939 Olsberg
E-Mail-Adresse: [email protected]

 

Questions about Data Protection

If you have any questions regarding data protection concerning our company or our website, you can contact the contact details mentioned in the "Controller" section.

 

Security

We have implemented comprehensive technical and organizational measures to protect your personal data from unauthorized access, misuse, loss, and other external disruptions. We regularly review our security measures and adjust them to the state of the art.

Your Rights You have the following rights concerning your personal data that concern you, which you can assert against us:

  • Right to Information: You can request information according to Article 15 of the General Data Protection Regulation (GDPR) about your personal data that we process.
  • Right to Rectification: If the information concerning you is not (or no longer) accurate, you can request correction according to Article 16 GDPR. If your data is incomplete, you can request completion.
  • Right to Erasure: According to Article 17 GDPR, you can request the erasure of your personal data.
  • Right to Restriction of Processing: According to Article 18 GDPR, you have the right to request restriction of the processing of your personal data.
  • Right to Object to Processing: You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data carried out under Article 6(1)(e) or (f) GDPR, according to Article 21(1) GDPR. In this case, we will not further process your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims (Article 21(1) GDPR). Additionally, according to Article 21(2) GDPR, you have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to such direct marketing. We inform you about the right to object in this privacy policy in connection with the respective processing.
  • Right to Withdraw Your Consent: If you have given consent for processing, you have the right to withdraw it according to Article 7(3) GDPR.
  • Right to Data Portability: You have the right to receive the personal data concerning you that you provided to us in a structured, commonly used, and machine-readable format ("data portability"), and you have the right to transmit those data to another controller if the conditions of Article 20(1)(a, b) GDPR are met (Article 20 GDPR).

You can exercise your rights by contacting the contact details mentioned in the "Controller" section.

If you believe that the processing of your personal data violates data protection law, you also have the right, according to Article 77 GDPR, to lodge a complaint with a supervisory authority of your choice. This includes the data protection supervisory authority responsible for the controller: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 200444, 40102 Düsseldorf, 0211/38424-0, [email protected].

 

Use of Our Website

You can use our website for purely informational purposes without disclosing your identity. When accessing the individual pages of the website for informational purposes, only access data is transmitted to our web space provider so that the website can be displayed to you. The following data is processed in this context:

  • Browser type/browser version,
  • Operating system used,
  • Language and version of the browser software,
  • Date and time of access, • Hostname of the accessing device, • IP address,
  • Content of the request (specific webpage),
  • Access status/HTTP status code,
  • Websites accessed through the website,
  • Referrer URL (previously visited website),
  • Message indicating whether the call was successful, and
  • Transferred data volume.

The temporary processing of this data is necessary to enable the operation of a website visit and the delivery of the website to your device from a technical perspective. Access data is not used to identify individual users and is not merged with other data sources. The legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interests lie in ensuring the functionality, integrity, and security of the website. Access data is deleted as soon as it is no longer required for the purpose of its processing. In the case of data collected to provide the website, this occurs when you end your visit to the website.

You have the right to object to the processing. Your right to object exists for reasons that arise from your particular situation. You can submit your objection to us using the contact details provided in the "Controller" section.

