Privacy Statement

1. Information on the collection of personal data

The protection of your personal data during the collection, processing and use on the occasion of your visit to our website or the use of our app is an important concern for us. Your data will only be processed within the framework of the legal regulations. Below you will find information about which data is collected during your visit to one of our online services and how it is used:

a. Collection and processing of data

Every access to one of our online services and every retrieval of a file stored on one of our online services is logged. The storage serves internal system-related IT security and statistical purposes. The following data is logged: Name of the retrieved file, date and time of retrieval, amount of data transferred, notification of successful retrieval, web browser and requesting domain.

In addition, the IP addresses of the requesting computers are logged in abbreviated form.

When using the app, we need your device identification, unique number of the terminal device (IMEI = International Mobile Equipment Identity), unique number of the network subscriber (IMSI = International Mobile Subscriber Identity).

Personal data is only collected if you provide this information yourself voluntarily, for example as part of an enquiry via our contact form or this to register for certain services.

We use the so-called double opt-in procedure for newsletter registration. This system works in such a way that you first enter your surname and first name including a valid e-mail address when registering. You will then receive an e-mail from us with a confirmation link. Your account will only be activated after your confirmation.

When registering for the "Hahnemühle Excellence Program", we automatically check at domain level on an anonymous basis whether the domain from which one wishes to register is approved for this use.

b. Use and disclosure of personal data

If you have provided us with personal data without further consent, we will only use this data to answer your enquiries, to process contracts concluded with you and for technical administration.

Your personal data will only be passed on to third parties or otherwise transferred if this is necessary for the purpose of contract processing - in particular the transfer of order data to suppliers -, if this is necessary for billing purposes or if you have given your prior consent. You have the right to revoke your consent at any time with effect for the future.

The deletion of the stored personal data takes place if you revoke your consent to the storage, if their knowledge is no longer necessary for the fulfilment of the purpose pursued with the storage or if their storage is inadmissible for other legal reasons.

c. Revocation

If you have given your consent to the processing of your data, you may revoke this consent at any time. Such a revocation will affect the permissibility of the processing of your personal data after you have expressed it to us.

d. Weighing up interests

Insofar as we base the processing of your personal data on the balance of interests, you can object to the processing. This is the case if the processing is in particular not necessary for the performance of a contract with you, which is shown by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will review the merits of the case and either cease or adapt the data processing or show you our compelling legitimate grounds on the basis of which we will continue the processing.

e. Advertising opposition

Of course, you can object to the processing of your personal data for the purposes of advertising and data analysis at any time. You can send your objection to advertising to the contact details given below under f..

f. The person responsible pursuant to Art. 4 (7) DS-GVO is:

Hahnemühle FineArt GmbH

Hahnestraße 5

37586 Dassel

Germany

Contact: Jannis Mocha / Detlev Kramer

Phone: +49 5561 791 361 / +49 5561 791 305

E-Mail: datenschutz@hahnemuehle.com

Website: www.hahnemuehle.com

The name and address of the data protection officer can be found at the end of this declaration.

2. Your rights

a. You have the following rights in relation to personal data relating to you:

  • • Right to information,
  • • Right of rectification or erasure
  • • Right to restrict processing
  • • Right to object to processing
  • • Right to data portability.

b. You also have the right to complain to a data protection supervisory authority about our processing of your personal data.

3. Cookies

Cookies are small text files that are sent to your browser when you visit certain websites. Information about your country of origin or browser language, for example, is stored in the text. Cookies increase the user-friendliness of websites and enable fast and effective surfing. They do not harm your terminal device and do not contain any confidential data such as email address or payment details.

Cookies necessary for the operation of the website are set automatically when the website is accessed. Other cookies and functionalities of the website operator and of third parties that are not necessary for use may only be used after their consent. For this purpose, you will be asked to select permitted cookies and functions when you access the website. This selection is in turn stored in a cookie until you delete this cookie from your end device.

