We, the WindChess Ltd, Slovakia, welcome your interest in our website and chess database products. Protecting your private life is very important to us. Below, we inform you in detail how we deal with your data.
We take very seriously the protection of your personal data and we handle it confidentially. What we do with your personal data is done exclusively in accordance with the legal framework imposed by the data protection law of the European Union, specifically the General Data Protection Regulation (hereinafter "GDPR") and subsequent applicable regulations.
This data protection statement informs you how we make use of your personal data on our website at www.windchess.com and about your rights under the GDPR.
Name and contact data of the firm to which the statement refers
Processing of personal data
In what follows we inform you about the processing of your personal data whenever you make use of our website simply as a visitor. Information about the processing of your personal data when you make use of what is on offer on our website as a user of the WindChess online shop can be found below under sub-heading III of this data protection statement. Information about the processing of your personal data as far as further services of WindChess - can be found below under sub-heading IV of this data protection statement.
The object of data protection
The object of data protection consists of "personal data”. This is all the information which refers to an identified or identifiable private person (so-called affected person). This includes e.g. information such as name, postal address, e-mail address or telephone number, but also information such as your WindChess user profile name or data linked to it.
Specific information about the personal data processed by us can be found below in the detailed data processing operations.
Collection and storing of personal data and the type and purpose of processing
a.) Visiting the website
Whenever you log into our website or leave a comment on it, the IP address of the computer you connected with is temporarily stored in a so-called logfile. The said data is then over-written with fresh data collected the next time you log in or leave a comment.
The legal basis for the data processing is Art. 6 (1) f) GDPR. Our legitimate interest follows from the fact that we are able to recognize any improper use and where appropriate prevent it. On no account will we make use of the data collected for the purpose of drawing conclusions about you as a person.
In addition, when you visit our website we employ cookies and analysis services. You will receive more detailed explanations about this under numbers 4 and 6 of this data protection statement.
b.) Receiving a newsletter
Insofar as according to Art. 6 (1) a) GDPR you have specifically given your consent, we use your e-mail address in order to regularly send you our newsletter. In order to receive the newsletter it is sufficient to have given us your e-mail address, e.g. by buying our product and registering and subscribing to our services and accepting Terms of Services. We cannot process your request without a valid email address.
If you purchase goods or services on our internet site and in doing so leave your e-mail address this can subsequently be used by us in order to send a newsletter. In such a case we will send with the newsletter exclusively direct advertising for our own goods or services. The legal basis for the sending of the newsletter following the purchase of goods or services is in this case § 7 (3) UWG together with Art. 6 (1) f) GDPR.
The data required for the sending of the newsletter are deleted as soon as they are no longer required for the purpose for which they were collected and insofar as no other legal basis requires further processing. Your e-mail address is then stored for the distribution of the newsletters until you withdraw your consent or no longer wish to receive the newsletter.
c.) Using our contact form and e-mail contact
For questions of any sort we offer you the option of contacting us via a contact form made available on our website. To do so you are required to use a valid e-mail address, so that we know from whom the request comes in order to be able to answer it. Further information can be added if you so wish.
Alternatively it is possible to make contact via the e-mail address which is provided. In this case your personal data which you have provided with the e-mail will be stored.
Data processing for the purpose of making contact comes under Art. 6 (1) f) GDPR. If the goal of making contact is the conclusion of a contract, then the additional legal basis for the processing of the data is Art. 6 (1) b) GDPR.
The personal data which we collect is deleted after the question you brought up has been dealt with.
Disclosure of data
We will only pass on your data to third parties if the data protection regulations allow this. In this sense, we are allowed to disclose your personal data to a third party if this processing is required in order to fulfil a contract with you or for the carrying out of pre-contractual measures, which stem from your request, e.g. passing on your address to a carrier (Art. 6 (1) b) GDPR).
Furthermore, we work together with providers of services, so-called contract workers, who process your data for us and directed by us as described in Art. 28 GDPR (e.g. in evaluating the use of our website via Google Analytics, cf. Number 5). These service providers are carefully selected and contracted by us; they are bound to our instructions and regularly vetted.
We employ cookies on our website. These are small files which are automatically created by your browser and which are stored on your device (laptop, tablet, smartphone, etc.), whenever you visit our website. Cookies in no way damage your device, do not accept viruses, trojans or other malicious software.
The cookie stores information which is generated on each occasion linked to the device which is actually in use. This does not mean, however, that we receive from them any direct knowledge of your identity.
On one hand, employing cookies serves to make access to what we are offering more pleasant for you. Thus we install so-called session cookies in order to recognize that you have already visited individual pages on our website. These are automatically deleted when you leave our website.
