This website uses Google Analytics or other technology to collect and store data for marketing and optimization purposes. From this data, usage profiles can be created under a pseudonym. Cookies may be used. Cookies are small text files stored locally in the cache of the site visitor’s internet browser. Cookies enable recognition of the internet browser. The data collected with the etracker technologies will not be used to personally identify the visitor to this website without the special consent of the data subject. A merger with personal data regarding the bearer of the pseudonym does not take place.
The data collected by the technologies will not be used to personally identify the visitor to this website or be combined with personal data about the bearer of the pseudonym without the specific consent of the data subject. Data collection and storage can be objected to at any time with effect for the future.
Transfer of your data to third parties does not occur without your express consent.
Even if you are not logged in to Facebook, Facebook stores and uses data about the operating system used, the browser version, the IP address and the origin location that can be derived from it.
In addition, Facebook can recognize you via so-called “cookies” as a non-logged in/unregistered user and use the statistical data obtained from the page request on your next login or your first registration on Facebook for profile creation.
The granted consent to the storage of the data, the e-mail address and their use for sending the newsletter can be revoked at any time, for example via the “unsubscribe” link in the newsletter.
Google Webfonts (http://www.google.com/webfonts/) are used to improve the visual presentation of different information on this website. When the page is opened, the web fonts are transferred to the browser's cache so that they can be used for display. If the browser does not support Google web fonts or does not allow access, then the text will be displayed in a default font. When opening the page, no cookies are saved with the website visitor. Data transmitted in connection with the page view is sent to resource-specific domains such as fonts.googleapis.com or fonts.gstatic.com. They are not associated with data that may be collected or used in connection with the parallel use of authenticated Google services such as Gmail.
2 Legal basis for the processing of personal data
The legal basis for data processing is Art. 6 Para. 1 Letter f GDPR. The justified interest consists in a faultless functioning of the Internet page.
3 Purpose of data processing
This is necessary so that your browser can display our texts in a visually improved manner. If your browser does not support this feature, your computer will use a default font for the display.
4 Duration of data retention
We do not currently have any information about how long data is retained by our processor.
5 Options for opting out and removal of data
You can set your browser so that the fonts are not loaded by the Google servers (e.g. by installing add-ons like NoScript or Ghostery for Firefox). If your browser does not support Google fonts or if you block access to the Google servers, then the text will be displayed in the system's default font.
HubSpot is a software company from the USA with a subsidiary in Ireland.
Contact: HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, telephone: +353 1 5187500. HubSpot is subject to the TRUSTe Privacy Seal and the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework.
Your personal data will only be passed on to third parties with your express consent, unless we are obliged to do so by court order or within the framework of criminal prosecution.
We use Google Ads Remarketing of Google Ireland Ltd, Gordon House, Barrow Street, D04 E5W5, Dublin, Ireland (hereinafter referred to as Google). Google Remarketing is used for the renewed addressing of visitors to the website for advertising purposes via Google Ads advertisements. Google Ads Remarketing can be used to create target groups ("similar target groups") who, for example, have visited certain pages. This makes it possible to identify the user on other websites and to display targeted advertising. During this process, Google places a cookie on the user's computer. This allows personal data to be stored and analyzed, especially the user's activity (in particular which pages have been visited and which elements have been clicked on), device and browser information (in particular the IP address and the operating system), data on the advertisements displayed (in particular which advertisements have been displayed and whether the user has clicked on them) and also data on advertising partners (in particular pseudonymized user IDs). Further information on the collection and storage of data by Google can be found under https://policies.google.com/privacy?gl=DE&hl=en
2. Purpose of data processing
The purpose of processing personal data is to address a specific target group. The cookies stored on the user's terminal device recognize the user who is visiting a website and are therefore able to display advertisements in line with the user's interests.
3. Legal basis for the processing of personal data
The legal basis for the processing is Article 6, Section 1, Clause 1, Letter f of the GDPR.