You can correct the selection of permitted cookies and function at any time via the user guide for consenting to cookies.

Alternative disabling of cookies

You can manage the use of cookies yourself via most browsers. To do this, go to the preferences. It is often even possible to set rules for cookies on individual websites. If you have any questions, contact the manufacturer of the browser you are using. If you do not accept cookies, this may result in limited use of the website.

4. Use of Google Analytics

(1) This website uses Google Analytics, a web analytics service provided by Google Inc ("Google"), with your consent. Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyse how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymisation is activated on this website, however, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.

(2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

(3) This website uses Google Analytics with the extension "_anonymizeIp()". This means that IP addresses are processed in abbreviated form, which means that personal references can be

ruled out. If the data collected about you is related to a person, this is immediately excluded and the personal data is deleted immediately.

(4) We use Google Analytics to analyse and regularly improve the use of our website. The statistics obtained enable us to improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 para. 1 lit. f DS-GVO.

(5) Third party information: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. User terms and conditions: www.google.com/analytics/terms/de.html, privacy overview: www.google.com/intl/de/analytics/learn/privacy.html, and privacy policy: www.google.de/intl/de/policies/privacy.

(6) You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: tools.google.com/dlpage/gaoptout. or by asserting your objection here. (opt-out) bit.ly/1Q6YkQI On the website youronlinechoices.com you can read more information about cookies and the individual providers. There you also have the option to object to usage-based online advertising by individual tools or by all tools.

(7) This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your usage in your customer account under "My data", "Personal data".

5. External links

For your optimal information, you will find links on our site that refer to third-party sites. These include our presence on Facebook, Twitter, Instagram, YouTube and LinkIn. Insofar as this is not obviously recognisable, we point out that it is an external link. We have no influence on the content and design of these pages of other providers and therefore refer to their data protection declarations. The guarantees of this data protection declaration therefore naturally do not apply there.

5.1 Use of our meta-offers.

We are jointly responsible for the use of our Facebook and Instagram offers with Meta Platforms Ireland Limited (Facebook Ireland Limited) - hereinafter referred to as Meta - , 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, www.facebook.com/help/contact/540977946302970 , as joint controllers pursuant to Art. 26 DSGVO and the Facebook Page Insights Supplement (https://www.facebook.com/legal/terms/page_controller_addendum ).

Meta processes (personal) data when using Facebook products - including when visiting our Facebook or Instagram page - even from persons who are not registered with any of the Facebook services. Facebook describes which (personal) data this is in detail, how it is processed, for what purposes and on what legal basis in its data policy (https://www.facebook.com/privacy/policy/?section_id=13-HowToContactMeta), which applies to all Facebook products. There you will also find information on how to contact Meat as well as on the settings options for advertisements, cookies, etc.. The data may be transferred to countries outside the European Union.

For more information about the cookies Meta uses when having a Facebook account, using Facebook products (including the website and apps) or visiting other websites and apps that use Meat products (including the "Like" button or other Facebook technologies), Facebook provides the Cookie Policy (https://www.facebook.com/policies/cookies/ ). Information on how to manage information held about you can also be found at this link: www.facebook.com/policies/cookies/

When you visit our Facebook or Instagram page, Meta records your IP address, among other things. Together with other information that Meta receives through cookies, Meta provides us as the operator of the Meta service with statistical information about the use of the respective service (so-called page insights). These are summarised data that show how users interact with the site. These page insights may be based on personal data collected by Meta in connection with a visit or interaction of users on or with our respective Meta service and its content. Meta provides more information about this here: www.facebook.com/about/privacy.

We can use Page Insights to anonymously evaluate reach, page views, time spent on video posts, actions (likes, comments, sharing of posts) as well as by age, gender and location (as indicated by users in their respective Facebook (meta) profiles). In doing so, settings can be made for the evaluation of the reach or corresponding filters can be set with regard to the selection of a time period, the consideration of a specific post as well as demographic groupings (e.g. female, 20-30 years old). This data is anonymised, aggregated and abstracted. These settings therefore do not allow us to draw any conclusions about individuals. The evaluation serves to optimally design the offer on our pages for the purpose of public relations. The legal basis for this data processing is Art. 6 para. 1 lit. a and f DSGVO.

