Table of Contents
Introduction and Overview
We have prepared this Privacy Policy (Version 03/17/2026-112279866) to provide you with information in accordance with the requirements of the
General Data Protection Regulation (EU) 2016/679 and applicable national laws, to explain what personal data (hereinafter “data”) we, as the data controller—and the data processors we engage (e.g., service providers)—process, will process in the future, and what legal options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is intended to explain the most important points to you as simply and transparently as possible. Where it promotes transparency, technical
Terms Explained in an Easy-to-Understand Way, links to additional information are provided, and
Graphics We use this to clearly and simply explain that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, unclear, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.
If you still have questions, please contact the responsible body listed below or in the legal notice, follow the provided links, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.
Scope of Application
This Privacy Policy applies to all personal data processed by our company and to all personal data processed by companies we have contracted (data processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:
- All online platforms (websites, online stores) that we operate
- Social Media Presence and Email Communication
- Mobile apps for smartphones and other devices
In short: This Privacy Policy applies to all areas in which personal data is processed in a structured manner within the company through the channels listed above. Should we enter into a legal relationship with you outside of these channels, we will inform you separately if necessary.
Legal Basis
In the following Privacy Policy, we provide you with transparent information regarding the legal principles and regulations—that is, the legal bases under the General Data Protection Regulation—that enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, access this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at
https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 Read more.We process your data only if at least one of the following conditions applies:
- Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, if we enter into a purchase agreement with you, we need certain personal information in advance.
- Legal Obligation (Article 6(1)(c) of the GDPR): We process your data when we are subject to a legal obligation to do so. For example, we are legally required to retain invoices for accounting purposes. These invoices generally contain personal data.
- Legitimate Interests (Article 6(1)(f) of the GDPR): In cases where legitimate interests are at stake that do not infringe upon your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.
Other conditions, such as the collection of data in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate section.In addition to the EU Regulation, national laws also apply:
- In Austria This is the Federal Act on the Protection of Individuals with Regard to the Processing of Personal Data (Data Protection Act), in short DSG.
- In Germany Does that apply? Federal Data Protection Act, in short BDSG.
If any additional regional or national laws apply, we will provide you with information about them in the following sections.
Contact Information for the Data Controller
If you have any questions regarding data protection or the processing of personal data, please find below the contact information for the data controller as specified in Article 4(7) of the EU General Data Protection Regulation (GDPR):
ambiCON GmbH
Suad Ferhatbegovic
Dresdner Strasse 47, 3rd Floor, A-1200 Vienna, Austria
Authorized Representative: Suad Ferhatbegovic
Email:
office@ambicon.at
Phone:
+43 (1) 908 19 99
Legal Notice:
https://www.ambicon.at/impressum/Retention period
It is our general policy to store personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.If you request the deletion of your data or revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.We provide further information below regarding the specific duration of each data processing activity, to the extent that we have additional details available.
Rights Under the General Data Protection Regulation
In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed in a fair and transparent manner:
- Under Article 15 of the GDPR, you have the right to know whether we process any of your data. If we do, you have the right to receive a copy of the data and to obtain the following information:
- the purpose for which we process the data;
- the categories, i.e., the types of data that are processed;
- who receives this data, and if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
- that you can file a complaint with a supervisory authority (links to these authorities are provided below);
- the source of the data, if we did not collect it from you;
- whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
- Under Article 16 of the GDPR, you have the right to have your data corrected, which means that we must correct any data if you find errors.
- Under Article 17 of the GDPR, you have the right to erasure („right to be forgotten“), which specifically means that you may request the erasure of your data.
- Under Article 18 of the GDPR, you have the right to restrict processing, which means that we may only store the data but may not use it further.
- Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
- Under Article 21 of the GDPR, you have the right to object, which, once exercised, will result in a change to the processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then review as soon as possible whether we can legally comply with this objection.
- If your data is used for direct marketing purposes, you may object to this type of data processing at any time. We may no longer use your data for direct marketing after that.
- If data is used for profiling, you may object to this type of data processing at any time. We may no longer use your data for profiling after that.
- Under Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (such as profiling).
- Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may file a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights—don’t hesitate to contact the data controller listed above!If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at
https://www.dsb.gv.at/ find. In Germany, there is a data protection officer for each federal state. For more information, you can contact the
Federal Commissioner for Data Protection and Freedom of Information (BfDI) contact. The following local data protection authority has jurisdiction over our company:
Austrian Data Protection Authority
Director: Dr. Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Phone number: +43 1 52 152-0
Email address: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/Data Transfer to Third Countries
We transfer or process data to countries outside the scope of the GDPR (third countries) only if you consent to such processing or if there is another legal basis for doing so. This applies in particular when the processing is required by law or necessary to fulfill a contractual relationship, and in any case only to the extent that it is generally permitted. In most cases, your consent is the primary reason we have data processed in third countries. The processing of personal data in third countries such as the United States, where many software providers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the U.S. currently exists only if a U.S. company, that processes personal data of EU citizens in the U.S. is an active participant in the EU-U.S. Data Privacy Framework. For more information, please visit:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_enData processing by U.S. services that are not active participants in the EU-U.S. Data Privacy Framework may result in data being processed and stored without being anonymized, where applicable. Furthermore, U.S. government authorities may access specific data, where applicable. In addition, collected data may be linked to data from other services of the same provider, provided you have a corresponding user account. Whenever possible, we try to use server locations within the EU, if such options are available.