4. Duration of data retention
5. Options of opting out and removal
You can prevent the collection and processing of your personal data by Google by preventing the storage of third-party cookies on your computer; by using the "Do Not Track" function of a supporting browser; by deactivating the execution of script code in your browser; or by installing a script blocker such as NoScript (www.noscript.net) or Ghostery (www.ghostery.com) in your browser. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en You can deactivate Google's use of your personal data by clicking on the following link: https://adssettings.google.de You can find further information on opting out and removal options relating to Google under https://policies.google.com/privacy?gl=EN&hl=en In addition, Google has signed and is certified under the privacy shield agreement concluded between the European Union and the USA. By doing so, Google undertakes to comply with the standards and regulations of European data protection law. Further information can be found under the following link: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
1. Description and scope of data processingFor the use of payment systems on our e-commerce portal, we use GiroSolution GmbH as payment service provider. By means of an interface to its “GiroCheckout” system, GiroSolution GmbH ensures the system connection of our e-commerce portal to the following payment procedures:
e) Credit cards
g) Direct debit
i) Immediate transfer
a) Surname and first name
c) E-Mail address
d) Information regarding age of majority at Giropay ID - age verification (the date of birth is not passed on)
e) Information to confirm the account details with Giropay ID - account verification (IBAN and BIC as well as the first and last name of the associated account holder)
2. Legal basis for data processingThe legal basis for data processing and the transfer of data to the above-mentioned third parties is Art. 6 Para. 1 Letter b GDPR. In addition, Art. 6 Para. 1 Letter f GDPR is the legal basis for data processing.
3. Purpose of data processingThe transfer of the data and its processing is necessary in order to make the payment associated with the transaction carried out by you on our e-commerce portal with the method of payment chosen by you and thereby to complete the transaction.
The integration of many different payment methods is complex and cost-intensive. We therefore use a service provider for the technical integration, which explains our justified interest in the above-mentioned data processing by GiroSolution GmbH according to Art. 6 Para. 1 Letter f GDPR.
4. Duration of data retentionThe data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of the above-mentioned data, this is the case when the contract has been settled and there are no further claims for reversal, i.e. after expiry of the statutory warranty service or granted warranty periods. The data will then be deleted subject to statutory retention periods beyond this point in time.
5. Options of opting out and removalThe collection of data for the provision of the website and the storage of data in log files is mandatory for the operation of the website. Consequently, there is no possibility of objection on the part of the user.
I. Name and address of the person responsible for data processing (Controller)
This data protection declaration applies to data processing by the following Controller pursuant to Art. 4 No. 7 GDPR:
BIOMES NGS GmbH
c/o TH Wildau
II. Name and contact details of the company data protection officer
The data protection officer of BIOMES NGS GmbH is the external service provider DataGuard.
Dachauer Straße 65
+49 89 7400 45840
III. Principles of processing personal data
BIOMES NGS GmbH undertakes to protect and respect the principles of data processing in accordance with Art. 5 Para. 1 GDPR. These include the lawfulness of processing, fairness of processing, transparency, purpose limitation, minimization of data, accuracy of data processing, limitation of storage, and the integrity and confidentiality of data. These principles apply whenever we process personal data, i.e. any information relating to an identified or identifiable natural person. A special category of personal data is health data, the processing of which we refer to in particular. Health data is personal data relating to the physical or mental health of a natural person including the provision of health services, and which reveals information about that person's state of health. Each of our employees who processes personal data undertakes in writing to observe data secrecy when starting work.
IV. Processing of personal data during the ordering process
Within the framework of the ordering process, personal data is processed for the processing of the order. These include
- Name of the customer
- Company name (optional)
- Street and house number
- Zip code and place of residence
- Telephone (optional)
- E-mail address
- Order note (optional)
- Payment method (PayPal, Giropay, EPS, credit card)
The data processing serves for the execution of the order. The legal basis is Art. 6 Para. 1 Letter b GDPR. The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. This is the case if you no longer wish to use the services and products of BIOMES.world or if you no longer wish to view the analysis results of your tested samples and wish to have your data deleted.