As the provider of the information service, we do not collect or process any other data from the use of the pages.

You have a right of appeal to the Irish Data Protection Commission (responsible for Meta Platforms Ireland Limited (Facebook Ireland Limited)), irrespective of the rights against us (Art. 77 GDPR).

If you have specific questions about the protection of your data, please contact our Data Protection Officer or the Data Protection Officer of Meta Platforms Ireland Limited (Facebook Ireland Limited)) www.facebook.com/help/contact/540977946302970,

5.2 Use of our Twitter service.

We use the technical platform and services of Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103 U.S.A. for the short message service offered here. The responsible party

for the data processing of persons living outside the United States is Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland.

We would like to point out that you use the Twitter short message service offered here and its functions on your own responsibility. This applies in particular to the use of the interactive functions (e.g. sharing, rating).

Information about which data is processed by Twitter and for what purposes can be found in Twitter's privacy policy: twitter.com/de/privacy

We have no influence on the type and scope of the data processed by Twitter, the type of processing and use or the transfer of this data to third parties. We also have no effective control options in this respect.

With the use of Twitter, your personal data will be processed by Twitter Inc. in the United States, Ireland and any other country in which Twitter Inc. does business, regardless of your residence.

On the one hand, Twitter processes your voluntarily entered data such as name and user name, email address, telephone number or the contacts in your address book when you upload or synchronise it.

On the other hand, Twitter also evaluates the content you share to determine what topics you are interested in. Stores and processes confidential messages you send directly to other users and can determine your location using location data, wireless network information or your IP address to send you advertising or other content.

Twitter Inc. may use analysis tools such as Twitter Analytics or Google Analytics for evaluation purposes. We have no influence on the use of such tools by Twitter Inc. If tools of this kind are used by Twitter Inc., we have neither commissioned this nor approved or supported this in any other way. The data obtained from this analysis is also not made available to us. Only certain non-personal information about tweet activity, such as the number of profile or link clicks through a particular tweet, is viewable in our account. We have no way of preventing or turning off the use of such tools on your Twitter account.

As Twitter Inc. is a non-European provider with a European branch only in Ireland, it is bound by European data protection regulations. This concerns, for example, your rights to information, blocking or deletion of data or the possibility to object to the use of usage data for advertising purposes.

You have options to restrict the processing of your data in the general settings of your Twitter account and under the item "Data protection and security". In addition, you can restrict Twitter's access to contact and calendar data, photos, location data, etc. on mobile devices (smartphones, tablet computers) in the settings options there. However, this depends on the operating system used.

More information on these points is available on the following Twitter support pages:

You can find out about the possibility of viewing your own data on Twitter here: support.twitter.com/articles/20172711

Information about the inferences drawn about you by Twitter can be found here: twitter.com/your_twitter_data

Information on the available personalisation and data protection setting options can be found here (with further references):

Furthermore, you have the option of requesting information via the Twitter data protection form or the archive requests:

 

We do not collect any data ourselves via your Twitter account. However, the data you enter on Twitter, in particular your user name and the content published under your account, are processed by us insofar as we retweet or reply to your tweets, if applicable, or also write tweets from us that refer to your account. The data you freely publish and disseminate on Twitter is thus included by us in our offer and made accessible to our followers.

You can also find more information about Twitter and other social networks and how to protect your data at www.youngdata.de.

Twitter usage concept:

Our public relations work also takes place on Twitter. With this usage concept, we as a non-public body assume responsibility for the use of social media. Please also note our privacy policy.

Twitter is a social network for short messages, photos and videos. Registered users can publish short messages free of charge via this service. These tweets have a limited length and are usually visible to everyone.

