TikTok privacy policy for the business presence of ROSE Bikes GmbH

Status: August 2023

Data protection is a top priority for us at ROSE Bikes. We know that the careful handling of your personal information is important to you. Your data will therefore be treated confidentially by us in strict compliance with the applicable data protection regulations.

Below we explain which data we use on our TikTok presence and which data is processed through the use of TikTok for Business. TikTok for Business is a platform for the creation and sharing of short videos and the placement of adverts through these short videos ("Ads"). We would like to point out that there has been massive criticism of the way TikTok works and its data protection practices.

We want you to understand how the services work and how we ensure the protection of your personal data, which is very important to us. We only use your personal data if we have your consent or legal permission to do so.

Table of contents

  1. General information about TikTok
  2. Contact details TikTok
  3. Contact details of the data protection officer
  4. Data processing at TikTokk
  5. Purposes and legal basis
  6. Categories of data
  7. Recipients of the data
  8. Data transfers to third countries
  9. Data retention period
  10. Rights of data subjects

I. General information about TikTok

The purposes and means of processing personal data when visiting our TikTok page https://www.tiktok.com/@rose_bikes?lang=de-DE are jointly determined by us, ROSE Bikes GmbH, Schersweide 4, 46395 Bocholt Germany (hereinafter: "ROSE Bikes" or "we") and TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter: "TikTok"). This results from the fact that, as the operator of the TikTok page, by setting up such a page, we give TikTok the opportunity to process personal data and place cookies on your computer or any other device as soon as you visit a TikTok page, regardless of whether you have a TikTok account.

Below you will find a description of how we and TikTok handle personal data when you visit a TikTok page. However, since we generally or to a large extent have no influence on the collection and processing of data by TikTok, we cannot provide any binding information at this time on the purposes and scope of the processing of your data by TikTok. However, we will monitor further developments in this regard and adapt this privacy policy accordingly if necessary.

We would like to point out that you use the TikTok page and its functions on your own responsibility. This applies in particular to the use of interactive functions (such as commenting, sharing, rating). TikTok assumes primary responsibility for the processing of the data. Below you will find a description of how we and TikTok handle personal data when you visit our TikTok account.

Legal information on the handling and processing activities of TikTok TT4B platform (= uploaded ad content, concerns the relationship between companies and TikTok and not customers/users and TikTok) can be found at: https://ads.tiktok.com/i18n/official/policy/privacy. Please note the following statement by TikTok:

“This Policy does not cover the processing of Information about your users and customers that (i) you provide to us (or we collect) via your use of TikTok Business Products; or that (ii) we receive via measurement partners integrated with your ad campaigns such as device identifiers, network identifiers, email addresses or phone numbers (“Ad Data”). Such processing is covered by the Privacy Policy of the product on which the advertising campaign is served (e.g. TikTok’s Privacy Policy).“ Further information on TikTok for Business Europe Privacy Policy can be found at: https://www.tiktokforbusinesseurope.com/de/privacy

Further information on TikTok Ads can be found at: https://ads.tiktok.com/help/article?aid=10000407, https://ads.tiktok.com/i18n/official/policy/business-products-terms und https://www.tiktok.com/legal/privacy-policy-eea?lang=de

You can find TikTok's cookie policy here: https://www.tiktok.com/legal/tiktok-website-cookies-policy?lang=de

II. Contact details TikTok

The primary controller for users from the European Economic Area and Switzerland is: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland

Another controller is: ROSE Bikes GmbH, Schersweide 4, 46395 Bocholt, Germany

III. Contact details of the data protection officer

You can contact the data protection officer of the primary controller TikTok at the following address: https://www.tiktok.com/legal/report/DPO

You can reach our data protection officer at DataCo GmbH, Nymphenburger Str. 86, 80636 Munich, Germany, datenschutz@dataguard.de

IV. Data processing at TikTok

    1. General information on data processing by TikTok

    We maintain online presences within social networks in order to communicate with interested and active users like you there and to inform you about products, events and news there. The purpose of our online presence is to make our information available in a target group-orientated and informative manner. To do this, it is necessary to be present on the relevant social media sites and provide the relevant information.

    When you visit our TikTok page (regardless of whether you are logged into your TikTok account or not), your browser transmits for technical reasons certain data to the web server for which TikTok is responsible. TikTok also uses "cookies". Cookies are small text files that are stored in the memory of your end device via your browser.

    The TikTok privacy policy, which forms the basis of this privacy policy, generally states

    • the categories of personal data that are processed when using TikTok applications,
    • the purposes for which this data is used,
    • the categories of recipients to whom this data is sent,
    • the information on the legal basis for the processing of this data
    • as well as information on how you can withdraw your consent to the processing of personal data,
    • information on how you can exercise your rights of access, rectification, portability and erasure against TikTok Technology Limited.

