luca Locations Privacy Policy for Operators

Last revised and updated on August 24, 2023

We, culture4life GmbH (”we“or”us“), are committed to protecting your data protection concerns in connection with your use of our services and strive at all times to maintain the security and integrity of your personal data in accordance with applicable data protection law.

Luca Locations is the platform for businesses and is, so to speak, opposite the luca app, which is used by your guests. This platform offers several services, such as offering your guests menus, seating plans and the digital payment service.

If you have signed up with Luca Locations, we, culture4life GmbH (”we“or”us“), your data and, if applicable, the data of your employees. Processing involving the personal data of your guests is carried out in Order processing contract addressed. You can find this in the overview of contract documents in your account.

Personal data is any information relating to an identified or identifiable natural person. For example, your name, email address, but also your IP address represent personal data, the processing of which is subject to strict limits under the General Data Protection Regulation (hereinafter GDPR). The requirements of the GDPR for handling this data apply primarily to the person responsible, i.e. the person who collects and processes the data. If the person responsible passes on the data to service providers to provide a service, this must be made transparent to you as the person concerned. The respective service provider must be bound to the same standards as the person responsible and controlled by him.

In this privacy policy, we inform you about the personal data processing that takes place at Using the luca Locations platform and the luca Locations app take place. In doing so, we describe specifically which data we collect and process on what basis and for what purposes, to which service providers we pass it on and what rights you have with regard to your data in connection with your use of luca Locations.

A. RESPONSIBLE PERSON

The person responsible for processing personal data collected directly by us is:

culture4life GmbH
Mörikestrasse 67
70199 Stuttgart
germany
info@culture4life.de

B. CONTACT DETAILS OF THE DATA PROTECTION OFFICER OF THE PERSON RESPONSIBLE

You can contact our data protection officer as follows:

culture4life GmbH
data protection officer
Rotherstraße 20
10245 Berlin
germany
privacy@culture4life.de

C. PROCESSING WHEN REGISTERING A LUCA LOCATION

To you at Luca Locations To register, it is necessary to provide information about your company and yourself.

  1. Data categories

We process the following contact details, which are necessary to register for Luca Locations:

  • First and last name of the managing director
  • company name
  • address
  • phone number
  • email address

For certain functionalities, you can store the contact details of your employees. For this purpose, the contact details of your employees are processed and stored.

  1. Purpose of processing

We process this data so that you can register your business and thus use Luca Locations.

  1. Legal basis of processing

The legal basis for data processing is in accordance with Art. 6 (1) 1 b) GDPR: Based on the terms of use applicable between you and us for luca Locations.

  1. Recipients of personal data

In order to achieve the purposes described above in this privacy policy, we share your personal data with the following recipients, with the proviso that they may not use this data in any way other than to provide services to us (as so-called contract processors within the meaning of Art. 28 GDPR):

Service provided by providersProvidersProcessed data Software maintenance and software operating services neXenio GmbH, Charlottenstr. 59, 10117 Berlin Contact details IT infrastructure services (server) Telekom Deutschland GmbH, Landgrabenweg 151, 53227 Bonn Contact details

Server location: Germany, Hungary (Open Telekom Cloud)

Email delivery Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin E-mail address

Order processing contracts have been concluded with these recipients in accordance with Article 28 GDPR, so that they can only process your data for a specific purpose and on our instructions.

  1. Storage period of the processed data

Within luca Locations, you can delete your account in the Account section. The account is initially archived for four weeks, after which your account is completely deleted.

The contact details required for registration will be processed by us as long as it is necessary to fulfill our contractual and legal obligations.

D. PROCESSING WHEN VISITING THE LUCA LOCATIONS WEBSITE/USING THE LOCATIONS APP

1. Data categories

When using the luca Location website and the app, Temporary usage data collected: Data that may be generated when using Luca Locations, i.e.:

  • IP address
  • IP location
  • Type and version of the terminal device used
  • Information about the mobile network used, time zone settings, operating system and platform

We also use the open source software Matomo and Mixpanel to measure reach. In addition, the following Analytical data raised.

  • Anonymized IP addresses
  • Pseudo-anonymized location (based on the anonymized IP address)
  • Pseudonymized visitor ID
  • Date and time, time zone settings, and local time
  • Accessed functions and elements of the app
  • Files and links that were clicked on and downloaded
  • External links that are used to open the app
  • App charging time
  • App settings (e.g. language settings, screen resolution)
  • Converted destinations

2. Purposes and legal bases of processing

We will only process your personal data for a specific purpose in accordance with the listed legal bases. Processing operations are described below in relation to the respective purpose and the respective legal bases for processing your personal data are mentioned:

Paragraph

Processing and purpose

legal basis

person responsible

(1)

When you register, we collect and store your contact details, to ensure that the services of our app are used.

Art. 6 (1) 1 b) GDPR: Based on the terms of use for luca services applicable between you and us

culture4life GmbH (we)

(2)

When registering and using the luca app, Temporary usage data collected and stored. The purpose is to ensure the security of the luca system and thus to guarantee the provision of services to you.

Art. 6 (1) 1 b) GDPR: Based on the terms of use for the luca app between you and us

culture4life GmbH (we)

(3)

We raise Analytical datato analyze the behavior of our visitors for the purpose of optimising our offer.

