Privacy Policy & Data Security

This privacy policy explains the nature, scope and purpose of the collection and use of your personal data.

Privacy Policy

Personal data (usually referred to just as “data” below) will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.

Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the “GDPR”), “processing” refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.

The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under our own control or in conjunction with others. We also inform you below about the third-party components we use to optimize our website and improve the user experience which may result in said third parties also processing data they collect and control.

I. Information about us as controllers of your data

The person responsible in accordance with Art. 4 para. 7 DSGVO and other national data protection laws of the member states of the European Union as well as other data protection regulations:

Crypto Tree GmbH

Sexauerstraße 5
81827 München
E-Mail: info@cryptotree.info

Managing Directors:
Matthias Heininger, Elena Kaut

Contact Person:
Matthias Heininger
E-Mail: matthias.heininger@cryptotree.info

II. The rights of users and data subjects

With regard to the data processing to be described in more detail below, users and data subjects have the right

  • to confirmation of whether data concerning them is being processed, information about the data being processed, further information about the nature of the data processing, and copies of the data (cf. also Art. 15 GDPR);
  • to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
  • to the immediate deletion of data concerning them (cf. also Art. 17 DSGVO), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict said processing per Art. 18 GDPR;
  • to receive copies of the data concerning them and/or provided by them and to have the same transmitted to other providers/controllers (cf. also Art. 20 GDPR);
  • to file complaints with the supervisory authority if they believe that data concerning them is being processed by the controller in breach of data protection provisions (see also Art. 77 GDPR).

In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.

Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller’s future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.

III. Information about the data processing

Hosting of the website

The hosting services used by us serve the provision of the following services: Infrastructure and platform services, computing capacity, storage space and database services, security services as well as technical maintenance services which we use for the purpose of operating the website. We and our hosting providers (WPEngine, Irongate House, 22-30 Duke’s Place, London, EC3A7LP, United Kingdom. Tel: +44 (0) 20 3770 9704https://wpengine.com), inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this website on the basis of our legitimate interests in the efficient and secure provision of our website pursuant to Art. 6 Para. 1 lit. f DSGVO in connection with Art. 28 DSGVO. Our data is stored in Europe. WPEngine is Privacy Shield certified and only processes data on behalf of Crypto Tree. Further information on your processed data can be found at https://wpengine.com/de/legal/privacy/

We have concluded a so-called “Data Processing Agreement” with WP Engine, in which we oblige WP Engine to protect the data of our customers and not to pass it on to third parties.

Provision of the website and creation of log files

Each time you access our website, our system and WP Engine automatically collect data and information from the computer system of the accessing computer.

The following data is collected:

  • Information about the browser type and the version used
  • The user’s operating system
  • The Internet service provider of the user
  • The IP address of the user
  • Date and time of access
  • Websites from which the user’s system accesses our website
  • Websites accessed by the user’s system through our website
  • Transferred amount of data
  • Notification of successful retrieval

We use this log data without allocation to your person or other profiling for statistical evaluations for the purpose of operating, security and optimisation of our website, but also for anonymous recording of the number of visitors to our website (traffic) and for the scope and type of use of our website and services, as well as for billing purposes to measure the number of clicks received from cooperation partners. This information enables us to provide personalized and location-based content and analyze traffic, troubleshoot and correct errors, and improve our services. This is also our legitimate interest pursuant to Art. 6 Para. 1 lit. f DSGVO. We reserve the right to subsequently check the log data if there is a justified suspicion of illegal use on the basis of concrete indications. We store IP addresses in the log files for a limited period of time if this is necessary for security purposes or for the provision of services or the billing of a service, e.g. if you use one of our offers. After the order process has been aborted or after payment has been received, we delete the IP address if it is no longer required for security purposes.

SSL or TLS encryption

Our Crypto Tree website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests you send to us as a site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Cookies

a) Session cookies

We use cookies on our website. Cookies are small text files or other storage technologies stored on your computer by your browser. These cookies process certain specific information about you, such as your browser, location data, or IP address.  

This processing makes our website more user-friendly, efficient, and secure, allowing us, for example, to display our website in different languages or to offer a shopping cart function.

The legal basis for such processing is Art. 6 Para. 1 lit. b) GDPR, insofar as these cookies are used to collect data to initiate or process contractual relationships.

If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis is then Art. 6 Para. 1 lit. f) GDPR.