    2. Cookies by TikTok

    TikTok uses cookies and similar tracking technologies for the operation and provision of its services. Cookies are used, for example, to save the language settings, to ensure that the same video is not viewed more than once by the user, and for security reasons. TikTok also uses these technologies for marketing purposes. Further information on the use of cookies can be found in the cookie policy for the TikTok websites and in the cookie policy for the TikTok platform. Where required by law, TikTok will obtain your consent to the use of cookies separately.

V. Purposes and legal basis

How TikTok uses the data from visits to TikTok pages for its own purposes, to what extent activities on the TikTok page are assigned to individual users, how long TikTok stores this data and whether data from a visit to the TikTok page is passed on to third parties is not conclusively and clearly stated by TikTok and is not fully known to us. However, we will monitor further developments in this regard and adapt this privacy policy accordingly if necessary. The following information is based on information publicly provided by TikTok regarding the processing of personal data when using TikTok products. TikTok processes your data based on your consent. Otherwise, TikTok processes the data of users either on the basis of a contract (art. 6 para. 1 sentence 1 letter b GDPR), as a result of a balancing of interests (art. 6 para. 1 sentence 1 lit. f GDPR) or for the fulfilment of legal obligations (art. 6 para. 1 sentence 1 lit. c GDPR).

Our mission with the TikTok presence is to make company information available to the right/appropriate target groups. The use of social media is widespread in the EU. This participation rate is rising sharply. It should be noted that the increasing concentration in social media markets and the targeting of users may also increase the risks to the rights and freedoms of a significant number of individuals. For example, certain social media providers may be able to combine a greater volume and variety of personal data, either alone or in conjunction with other companies. This capability may mean that it is possible to offer more advanced targeting campaigns. We offer a wide range across all bike categories, which impress with the highest quality and fulfil all requirements in terms of design and technology. Our target group is primarily young people like you who enjoy cycling and can be reached precisely on TikTok.

We process your personal data on the basis that you click on our content and contact us. The legal basis for this is your consent pursuant to art. 6 para. 1 sentence 1 lit. a GDPR and our legitimate interest in accordance with art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest lies in responding to your enquiry or interacting with you in the context of social media marketing.

VI. Categories of data

The information that TikTok processes is categorised into data provided by you, automatically collected data and data from other sources:

1. Data provided by you

  • Profile information: e.g. your date of birth, your user name, your e-mail address and/or telephone number and your password. If further data is added to the profile, then also, for example, a biography or a profile photo.
  • User content: Content created by you or published via the platform, including photos, videos, audio recordings, live streams and comments, as well as the associated metadata (e.g. when, where and by whom the content was created). User content is collected by preloading at the time of creation, import or upload, regardless of whether you want to save or upload this user content, for example to recommend music based on the video. Content (such as text, images and videos) from your device's clipboard is also collected when you copy or paste content to or from the platform or exchange content between the platform and a third-party platform.
  • Direct messages: When you communicate with others via direct messages, the content of the message and the associated metadata are collected (e.g. the time at which the message was sent, received and/or read, as well as the participants in the communication). This is done to block spam, detect criminal offences and protect users.
  • Your contacts: If you choose to import your contacts, data will be collected from your device's phone book or your social media contacts. This data is used to help you make connections on the platform when you use the "Find friends" function and to suggest your account to others.
  • Purchase information: Payment card data or other payment data from third-party providers (such as PayPal) if payment is required. We also collect your transaction and purchase history.
  • Survey and advertising campaigns: Data you provide to TikTok when you choose to participate in surveys, promotions, contests, marketing campaigns or events.
  • Information when you contact us: When you contact TikTok, data is collected that you send to TikTok, such as proof of identity or age, feedback about your use of the services or data about possible violations of the terms of use, community guidelines or other provisions.

2. Automatically collected data

  • Technical details: Certain device and network connection data, including your device model, operating system, keystroke patterns or rhythms, IP address and system language; service-related, diagnostic and performance data, including crash reports and performance logs; you are automatically assigned a device ID and user ID when you use the platform; when you log in from multiple devices, data such as your device ID and user ID is used to identify your activity across devices to provide you with a seamless login experience and for security purposes.
  • Location: Approximate location based on your technical data (e.g. SIM card and IP address) to personalise your experience and perform diagnostics and troubleshooting. With your permission, TikTok can also collect precise location data (e.g. GPS).
  • Information on utilisation: Data is collected about how you use the platform's services, including data about the content you view, how long and how often you use the platform's services, how you interact with other users, your search history on the platform and your settings.
  • Content characteristics and properties: TikTok recognises and collects features and characteristics of the video and audio recordings that are part of your user content, e.g. by identifying objects and landscapes, the presence or position of a face or other body parts within an image and the text of the words spoken in your user content. This is done by TikTok, for example, for content moderation and to provide special effects (such as video filters and avatars) and subtitles.
  • Derived data: The data that TikTok has about you is used to infer your characteristics (such as age and gender) and interests. TikTok uses these inferences, for example, to keep the platform secure, to moderate content and, where permitted, to present you with personalised advertising based on your interests.
  • Cookies: TikTok uses cookies and similar tracking technologies for the operation and provision of its services. Cookies are used, for example, to save the language settings, to ensure that the same video is not viewed more than once by the user, and for security reasons. TikTok also uses these technologies for marketing purposes. Further information on the use of cookies can be found in the cookie policy for the TikTok websites and in the cookie policy for the TikTok platform. Where required by law, TikTok will obtain your consent to the use of cookies separately.