V. Registration and activation of the data set at my.BIOMES.world
Registration and activation of the data set at my.BIOMES.world, you must register once and activate your data set. The following personal data is collected during registration:
- Surname and first name
- Company (optional)
After registration, the collected data set of the sample that was sent in and analyzed is activated. For this purpose, the following further aspects of the sample provider are queried:
- Profile name or sample identifier
- Activation code
- Comment (optional)
- Date of birth (optional)
- Age (optional)
- Height (optional)
- Weight (optional)
- Gender (optional)
- Nutrition type (optional)
- Sport activities (optional)
- Ingestion of probiotics (optional)
- Time of last antibiotic treatment (optional)
Some of the collected data relates to health. You provided the data voluntarily and the legal basis for data processing is the consent you gave according to Art. 9 Para. 2 Letter a GDPR. You can revoke this at any time. However, this does not affect the lawfulness of data processing carried out on the basis of consent prior to revocation. The data is used to attribute the sample to your person and for the customer-specific analysis of the sample you sent in. With this data, the analysis result can be presented in a more precise and personalized way, since it can be compared to a suitable subgroup and not with the whole cohort. The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. This is the case if you no longer wish to use the services and products of BIOMES.world or if you no longer wish to view the analysis results of your tested samples and wish to have your data deleted.
VI. Processing of health data in the primary analysis proces
In the primary analysis process, we examine the microbial DNA of your stool sample. The analysis process starts with the activation of the sample collection kit and ends when the analysis results are made available by e-mail and/or access to the dedicated dashboard, which you can reach at my.BIOMES.world. We examine your sample with sequencing methods and can thereby analyze microorganisms. Through a comparison with our scientific database, we can create your individual intestinal flora profile. This profile is analyzed with algorithms so that it is possible to draw conclusions about every bacterium living in your intestine. This in turn permits conclusions to be drawn about your state of health, which means that the results of the analysis constitute health data. Personal and analysis data is linked via encrypted pseudonymization. The personal data and the data of the analysis results are stored on two different, physically separated database systems and can only be attributed with the help of the cryptic pseudonymization ID.
The legal basis for the processing is your consent pursuant to Art. 9 Para. 2 Letter a GDPR and the purpose of the processing is the analysis of your intestinal flora. You can revoke your consent at any time, but the legality of the processing carried out on the basis of your consent up to the point of revocation will not be affected by this. We will delete your data if it is no longer necessary to achieve the purpose for which it has been collected. This is the case if you no longer wish to use the services and products of BIOMES.world or if you no longer wish to view the analysis results of your tested samples and wish to have your data deleted.
VII. Purchase of INTEST.pro from a business partner
If you purchase the INTEST.pro self-test from a pharmacy or another business partner, then the respective business partner will also process the personal data you provide (see V.) and will also have access to the dashboard and can view your analysis results. Your personal details are used for registration by the business partner at www.biomes.world. The business partner requires access to the analysis result in order to make the analysis results available in an advisory function.
The legal basis for data processing is the consent you gave according to Art. 9 Para. 2 Letter a GDPR. You can revoke this at any time. However, this does not affect the lawfulness of data processing carried out on the basis of consent prior to revocation. The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. This is the case if you no longer wish to use the services and products of BIOMES.world or if you no longer wish to view the analysis results of your tested samples and wish to have your data deleted.
VIII. Secondary analysis process
The data from the primary analysis process will, with your permission, be used for a better and more understandable presentation in the dashboard or exported reports. This is done by anonymizing the data needed to evaluate the analysis results. No personal data will be processed in this context. In addition, the anonymized data is fed into a database with which other samples are cross-checked so that the overall analytical results can be continuously improved. It is not possible to draw conclusions about your person within the framework of the secondary analysis process.
IX. Rights of the data subject
If your personal data is processed, then you are a data subject within the meaning of the GDPR. You have the right
- To request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you may request information about the purposes of the processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of a right of correction, deletion, limitation of processing or objection, the existence of a right of appeal, the origin of your data if it has not been collected by us, and the existence of an automated decision making process including profiling and, if applicable, meaningful information on its details;
- To request the immediate correction of incorrect or incomplete personal data stored by us in accordance with Art. 16 GDPR;
- To demand the deletion of your personal data stored by us in accordance with Art. 17 GDPR, unless processing is necessary for exercising the right to freedom of expression and information, for fulfilling a legal obligation, for reasons of public interest or for asserting, exercising or defending legal claims;
- To demand the restriction of the processing of your personal data in accordance with Art. 18 GDPR if the accuracy of the data is disputed by you, the processing is unlawful but you refuse its deletion and we no longer need the data but you need it to assert, exercise or defend legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR;
- To receive your personal data which you have provided to us in a structured, current and machine-readable format or to request transfer to another responsible person in accordance with Art. 20 GDPR.
X. Right to appeal to a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to appeal to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or place of work or of our company headquarters for this purpose.