Users can "follow" other users so that they can read their messages in their own Twitter feed.

The advantages of Twitter are its wide reach and - in contrast to some other social networks - its readability without the need for the user to register, as well as its usability without the use of a real name.

You can find more information on Twitter here: about.twitter.com/de.html

The Twitter channels are a useful addition to the existing communication channels, such as the website, press releases, print products and events. The Twitter channels primarily inform users about current news from our business operations.

For some target groups, the "classic" instruments alone (print, website, mailing) were no longer sufficient. We found that with Twitter we can reach a wide circle of interested people much more directly, quickly and on a daily basis, especially since interested recipients can

subscribe to corresponding tweets. The Twitter channel allows for a wide dissemination of our messages, better networking with other institutions and sources of information and an immediate reaction to what is happening.

Furthermore, through direct dialogue with readers, we can gather opinions and receive feedback to optimise our business activities.

With our Twitter account we inform users about news from our business operations.

Responsibility for editorial support lies with our management and the associated communications and media team.

We would like to point out to users that the Twitter channel is merely an additional option for contacting us or receiving information from us. Alternatively, the information offered via Twitter can also be accessed via the corresponding links on our website or on the other linked websites. In principle, you can contact us with all enquiries. Please use the information provided above for this purpose.

This usage concept is evaluated by us once a year with regard to whether and how it is used. This evaluation of the usage concept takes into account the usage figures and reach as well as the target group structure of the networks.

5.3 Use of our LinkedIn offer

We manage our account in accordance with the principles set out below:

We are jointly responsible with LinkedIn Ireland Unlimited Company,Wilton Place, Dublin 2, Ireland www.linkedin.com/help/linkedin/answer/1581/hilfe-erhalten-und-den-linkedin-kundenservice-kontaktieren hereinafter referred to as the "Platform Operator".

We only process your personal data, such as your surname and first name, your e-mail address and IP address, etc., if there is a legal basis for doing so. You can find more detailed information on processing by the platform operator in the platform operator's data protection declaration.

Therefore, data is only passed on to third parties if there is a legal basis for the processing. For example, we disclose personal data to persons or companies that act for us as processors in accordance with Art. 28 DSGVO. A processor is anyone who processes personal data on our behalf, i.e. in particular in an instruction and control relationship with us.

In accordance with the requirements of the GDPR, we conclude a contract with each of our order processors to oblige them to comply with data protection regulations and thus provide your data with comprehensive protection.

We would like to point out that your data may also be passed on to third parties by the platform operator. However, we have no influence on this.

You can find more detailed information on processing by the platform operator in the platform operator's data protection declaration.

We store all personal data that you transmit to us only for as long as it is needed to fulfil the purposes for which this data was transmitted or as long as this is required by law. Once the purpose has been fulfilled and/or the legal storage periods have expired, the data will be deleted or blocked by us, insofar as this is technically possible for us.

Information on data storage by the platform operator can be found in its privacy policy, see above.

This platform uses SSL encryption for security reasons and to protect the transmission of confidential content, such as enquiries that you send to us or the platform operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. There is no separate indication within apps that SSL encryption is available.

If SSL encryption is activated, the data you transmit to us cannot be read by third parties.

Collection and storage of personal data as well as their type and purpose of use

When you access the website of the platform operator, information is automatically sent to the server of the platform operator by the browser used on your end device or by the app. This information is temporarily stored by the platform operator in a so-called log file.

However, this data is only available to the platform operator. It is not possible for us to access this data. Further information can be found in the platform operator's privacy policy, see above.

We do not collect any personal data about you. However, it is possible to obtain pseudonymised data in the form of statistics about the users of our site over a certain period of time. The software for analysing user statistics is usually provided by the platform operator itself, but in some cases it is also possible to integrate third-party software (e.g. Google Analytics). Here, data about the users of the site can be collected, such as age, gender, country of origin, browser used and interests.