When you close your browser, these session cookies are deleted.

b) Disabling cookies

You can refuse the use of cookies by changing the settings on your browser. Likewise, you can use the browser to delete cookies that have already been stored. However, the steps and measures required vary, depending on the browser you use. If you have any questions, please use the help function or consult the documentation for your browser or contact its maker for support. Browser settings cannot prevent so-called flash cookies from being set. Instead, you will need to change the setting of your Flash player. The steps and measures required for this also depend on the Flash player you are using. If you have any questions, please use the help function or consult the documentation for your Flash player or contact its maker for support.

If you prevent or restrict the installation of cookies, not all of the functions on our site may be fully usable.

Newsletter

If you register for our free newsletter, the data requested from you for this purpose, i.e. your email address and, optionally, your name and address, will be sent to us. We also store the IP address of your computer and the date and time of your registration. During the registration process, we will obtain your consent to receive this newsletter and the type of content it will offer, with reference made to this privacy policy. The data collected will be used exclusively to send the newsletter and will not be passed on to third parties.

The legal basis for this is Art. 6 Para. 1 lit. a) GDPR.

You may revoke your prior consent to receive this newsletter under Art. 7 Para. 3 GDPR with future effect. All you have to do is inform us that you are revoking your consent or click on the unsubscribe link contained in each newsletter.

Contact

If you contact us via email or the contact form, the data you provide will be used for the purpose of processing your request. We must have this data in order to process and answer your inquiry; otherwise we will not be able to answer it in full or at all.

The legal basis for this data processing is Art. 6 Para. 1 lit. b) GDPR.

Your data will be deleted once we have fully answered your inquiry and there is no further legal obligation to store your data, such as if an order or contract resulted therefrom.

Google Analytics

Our website uses Google Analytics, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies. These enable an analysis of the use of our website by Google. The information collected by the cookie about the use of our pages (including your IP address) is usually transferred to a Google server in the USA and stored there. This is also our legitimate interest pursuant to Art. 6 para. 1 lit. f DSGVO. We would like to point out that on this website Google Analytics was extended by the code “get_anonymizeIp();” in order to guarantee an anonymous recording of IP addresses (so-called IP masking). If anonymisation is active, Google shortens IP addresses within member states of the European Union or in other signatory states to the Agreement on the European Economic Area, which means that no conclusions can be drawn about your identity. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. Google complies with the privacy provisions of the Privacy Shield Agreement and is registered with the Department of Commerce’s Privacy Shield program and uses the information it collects to evaluate and report on the use of our web sites and to provide other related services to us. Google guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

For more information, please refer to the following link: 

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the transmission to Google of the data generated by the cookie and relating to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing the browser plug-in available under the following link:

http://tools.google.com/dlpage/gaoptout?hl=en

As an alternative to the browser plug-in or within browsers on mobile devices, you can click on the following link to set an opt-out cookie that will prevent Google Analytics from collecting information from this site in the future (this opt-out cookie works only in this browser and only for this domain). If you delete the cookies in your browser, you must click this link again: Disable Universal Analytics

You can find out more at https://policies.google.com/privacy?hl=de and https://privacy.google.com/businesses/processorterms/

Google reCAPTCHA

Unsere Website verwendet “Google reCAPTCHA”, Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Google guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

This service allows Google to determine from which website your request has been sent and from which IP address the reCAPTCHA input box has been used. In addition to your IP address, Google may collect other information necessary to provide and guarantee this service.   

The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the security of our website and in the prevention of unwanted, automated access in the form of spam or similar.

Google offers detailed information at

https://policies.google.com/privacy

concerning the general handling of your user data.

Google Fonts

Our website uses Google Fonts to display external fonts. This is a service provided by Google Inc., (hereinafter: Google).

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Google guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

To enable the display of certain fonts on our website, a connection to the Google server in the USA is established whenever our website is accessed.

The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the optimization and economic operation of our site.

When you access our site, a connection to Google is established from which Google can identify the site from which your request has been sent and to which IP address the fonts are being transmitted for display.

Google offers detailed information at

https://adssettings.google.com/authenticated

https://policies.google.com/privacy

in particular on options for preventing the use of data.

Facebook plug-in

Our website uses the plug-in of the Facebook social network. Facebook.com is a service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. In the EU, this service is also operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, hereinafter both referred to as “Facebook.”

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active

Facebook guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website.

Further information about the possible plug-ins and their respective functions is available from Facebook at

https://developers.facebook.com/docs/plugins/

If the plug-in is stored on one of the pages you visit on our website, your browser will download an icon for the plug-in from Facebook’s servers in the USA. For technical reasons, it is necessary for Facebook to process your IP address. In addition, the date and time of your visit to our website will also be recorded.