Tracking Über die zuvor genannten Zugriffsdaten hinaus werden bei der Nutzung der Website sog. Cookies, Pixel oder andere Tracking-Technologien verwendet. Bei Cookies handelt es sich um kleine Textdateien mit einer Zahlenfolge, die lokal im Zwischenspeicher des verwendeten Browsers gespeichert werden. Pixel sind Ein-Pixel-Bilder, die intransparent oder in der Hintergrundfarbe der Website angelegt werden und daher für den Nutzer nicht sichtbar sind. Auch der Pixel erfasst Informationen über Ihr Nutzerverhalten auf der Website. Fingerprinting-Technologien erzeugen aufgrund der Browser-Einstellungen einen eindeutigen Fingerabdruck und identifizieren somit einen einzelnen Browser. Mittels eines Skripts, welches jeder Internet-Browser automatisch ausführt, können mitunter Informationen wie etwa die Auflösung des Bildschirms, verwendete Schriftarten, Betriebssystem, Hardwareinformationen und integrierte Browser-Plugins erhoben werden, die in ihrer spezifischen Kombination letztlich eine Rückführung auf einen bestimmten Nutzer ermöglichen können. Die Tracking-Technologien dienen dazu, unsere Website nutzerfreundlich zu gestalten. Der Einsatz von Tracking-Technologien kann technisch notwendig sein oder zu anderen Zwecken erfolgen (z.B. Analyse/ Auswertung der Website-Nutzung). Technisch notwendige Elemente Einige Elemente unserer Internetseite erfordern es, dass der aufrufende Browser auch nach einem Seitenwechsel identifiziert werden kann. In den technisch notwendigen Elementen, wie insbesondere Cookies oder ähnlichen Methoden des Endgerätezugriffs, werden zum Zwecke der Durchführung bzw. Erleichterung der elektronischen Kommunikation und Bereitstellung eines vom Nutzer angefragten Dienstes der Informationsgesellschaft folgende Daten verarbeitet:

  • Spracheinstellungen,
  • Einstellungen zu Schriftarten oder
  • Log-In-Informationen.

Die durch technisch notwendige Elemente erhobenen Nutzerdaten werden nicht zur Erstellung von Nutzerprofilen verarbeitet. Die Rechtsgrundlage für diese Verarbeitung ist Art. 6 Abs. 1 S. 1 lit. f) DSGVO. Unsere berechtigten Interessen an der Verarbeitung bestehen darin, die genannten besonderen Funktionalitäten bereitzustellen und dadurch die Benutzung der Website attraktiver und effektiver zu gestalten. Die Cookies werden gelöscht, sobald Sie sich ausloggen oder, je nachdem, welchen Browser Sie verwenden und welche Browsereinstellungen Sie vorgenommen haben, wenn Sie den Browser schließen. Sie können Widerspruch gegen die Verarbeitung einlegen. Ihr Widerspruchsrecht besteht bei Gründen, die sich aus Ihrer besonderen Situation ergeben. Sie können uns Ihren Widerspruch über die im Abschnitt „Verantwortlicher“ genannten Kontaktdaten zukommen lassen.

 

Tracking

In addition to the aforementioned access data, so-called cookies, pixels, or other tracking technologies are used when using the website. Cookies are small text files with a sequence of numbers that are stored locally in the cache of the used browser. Pixels are one-pixel images created intransparently or in the background color of the website and are therefore not visible to the user. The pixel also captures information about your user behavior on the website. Fingerprinting technologies generate a unique fingerprint based on browser settings and thus identify an individual browser. Through a script that every internet browser automatically executes, information such as screen resolution, used fonts, operating system, hardware information, and integrated browser plugins can be collected, which in their specific combination may ultimately allow tracing back to a specific user. Tracking technologies are used to make our website user-friendly. The use of tracking technologies may be technically necessary or for other purposes (e.g., analysis/evaluation of website usage).

 

Technically Necessary Elements

Some elements of our website require that the calling browser can still be identified after a page change. In the technically necessary elements, such as cookies or similar methods of device access, the following data is processed for the purpose of carrying out or facilitating electronic communication and providing a service requested by the user of the information society:

  • Language settings,
  • Font settings, or
  • Log-in information.

The user data collected through technically necessary elements is not processed to create user profiles. The legal basis for this processing is Art. 6(1)(f) GDPR. Our legitimate interests in processing are to provide the mentioned special functionalities and thereby make the use of the website more attractive and effective. The cookies are deleted when you log out or, depending on the browser you use and the browser settings you have made, when you close the browser.

You have the right to object to the processing. Your right to object exists for reasons that arise from your particular situation. You can submit your objection to us using the contact details provided in the "Controller" section.