However, this data is always pseudonymised and it is not possible for us to make statements about individual users based on this data alone. We use this data exclusively to optimise the content we offer and its marketing and to adapt it to the respective user interests. This is a legitimate interest according to Art. 6 para. 1 p. 1 lit. f DSGVO.

Furthermore, it is possible for you to interact with our account. You can do this, for example, by marking a post with "Like", sharing or commenting on it, or by writing to us directly.

When you interact with us, data processing by us is usually inevitable, as we can see your account and thus have access to your personal data, such as your user name, your profile picture or the date or time of the interaction.

We use this data exclusively to optimise the content we offer and its marketing and to adapt it to the respective user interests. This is a legitimate interest pursuant to Art. 6 para. 1 p. 1 lit. f DSGVO. Our legitimate interest follows from the above-mentioned reason of optimising the content provided by us on our profile. Furthermore, the data collected is information that is only made available to us through your interaction with our profile. This establishes a relevant and appropriate relationship between you and our profile.

Where deletion is possible by us, personal data will be deleted by us after 28 days at the latest, unless there is a legal basis for further processing beyond this period.

Further information on data processing by the platform operator can be found in the platform operator's privacy policy, see above.

This platform uses cookies. We have no influence on which cookies the platform operator uses. You can find more information in the privacy policy of the platform operator under the following link: www.linkedin.com/legal/privacy-policy

To enforce your rights, you can contact the platform operator directly if the processing is carried out by the platform operator. We have provided you with the contact details of the platform operator as the data controller at the beginning of this document. Of course, you can also contact us to enforce your rights.

With regard to changes to the data protection declarations by the platform operator, reference should be made to the platform operator's data protection declaration, see above.

5.4 Use of YouTube

We also use the function for embedding YouTube videos from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "YouTube") on some of our online offers.YouTube is a company affiliated with Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). The function displays videos stored on YouTube in an iFrame on the website. The option "Extended data protection mode" is activated. This means that YouTube does not store any information about visitors to the website. Only when you watch a video is information about it transmitted to YouTube and stored there. Your data may be transmitted to the USA. The use of cookies or comparable technologies takes place with your consent on the basis of § 15 para. 3 p. 1 TMG in conjunction with. Art. 6 para. 1 lit. a DSGVO. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until revocation.

For more information on the collection and use of data by YouTube and Google, your rights in this regard and ways to protect your privacy, please refer to YouTube's privacy policy at www.youtube.com/t/privacy.

6. Safety

We take technical and organisational security measures in accordance with the latest state of the art to protect the data you have made available to us from accidental or intentional manipulation, loss, destruction or access by unauthorised persons. For example, the data you enter in the contact form is transmitted to us in encrypted form. The security measures are continuously improved in line with technological developments.

Hint:

We make every effort to store your personal data in such a way that it is not accessible to third parties by taking all technical and organisational measures. When communicating by email, we cannot guarantee complete data security during transport, so we recommend that you send confidential information by post.

7. Right to information

Upon written request, we will be happy to inform you about the data stored about you. Please contact the person named under 1 f. or our data protection officer:

Dipl.-Ing. Jörg Hagen Königstraße 50a

30175 Hanover E-mail: info(at)jhcon.de

8. Use of My Art Registry

The photographer/artist assures that the low-res photographs (thumbnail) of all works of art uploaded by him/her are free of third party rights and that he/she may freely dispose of them. He/she also warrants that persons depicted or the owners of the rights to depicted works of fine or applied art, as well as the authors of images from which the depicted photographs/works of art were created by editing or redesigning, have given their consent to publication and exploitation in verifiable form. The photographer/artist shall indemnify Hahnemühle against all claims asserted against Hahnemühle by third parties on account of an infringement of their rights. The indemnification obligation shall also include the costs incurred by Hahnemühle in defending such claims. The indemnification obligation shall not apply if the photographer proves that the artist is not at fault.