If you are logged in to Facebook while visiting one of our plugged-in websites, the information collected by the plug-in from your specific visit will be recognized by Facebook. The information collected may then be assigned to your personal account at Facebook. If, for example, you use the Facebook Like button, this information will be stored in your Facebook account and published on the Facebook platform. If you want to prevent this, you must either log out of Facebook before visiting our website or use an add-on for your browser to prevent the Facebook plug-in from loading.

Further information about the collection and use of data as well as your rights and protection options in Facebook’s privacy policy found at

https://www.facebook.com/policy.php

Twitter plug-in

Our website uses the plug-in of the Twitter social network. The Twitter service is operated by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA (“Twitter”).

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active

Twitter guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website.

If the plug-in is stored on one of the pages you visit on our website, your browser will download an icon for the plug-in from Twitter’s servers in the USA. For technical reasons, it is necessary for Twitter to process your IP address. In addition, the date and time of your visit to our website will also be recorded.

If you are logged in to Twitter while visiting one of our plugged-in websites, the information collected by the plug-in from your specific visit will be recognized by Twitter. The information collected may then be assigned to your personal account at Twitter. If, for example, you use the Twitter Tweet button, this information will be stored in your Twitter account and may be published on the Twitter platform. To prevent this, you must either log out of Twitter before visiting our site or make the appropriate settings in your Twitter account.

Further information about the collection and use of data as well as your rights and protection options in Twitter’s privacy policy found at

https://twitter.com/privacy

Instagram Social Plug-in

Our website uses social plugins (“Plugins”) from Instagram, which is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). The plugins are marked with an Instagram logo, for example in the form of an “Instagram camera”. An overview of the Instagram plugins and their appearance can be found here: http://blog.instagram.com/post/36222022872/introducing-instagram-badges

When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to Instagram’s servers. The content of the plugin is transmitted by Instagram directly to your browser and integrated into the page. This integration tells Instagram that your browser has accessed the appropriate page on our site, even if you do not have an Instagram profile or are not logged into Instagram. 

This information (including your IP address) is transferred directly from your browser to an Instagram server in the USA and stored there. If you are logged into Instagram, Instagram can directly associate your visit to our website with your Instagram account. If you interact with the plugins, for example by pressing the “Instagram” button, this information is also sent directly to and stored on an Instagram server. The information is also published to your Instagram account and displayed to your contacts. 

The purpose and scope of the data collection and the further processing and use of the data by Instagram as well as your related rights and privacy settings can be found in Instagram’s privacy policy: https://help.instagram.com/155833707900388/ 

If you do not want Instagram to associate the data collected through our website directly with your Instagram account, you must log out of Instagram before visiting our website. You can also prevent the Instagram plugins from loading completely by using add-ons for your browser, e.g. the script blocker “NoScript” (http://noscript.net/).

YouTube

We use YouTube on our website. This is a video portal operated by YouTube LLC, 901 Cherry Ave, 94066 San Bruno, CA, USA, hereinafter referred to as “YouTube”.

YouTube is a subsidiary of Google LLC, Gordon House, Barrow Street, Dublin 4, Irland, hereinafter referred to as “Google”.

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Google and its subsidiary YouTube guarantee that they will follow the EU’s data protection regulations when processing data in the United States.

We use YouTube in its advanced privacy mode to show you videos. The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website. According to YouTube, the advanced privacy mode means that the data specified below will only be transmitted to the YouTube server if you actually start a video.

Without this mode, a connection to the YouTube server in the USA will be established as soon as you access any of our webpages on which a YouTube video is embedded.

This connection is required in order to be able to display the respective video on our website within your browser. YouTube will record and process at a minimum your IP address, the date and time the video was displayed, as well as the website you visited. In addition, a connection to the DoubleClick advertising network of Google is established.

If you are logged in to YouTube when you access our site, YouTube will assign the connection information to your YouTube account. To prevent this, you must either log out of YouTube before visiting our site or make the appropriate settings in your YouTube account.

For the purpose of functionality and analysis of usage behavior, YouTube permanently stores cookies on your device via your browser. If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Further details can be found in the section about cookies above.

Further information about the collection and use of data as well as your rights and protection options in Google’s privacy policy found at

https://policies.google.com/privacy

Active Campaign

Crypto Tree uses Active Campaign services to contact and send updates. Provider is the US provider ActiveCampaign, LLC, 150 N. Michigan Ave Suite 1230, Chicago, IL, US, USA. Active Campaign is a service that can be used, among other things, to organize and analyze the sending of newsletters. If you enter data for newsletter subscription purposes (e.g. e-mail address), it will be stored on Active Campaign’s servers in the USA.