 

Contacting our Company and Requesting Additional Information

When contacting our company and requesting further documents, such as via email or through the contact form on the website, the personal data provided by you will be processed by us to respond to your inquiry. For inquiries through the contact form on the website, the provision of a name, a valid email address, the company name, and a message to us is mandatory for processing. Optionally, you can provide the country, the name of the PMS (Property Management System), and the name of the Channel Manager. At the time of sending the message to us, your IP address, as well as the date and time of the request, are also processed. The legal basis for processing is Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR if the contact aims at concluding a contract. If the inquiry aims at entering into a contract, the provision of your data is necessary and mandatory for contract conclusion. Failure to provide the data makes it impossible to conclude a contract or carry out the communication or processing of the request. The processing of personal data from the input mask serves solely for handling the contact. In the case of contact via email, the necessary legitimate interest in processing the data is also present. The other data processed during the sending process is used to prevent misuse of the contact form and to ensure the security of our information technology systems. In this context, the data is not passed on to third parties. We delete the data collected in this context when it is no longer needed, usually two years after the end of communication, or restrict processing if statutory retention obligations exist.

You can object to the processing. Your right to object exists for reasons that arise from your particular situation. You can submit your objection to us using the contact details provided in the "Controller" section.

 

Booking a Demo

To schedule an appointment with the Sales Team, we use the online calendar of Calendly, LLC (3423 Piedmont Road NE, Atlanta, GA 30305-1754, United States, hereinafter referred to as "Calendly"), which is integrated via a widget. Access data is transmitted to "Calendly" when the website is accessed via the widget, even if you do not schedule an appointment. When you press the "Book a demo" button, you will be automatically connected to our appointment account at "Calendly." After choosing your appointment, personal data such as name, email address, company name, and optionally, the name of the PMS or Channel Manager, and your message to us are processed. At the time of sending the appointment request to us, your IP address, as well as the date and time of the request, are also processed. The legal basis for processing is Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR if booking the demo aims at concluding a contract. If the request aims at entering into a contract, the provision of your data is necessary and mandatory for contract conclusion. Failure to provide the data makes it impossible to conclude a contract or carry out the communication or conduct a demo with the Sales Team. The processing of personal data from the input mask serves solely for handling the agreement of a demo with the Sales Team. The other data processed during the sending process is used to prevent misuse of the contact form and to ensure the security of our information technology systems. "Calendly" processes the data in the USA. There is no adequacy decision of the EU Commission for data transfer to the USA. Standard contractual clauses have been concluded with "Calendly" to ensure compliance with an adequate level of data protection. Upon request, we will provide you with a copy of the standard contractual clauses. We delete the data collected in this context when it is no longer needed, usually two years after the end of communication, or restrict processing if statutory retention obligations exist. Further information about the processing of your data by "Calendly" can be found at https://calendly.com/privacy

You can object to the processing. Your right to object exists for reasons that arise from your particular situation. You can submit your objection to us using the contact details provided in the "Controller" section.

 

Processing for Contractual Purposes

We process your personal data to the extent necessary for the initiation, establishment, performance, and/or termination of a legal transaction with our company. The legal basis for this processing is Art. 6(1)(b) GDPR. Providing your data is necessary for contract conclusion, and you are contractually obligated to make your data available. Failure to provide your data makes it impossible to conclude and/or perform the contract. After achieving the purpose (e.g., contract processing), personal data is blocked or deleted for further processing unless we are authorized to further process it due to your consent (e.g., consent to process the email address for sending electronic promotional emails), a contractual agreement, legal authorization (e.g., authorization for direct advertising), or legitimate interests (e.g., retention for the enforcement of claims).