3. Data from other sources

  • Advertising, measurement and data partners: Advertising, measurement and data partners share data with TikTok such as mobile identifiers for advertising, hashed email addresses and event data about the actions you have taken on a website or app. Some of our advertisers and other partners allow TikTok to collect similar data directly from their website or app by integrating the TikTok Advertiser Tools (such as TikTok Pixel).
  • Data from third-party platforms: If you sign up for TikTok via a third-party platform (such as Facebook or Google), the third-party platform will share data such as your email address, user ID and public profile.
  • Integration partners: When you interact with a third-party service (e.g. apps, websites or third-party products) that integrates TikTok Developer Tools, TikTok receives the data necessary to provide you with features such as cross-service authentication or cross-posting. This happens, for example, when you log in to another service with your TikTok account or when you use the TikTok "Share" button on a third-party service to share content from the third-party service with TikTok.
  • Other: Other users or individuals may provide TikTok with information about you, for example, when you are mentioned in another user's content or direct messages, when a complaint or feedback is submitted by a third party, or when your contact information is submitted to us by another user through TikTok's "Find Friends" feature.

VII. Recipients of the data

In addition to us, the recipients of the data are:

  • Service providers that provide, support and develop services such as cloud hosting, content delivery, customer and technical support, content moderation, marketing, analytics and online paymentsPartners such as integration partners and third-party platforms (if selected by the user)
  • Partners such as integration partners and third-party platforms (if selected by the user)
  • TikTok group of companies
  • Other users and the public
  • Corporate transaction
  • Law enforcement agencies, authorities, copyright holders or other third parties

VIII. Data transfer to third countries

The app operator is based in the People's Republic of China, which has not been recognised as a country offering an adequate level of data protection. TikTok processes data within and outside the European Economic Area and bases its processing on adequacy decisions in accordance with art. 45 GDPR (for third countries for which the European Commission has an adequate level of data protection) or on standard contractual clauses in accordance with art. 46 para. 2 GDPR (in all other third countries for which there is no adequacy decision).

We do not transfer data to third countries. However, in the course of processing your personal data, we may pass on your personal data to other recipients. We only transfer your personal data to external recipients if you have given your consent or if this is permitted by law.

IX. Data retention period

In the TikTok Privacy Policy you will find information on the duration of the storage of personal data as well as information on the criteria for determining this duration.

collected. We will take reasonable steps to ensure that your personal data is only processed under the following conditions:

  1. For the duration that the data is used to provide you with a service
  2. As required by applicable law, contract or in view of our legal obligations
  3. Only for as long as is necessary for the purpose for which the data was collected, or longer if required by contract, applicable law, using appropriate safeguards.

If the data is no longer required for the fulfilment of contractual or legal obligations, it is regularly deleted, unless its – temporary – storage is still necessary, in particular for the fulfilment of legal storage periods of up to ten years (from the German Commercial Code, the German Fiscal Code and the German Money Laundering Act, among others).

X. Rights of data subjects

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

  1. Right to information
    If your personal data is processed, you have the right to obtain information from the controller about the data stored about you (art. 15 GDPR).
  2. Right to rectification
    If inaccurate personal data is processed, you have the right to rectification (art. 16 GDPR).
  3. Right to erasure or restriction and objection
    If the legal requirements are met, you may request the deletion or restriction of the processing and object to the processing (art. 17, 18 and 21 GDPR).
  4. Right to instruction
    If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged pursuant to art. 19 GDPR, to communicate any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
  5. Right to data portability
    If you have consented to the data processing or if there is a contract for data processing and the data processing is carried out with the help of automated procedures, you may have a right to data portability (art. 20 GDPR).
  6. Right of objection
    In accordance with art. 21 GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on art. 6 para. 1 sentence 1 lit. e or f GDPR; this also applies to profiling.
  7. Right to revoke the declaration of consent under data protection law
    If you have consented to the processing by the controller by means of a corresponding declaration, you can revoke your consent at any time for the future. The legality of the data processing carried out on the basis of consent until revocation is not affected by this.
  8. Automated decision-making in individual cases including profiling
    In accordance with art. 22 GDPR, you have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
  9. Right of appeal to a supervisory authority
    Furthermore, there is a right of appeal to a supervisory authority (art. 77 GDPR).