Active Campaign is certified under the EU-US Privacy Shield. The “Privacy Shield” is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA.

Active Campaign enables us to analyse our newsletter campaigns. When you open an e-mail sent with Active Campaign, a file contained in the e-mail (so-called web beacon) connects to Active Campaign’s servers in the USA. This allows you to determine whether a newsletter message has been opened and which links have been clicked. Technical information is also recorded (e.g. time of access, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients.

If you do not want Active Campaign to perform an analysis, you must unsubscribe from the newsletter. To do this, we provide a link in each newsletter message. You can also unsubscribe directly on the website.

Data processing is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted from our servers as well as from Active Campaign’s servers after you cancel the newsletter. This does not affect data stored by us for other purposes (e.g. e-mail addresses for the member area).

For more information, please refer to Active Campaign’s privacy policy at: https://www.activecampaign.com/privacy-policy/.

Link to Privacy Shield certification: 

https://www.privacyshield.gov/participant?id=a2zt0000000GnH6AAK

We have a “Data Processing Agreement” with Active Campaign in which we require Active Campaign to protect our customers’ information and not disclose it to third parties.

Jetpack – WordPress Stats

Our website uses Jetpack with the WordPress Stats extension. This is a web analysis service provided by Automattic Inc, 132 Hawthorne Street, San Francisco, CA 94107, USA, hereinafter referred to as “Automattic”.

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC&status=Active

Automattic guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

The Jetpack: WordPress Stats services is used to analyze how our website is used. The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our site.

Jetpack: WordPress Stats stores cookies on your device via your browser in order to analyze how you use our site.

Data such as your IP address, the pages you visit, the website from which you came (referrer URL), the duration of your visit, and the frequency of your visits will be processed. The data collected will be stored on an Automattic server in the USA. However, your IP address will be made anonymous immediately after processing and before it is stored.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Further details can be found in the section about cookies above.

Amazon Associates (PartnerNet)

Our website participates in the Amazon Associates program, known as PartnerNet in German. This is a service provided by Amazon Europe Core S.à r.l., 5 Rue Plaetis, 2338 Luxembourg, Luxembourg. Advertisements from Amazon.de are placed on our website via the Amazon Associates program. If you click on one of these advertisements, you will be redirected to the corresponding offer on the Amazon website. If you subsequently decide to purchase the advertised product there, we will receive a commission from Amazon.

Amazon uses cookies to allow this service to work. With the help of these cookies, Amazon can verify that you were forwarded from our website to its website.

Amazon offers further information about data protection at this link:

https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.

The legal basis for collecting and processing this information is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in ensuring that our commissions are processed and paid by Amazon.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Further details can be found in the section about cookies above.

Google AdWords with Conversion Tracking

On our website we use the online advertising program “Google AdWords” and in this context conversion tracking. Google Conversion Tracking is an analysis service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). 

Through certification according to the EU-US Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Google guarantees that it will follow the EU’s data protection regulations when processing data in the United States.

We use conversion tracking to provide targeted promotion of our site. The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our site.

If you click on an ad placed by Google, the conversion tracking we use stores a cookie on your device. These so-called conversion cookies expire after 30 days and do not otherwise identify you personally.

If the cookie is still valid and you visit a specific page of our website, both we and Google can evaluate that you clicked on one of our ads placed on Google and that you were then forwarded to our website.

The data collected in this way is in turn used by Google to provide us with an evaluation of visits to our website and what visitors do once there. In addition, we receive information about the number of users who clicked on our advertisement(s) as well as about the pages on our site that are subsequently visited. Neither we nor third parties who also use Google AdWords will be able to identify you from this conversion tracking.

You can also prevent or restrict the installation of cookies by making the appropriate settings in your browser. Likewise, you can use the browser to delete cookies that have already been stored. However, the steps and measures required vary, depending on the browser you use. If you have any questions, please use the help function or consult the documentation for your browser or contact its maker for support.

In addition, Google provides further information with regard to its data protection practices at

https://services.google.com/sitestats/de.html

http://www.google.com/policies/technologies/ads/ 

http://www.google.de/policies/privacy/

in particular information on how you can prevent the use of your data.

Questions about the imprint or the privacy policy?

We’re not leaving you in the data jungle. Get in touch with us!