Back to login
Data protection
- OCULUS Optikgeräte GmbH (hereinafter also referred to as “OCULUS”) is the controller with the meaning of data protection law and in accordance with Section 1.1.
- OCULUS processes data sent by a contact person of the IOL company (email, business card, enquiry, phone call, IOL data). The data is processed for initiating business relationships, for instance, for responding to requests for information, for engaging in general communication with the company and for using the platform according to its intended purpose. The data may also be stored and processed on the grounds of legal provisions.
OCULUS also processes data required for the conclusion and performance of a contract between OCULUS and the IOL company. - The main legal basis for the processing of your personal data during these processes are Art. 6 (1) lit. f) GDPR (legitimate interests, e.g. within the meaning of a planned initiation of business or fulfilment of a request for information) and Art. 6 (1) lit b) GDPR (performance of a contract).
-
The data collected is stored for as long as it is required, i.e. as long as it is required for fulfilling the purpose of its collection. This notably means that the personal data collected will be deleted after the termination of the contract unless this conflicts with statutory or contractual retention periods. The data is therefore deleted as soon as it is no longer required for communicating with the company, for providing it with information, for maintaining a business relationship or because it is no longer required by law. It is deleted, in particular, if
- the stated reasons no longer apply and are unlikely to occur again in the future;
- the company asserts an existing right to erasure;
- the deletion is prescribed by law.
-
Any personal data collected by the contact person is not transferred to third parties, unless
- it is prescribed by law;
- it is required for the fulfilment of contractual obligations;
- it is required due to legitimate interests of third parties; or
- it has been agreed on the grounds of consent issued.
- order processors engaged by us;
- authorities
- public organisations;
- customers and partners.
- The personal data is processed in our internal systems, at the premises of order processors contractually engaged by OCULUS and in computer centres located in the Federal Republic of Germany.
- OCULUS shall back up the data regularly and within the required scope. OCULUS shall further meet the technical and organisational requirements in accordance with Art. 32 GDPR. In particular, OCULUS shall protect the systems to which we have access against unauthorised reading, storage and modification as well as other unauthorised access or attacks of any kind by employees or third parties. OCULUS shall employ suitable state-of-the-art measures within the required scope, particularly to protect the systems against viruses and other malicious programs or program routines, and also implement measures to protect their facilities, particularly against burglary.
-
A data subject within the meaning of the General Data Protection Regulation has the right to information about their personal data processed by OCULUS (Art. 15 GDPR). Should we receive an action seeking disclosure that has not been placed in writing, please note that we may request for the data subject to provide evidence that they are the person they claim to be.
- The data subject has the right to rectification, erasure and restriction of processing, unless stated otherwise by law (Art. 16, 17, 18 GDPR).
- The data subject further has the right to object to the processing, unless stated otherwise by law (Art. 21 GDPR).
- The data subject has the right to complain. The data subject therefore may complain to the competent supervisory authorities (“Landesdatenschutzbeauftragte” in Germany) if they are of the opinion that OCULUS has incorrectly processed their personal data (Art. 77 GDPR).
- If the personal data was collected on the basis of the data subject’s declaration of consent, the data subject has the right to withdraw such consent at any time and without stating any reasons (Art. 7 (3) GDPR).