Over and above that we also make use of temporary cookies in order to make things as user-friendly as possible; these are stored on your device for a pre-determined length of time. If you revisit our website in order to avail yourself of our services, it is automatically recognized that you have already been on the site and which inputs and settings you have used so that you do not have to enter them again.
On the other hand we employ cookies for a statistical analysis to evaluate the use of our website and for the purpose of optimizing our offer to you (see Number 5).
The data processed by cookies are required for the purposes named to protect our legitimate interests and those of third parties according to Art. 6 (1) f) GDPR.
Most browsers accept cookies automatically. You can, however, configure your browser in such a way that no cookies are stored on your computer or that a warning is given before a new cookie is saved. Complete deactivation of cookies, however, can lead to you not being able to use all the functions on our website.
Analysis by Google Analytics
The tracking measures we have installed have been done on the basis of Art. 6 (1) f) GDPR. With the tracking measures being applied, we want to ensure needs-based design and on-going optimization of our website. On the other hand, we employ the tracking measures to evaluate statistically the use of our website and for the purpose of optimizing what we are offering you. These interests are justified in the sense of the aforementioned regulations.
For the purposes of making our website user-friendly and continually optimizing it we make use of Google Analytics, a web analysis service of Google Inc. (https://about.google/intl/en/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”). In this connection pseudo user profiles are created and cookies (see under Number 4) used. The information derived from the cookie about your use of the website such as
- browser type/version,
- operating system used,
- referrer URL (the website described above),
- host name of the computer accessing the site (IP address),
- time of logging on to the server,
is transmitted to Google’s server in the USA and stored there in accordance with the agreement we have with Google concerning the data in the contract. The information is used to evaluate the use of the website and to produce reports on the website activities and to provide further services linked to the use of the website and the internet for the purposes of market research and rendering the web pages user friendly. This information is also when appropriate passed on to a third party insofar as this is legally required or insofar as the third party has a contract to work on this data. In no case is your IP-address linked to other data by Google. The IP addresses are anonymized, so that no attribution is possible (IP masking). Sessions and campaigns are ended after a specified length of time. The standard time at which to end a session is after 30 minutes with no activity and for campaigns it is six months. The time limit for can go to a maximum of two years.
You can prevent the installation of cookies through an appropriate setting of your browser software; we would, however, point out that in such a case it is possible that not all functions of this website can be used to their full potential.
Moreover, you can prevent the recording of the data generated via the cookie of your use of the website (including your IP address) as well as the handling of this data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=en).
Within the online shop on our website (for more details see under Number III) we also employ tools for the continual optimization of our online marketing. These measures which we include are there for the protection of our legitimate interest on the basis of Art. 6 (1) f) GDPR.
a.) Google AdWords
We employ the "AdWords" procedure of Google in order to place adverts in Google’s advertising network in such a way that they are displayed to users who are potentially interested in our adverts. In this case when they are accessed on our and other websites on which Google’s advertising network is active, a code is executed by Google and so-called marketing tags (also known as web beacons) are attached. With their help, an individual cookie is stored on your device (instead of cookies alternative technologies can also be used). This notes which websites you have visited, and which contents interested you or which pages you clicked on; furthermore, technical information and other details are stored for further use. Moreover, an individual “conversion cookie” is installed. The information obtained with the help of this is used by Google to establish conversion statistics for us. We only learn, however, the anonymous total number of users who have clicked on our advert and who have been transferred onwards to a page which has a marketing tag attached to it. The users‘ data are processed under a pseudonym within Google’s advertising network, unless they have chosen some other setting. The information collected is transmitted to Google and saved on their servers in the USA. You will find further information as to the use of the data by Google and options regarding settings and objections as well as the settings for the display of adverts under https://policies.google.com/technologies/ads or https://adssettings.google.com/authenticated.
b.) Google Retargeting
We use Google’s retargeting technologies. This makes it possible to send to users of our website in a targeted fashion advertising linked to their interests such as they have already shown for our website and our products. The display of adverts follows on from a cookie-based analysis of the previous behavior of the user, but no personal data is stored during this process. In the retargeting a cookie is installed on your device in order to collect anonymized data concerning your interests. This means that you are shown adverts which are most probably more related to the products which interest you. You can prevent the storing of cookies for the purpose of retargeting by installing the following plugin: https://www.google.com/settings/ads/onweb/. You can find further information about the data processing connected with retargeting by Google under http://www.google.com/policies/technologies/ads/.