Your personal data may be disclosed to third parties if:

  • It is necessary for the initiation, performance, or termination of legal transactions with our company (e.g., disclosing data to a payment service provider/shipping company to process a contract with you) (Art. 6(1)(b) GDPR), or
  • A subcontractor or agent whom we use exclusively within the scope of providing the offers or services you requested needs this data (such helpers are only authorized to process the data to the extent necessary for providing the offer or service unless expressly stated otherwise), or
  • An enforceable administrative order (Art. 6(1)(c) GDPR) is in place, or
  • An enforceable court order (Art. 6(1)(c) GDPR) is in place, or
  • We are obligated by law (Art. 6(1)(c) GDPR), or
  • Processing is necessary to protect the vital interests of the data subject or another natural person (Art. 6(1)(d) GDPR), or
  • It is necessary for the performance of a task carried out in the public interest or in the exercise of official authority (Art. 6(1)(e) GDPR), or
  • We can invoke our predominant legitimate interests or those of a third party for disclosure (Art. 6(1)(f) GDPR).

Beyond this, your personal data will not be disclosed to other individuals, companies, or entities unless you have effectively consented to such disclosure. The legal basis for processing in this case is Art. 6(1)(a) GDPR. In this privacy information, we inform you about the respective recipients in relation to the specific processing operation.

 

Login

To use our services, a customer account is created. Personal data is processed for the login. Access data for the customer account is automatically sent to the customer with a randomly generated password. The user can then change the password. Furthermore, during login, the user's IP address, date, and time may be processed.

Otherwise, the data will be deleted as soon as it is no longer necessary for the purpose of processing. In the login area, the following functions are available:

  • Reviewing upsells,
  • Acceptance and rejection of upsells.

The legal basis for processing is Art. 6(1)(b) GDPR. Providing your data is necessary for contract conclusion or performance and is mandatory. Failure to provide your data means you cannot use the login area, i.e., contract conclusion and/or performance is not possible.

Your data will be deleted as soon as it is no longer necessary for the processing purpose. This occurs after deleting the customer account, unless we are obliged to retain the data due to legal regulations. In this case, we restrict processing. Due to mandatory commercial and tax regulations, we are obligated to retain address, payment, and order data for up to ten years.

 

Hosting

We use external hosting services provided by bluehost inc. (5335 Gate Parkway Suite 300 Jacksonville, FL 32256 USA), which serve to provide the following services: infrastructure and platform services, computing capacity, storage resources, and database services, as well as security and technical maintenance services. For these purposes, all data – including the access data mentioned under the section "Use of our Website" – that is necessary for the operation and use of our website is processed. The legal basis for processing is Art. 6(1)(f) GDPR. With the use of external hosting services, we aim to efficiently and securely provide our website. Bluehost processes the data in the USA. There is no adequacy decision by the European Commission for data transfer to the USA. Standard contractual clauses have been concluded with Bluehost to ensure compliance with an adequate level of data protection. Upon request, we can provide you with a copy of the standard contractual clauses.

You have the right to object to the processing. Your right to object exists for reasons arising from your particular situation. You can communicate your objection to us using the contact details provided in the "Controller" section.

 

Web Analytics Software Matomo

We use the web analytics software Matomo, an open-source software for statistical analysis of visitor access, to improve and make our web app more user-friendly. The provider is "Innocraft" (Innocraft Ltd., 150 Willis Street, 6011 Wellington, New Zealand, [email protected]). "Matomo" is open-source software that enables statistical evaluations on our web app, especially regarding visitor access, page views, downloads, previously visited web apps, and the success measurement of entries in search engines. The analyzed information and statistics are processed exclusively on our own web servers or databases. The "Matomo" tool captures, analyzes, and categorizes information generated by the user's device through technologies such as fingerprinting about the use of our web app and interactions with our web app, as well as access data, including IP address, browser information, the previously visited web app, and the date and time of the server request, for the purpose of statistical analysis and reach measurement of advertisements in search engines. The legal basis for processing is Art. 6(1)(f) GDPR. We use "Matomo" with an extension that processes IP addresses in a shortened form to make direct identifiability more difficult. Our legitimate interests lie in the statistical analysis of website usage and the optimization and improvement of our web offering. The storage duration is 12 months.

You have the right to object to the processing. Your right to object exists for reasons arising from your particular situation. You can communicate your objection to us using the contact details provided in the "Controller" section.

Â