Art. 6 (1) 1 f) GDPR

culture4life GmbH (we)

3. Recipients of personal data

In order to achieve the purposes described above in this privacy policy, we share your personal data with the following recipients, with the proviso that they may not use this data in any way other than to provide services to us (as so-called contract processors within the meaning of Art. 28 GDPR):

Services provided by providers

Providers

Processed data

Software maintenance and software operations services

neXenio GmbH, Charlottenstr. 59, 10117 Berlin

temporary usage data

IT infrastructure services (servers)

Telekom Deutschland GmbH, Landgrabenweg 151, 53227 Bonn

temporary usage data. Server location: Germany, Hungary (Open Telekom Cloud)

Hosting by Matomo Analytics

SaaS Web Internet Solutions GmbH Steinstraße 25, 76133 Karlsruhe

Analysis data For more information about processing by Matomo, please visit: https://matomo.org/gdpr-analytics/

Mixpanel

Mixpanel, Inc. One Front Street, Floor 28 San Francisco, CA 94111

Analysis data For more information about Mixpanel's processing, please visit: https://mixpanel.com/legal/mixpanel-gdpr

Order processing contracts have been concluded with these recipients in accordance with Article 28 GDPR, so that they can only process your data for a specific purpose and on our instructions.

4. Storage period of the processed data

Your personal data will be automatically deleted after the deadlines described below:

  • Temporary usage data: Temporary usage data is processed in log files. These are stored by us for a maximum of 7 days and then automatically deleted. No further storage takes place.
  • Analysis data: Analytical data can be stored for up to 14 months (Matomo) and up to 5 years (Mixpanel).

E. CONTACT, SUPPORT CHAT, PUSH NOTIFICATIONS & NEWSLETTER DELIVERY

1. Contacting Support

To easily contact us, we provide you with a chat with our luca support team. The chat function is provided by our contract processor HubSpot, Inc. 25 First Street, Cambridge, MA 02141 USA. The chat function is provided on the legal basis of Art. 6 para. 1 lit. b DSGVO (contract performance support).

You can find more information about Intercom's data protection over here

2. Push notifications

You also have the option to activate push notifications on your mobile device (mobile phone, tablet). A push notification is a message that appears on a mobile device as a result of a triggering event. These push notifications are sent via the “Firebase Cloud Messaging” service provided by Google, Inc. Mountain View, USA provided. In order to be able to use push notifications, you will be asked for permission to send such messages to your device when you first start the app. The so-called Firebase installation ID is created to determine which devices the messages should be sent to. Firebase keeps the Firebase installation ID until the Firebase recipient (you) unsubscribes/deactivates push notifications in the app/device settings. Once unsubscribed, your ID will be removed from Firebase service live and backup systems within 180 days. The push notification is processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a DSGVO) to the approval of your device settings. This can be revoked at any time in the device settings by deactivating it.

You can find more information about the provider's data protection here: https://firebase.google.com/support/privacy

3rd newsletter

We use the email address you provide to send you regular information about Luca.

In this respect, data processing is carried out solely on the basis of our legitimate interest in personalized direct marketing in accordance with Art. 6 para. 1 lit. f DSGVO. You can unsubscribe at any time. If you have initially objected to the use of your email address for this purpose, we will not send you an email. You are entitled to object to the use of your e-mail address for the above mentioned advertising purpose at any time with effect for the future by notifying us of your wish to unsubscribe at any time via the unsubscribe link within the newsletter or by sending an email to privacy@culture4life.de. After receipt of your objection, the use of your email address will be discontinued immediately. To receive the newsletter, it is sufficient to provide and confirm an email address.

We use HubSpot, Inc., 5 FirstStreet to send and manage our newsletter. Cambridge. MA 02141 USA He processes your personal data on our behalf.

F. RIGHTS OF DATA SUBJECTS

With regard to the processing of your personal data, you have the following rights provided for in the GDPR, which you can assert against us for all processing:

  • The right to request a statement as to whether your personal data is being processed and, where this is the case, the right to access this data. This information includes, among other things, the processing purposes, the categories of processed personal data and the recipients or categories of recipients to whom the personal data have been or are still being disclosed (Art. 15 GDPR).
  • The right to request that your personal data be corrected if it is incorrect or incomplete (Article 16 GDPR).
  • The right, under certain conditions, to request that your personal data be deleted immediately (so-called “right to be forgotten”) (Art. 17 GDPR). Your data can be deleted accordingly, unless there is a legitimate interest or legal retention periods to the contrary.
  • The right to request that the processing of your personal data be restricted under certain conditions (Article 18 GDPR).
  • The right to withdraw consent given to us with regard to the processing of your personal data at any time. Such a revocation is valid for the future and does not affect the lawfulness of the processing that took place up to your withdrawal.

To exercise these rights against us, you can also contact our data protection officer.

Notwithstanding the above rights, you have the right to lodge a complaint with a supervisory authority for data protection and freedom of information, such as the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information:

State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, P.O. Box 10 29 32, 70025 Stuttgart.

Phone: 0711/615541-0
Fax: 0711/615541-15

poststelle@lfdi.bwl.de

G. VERSION

This is the current version of our privacy policy (valid from 24.08.2023). We reserve the right to adapt this privacy policy (in particular in the event of changes in the legal situation or changes to our services). For this reason, it is recommended that you review this privacy policy at regular intervals.