When you visit the website we make use of the common SSL process (Secure Socket Layer) in connection with the highest level of encoding which is supported by your browser. In general this involves a 256 Bit encoding. If your browser does not support 256 Bit encoding, we will instead revert to 128 Bit v3 technology. You can recognize whether an individual website of ours on the net is encoded by the by the representation of a closed key or padlock symbol in the bottom status bar of your browser.
Moreover, we make use of appropriate technical and organizational security measures in order to protect your data against random or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously being improved according to technological developments.
How we use the personal data of users of the ChessWind membership program
If you use the ChessWind membership program (hereinafter “ChessWind Members” or “Shop”) the following supplementary information is in force.
ChessWind user account
In order to acquire goods and/or services via the shop, you have to log in with your ChessWind user account. If you do not have such a ChessWind user account, you will be asked to set up a new ChessWind user account. With your ChessWind user account accessible via your e-mail address and the password you have chosen, you have at any time access to your previous orders and control over your personal data for the processing of orders.
To set up a ChessWind user account you have to enter into the input box the user profile name you wish, your e-mail address and the password you wish to use.
Our justification for the use of the data for the management of the ChessWind user account, and which you input pursuant to an order, derives from Art. 6 (1) b) GDPR, since the use of the data is required in order to fulfill the contract requested.
If you wish, we will delete the ChessWind user account. Until then we will store the relevant data without limit of time so that you can at any time have access to it. When a ChessWind user account is deleted after the processing of an order (expiration of the warranty period) we lock the data referring to specific purchases and delete it after expiration of the warranty period.
We also process the purchase history associated with your ChessWind user account. This processing is justified by reference to Art. 6 (1) f) GDPR and serves our justified interest in always improving what we offer an offering you suitable products from the ChessWind Shop.
Payment data, delivery address and billing address
When acquiring services in the ChessWind Shop you are required to choose a way to pay and let either us or the company which guarantees your payments have the relevant payment data. Our payment services are outsourced to PayPal Inc since 2007. All necessary payment information submitted to PayPal is stored and analyzed by PayPal Inc according to their GDPR following.
Our justification for the use of your payment data, delivery address and billing address for the settlement of your purchase, and which you input pursuant to an order, derives from Art. 6 (1) b) GDPR, since the use of the data is required in order to fulfill the contract requested.
Some points on mandatory information
According to Art. 13 (2) e) GDPR we advise you that the provision of your personal data is neither legally nor contractually required. Insofar as its provision is necessary for the fulfilling of a contract, this is made clear during the ordering process in compulsory fields. Moreover, you are not obliged to provide us with personal data. Not doing so will have no negative consequences for you, apart from the fact that it may not be possible to fulfill the order you desired. We do not process your personal data for the purposes of some automated decision making.
Rights of the data subject
You have the right:
- According to Art. 15 GDPR to obtain information about personal data of yours processed by us. Specifically, you can obtain information concerning the purposes of the processing, the category of personal data concerned, the categories of recipient to whom the personal data have been or will be disclosed, the envisaged period for which the personal data will be stored, the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data, the right to lodge a complaint, where the personal data are not collected from the data subject, any available information as to their source, the existence of automated decision-making, including profiling, and meaningful information about their details;
- According to Art. 16 GDPR the right to obtain without undue delay the rectification of inaccurate or incomplete personal data we have stored and which concerns you;
- According to Art. 17 GDPR the right to obtain the erasure of personal data concerning you, so long as the processing is not required for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or for the establishment, exercise or defense of legal claims;
- According to Art. 18 GDPR the right to obtain restriction of processing your personal data when the accuracy of the personal data is being contested by you, the processing is unlawful and you oppose the erasure of the personal data and we no longer need the data but you require it for the establishment, exercise or defense of legal claims or according to Art. 21 DSGVO you have raised an objection to its processing;
- According to Art. 20 GDPR the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit those data to another data controller;
- According to Art. 7 (3) GDPR the right to withdraw your consent at any time. This has as a consequence that for the future we may no longer continue to process the data for which this consent was given and
- According to Art. 77 GDPR the right to lodge a complaint with a supervisory authority, As a rule this may be that of your habitual residence, place of work or the headquarters of our firm.
The right to object
Insofar as your personal data is being processed on the basis of legitimate interests according to Art. 6 (1) f) GDPR, you have the right according to Art. 21 GDPR to raise an objection against the processing of your personal data, if there are grounds for it which result from your particular situation or if the objection is directed against direct marketing. In the latter case you have a general right to object, which will be implemented by us without specification of a special situation.
Validity and changes to this data protection statement
This data protection statement is at present in force and dates from March 25 2019.
The further development of our website and offers on it or altered legal or official requirements can make it necessary to make changes to this data protection statement. You can access and print out the data protection statement in force at any time at https://www.windchess.com/privacy-policy