We provide more detailed information about data transfers to third countries, where applicable, in the relevant sections of this Privacy Policy.
Data Processing Security
To protect personal data, we have implemented both technical and organizational measures. Whenever possible, we encrypt or pseudonymize personal data. In this way, we make it as difficult as possible—within the limits of our capabilities—for third parties to infer personal information from our data.Article 25 of the GDPR refers to “data protection through technology design and privacy-friendly default settings,” meaning that security must always be a priority—whether in software (e.g., forms) or hardware (e.g., access to the server room)—and appropriate measures must be implemented. In the following, we will discuss specific measures where necessary.
TLS Encryption with HTTPS
TLS, encryption, and HTTPS sound very technical—and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the Internet in a way that is secure against eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secure—no one can „eavesdrop.“In doing so, we have introduced an additional layer of security and comply with data protection through technology design (
Article 25(1) of the GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.
You can recognize that this data transmission security measure is in use by the small padlock icon

in the upper-left corner of the browser, to the left of the web address (e.g., examplepage.de) and the use of the https scheme (instead of http) as part of our web address.
If you’d like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.
Communication
| Communication Summary
👥 Data Subjects: Anyone who communicates with us by phone, email, or online form
📓 Data Processed: e.g., phone number, name, email address, form data entered. You can find more details under the respective contact method
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Retention period: Duration of the business transaction and as required by law
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests) |
When you contact us and communicate by phone, email, or online form, we may process personal data.The data is processed to handle and address your inquiry and the related business transaction. The data is stored for as long as necessary or as required by law.
Affected Individuals
All of the processes mentioned above affect anyone who contacts us through the communication channels we provide.
Phone
When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business matter has been resolved and legal requirements permit it.
Email
When you communicate with us via email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and on the email server. The data will be deleted as soon as the business transaction is complete and legal requirements permit.
Online Forms
When you communicate with us via the online form, data is stored on our web server and, if necessary, forwarded to one of our email addresses. The data is deleted as soon as the business transaction is complete and legal requirements permit.
Legal Basis
The processing of data is based on the following legal grounds:
- Art. 6(1)(a) of the GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
- Art. 6(1)(b) of the GDPR (Contract): It is necessary for the performance of a contract with you or a processor, such as a telephone service provider, or we need to process the data for pre-contractual activities, such as preparing a quote;
- Art. 6(1)(f) GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical systems—such as email programs, Exchange servers, and mobile network providers—are necessary to ensure efficient communication.
Data Processing Agreement (DPA)
In this section, we’d like to explain what a data processing agreement is and why it’s needed. Since the term “data processing agreement” is quite a tongue-twister, we’ll often use the acronym DPA throughout this text. Like most companies, we do not operate alone but also use the services of other companies or individuals. By involving various companies or service providers, we may need to share personal data for processing. These partners then act as data processors, with whom we enter into a contract known as a Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be governed by the DPA.
Who are data processors?
As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. More specifically, and according to the GDPR definition: any natural or legal person, public authority, agency, or other body that processes personal data on our behalf is considered a data processor. Processors can therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.To help clarify these terms, here is an overview of the three roles under the GDPR:
Affected person (You, as a customer or prospective customer) →
Person in Charge (we, as a company and client) →
Data Processor (Service providers such as web hosting providers or cloud service providers)
Contents of a Data Processing Agreement
As mentioned above, we have entered into a Data Processing Agreement (DPA) with our partners, who act as data processors. Above all, this agreement stipulates that the data processor shall process the data exclusively in accordance with the GDPR. The agreement must be concluded in writing; however, in this context, an electronic agreement is also considered „in writing.“ The processing of personal data takes place only on the basis of this agreement. The agreement must include the following:
- Commitment to Us as the Data Controller
- Obligations and Rights of the Data Controller
- Categories of Data Subjects
- Type of Personal Data
- Nature and Purpose of Data Processing
- Purpose and Duration of Data Processing
- Location of Data Processing
Furthermore, the contract sets forth all of the data processor’s obligations. The most important obligations are:
- Measures to ensure data security
- to take all necessary technical and organizational measures to protect the rights of the data subject
- to maintain a data processing register
- to cooperate with the data protection supervisory authority at its request
- to conduct a risk analysis with respect to the personal data received
- Sub-processors may only be engaged with the written authorization of the controller
You can see what such an AVV looks like, for example, at
https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html View. A sample contract is presented here.
Cookies
| Cookies Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Depends on the specific cookie. For more details, see below or contact the software provider that sets the cookie.
📓 Data processed: Depends on the specific cookie used. More details can be found below or from the software provider that sets the cookie.
📅 Storage period: Depends on the specific cookie; may vary from hours to years
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.Whenever you browse the Internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.One thing is undeniable: cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, as there are other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically stored in the cookie folder—essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this „user-specific“ information back to our site. Thanks to cookies, our website knows who you are and provides you with the settings you’re accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.The following diagram illustrates a possible interaction between a web browser—such as Chrome—and the web server. In this scenario, the web browser requests a website and receives a cookie from the server, which the browser reuses as soon as another page is requested.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other „malware.“ Cookies also cannot access information on your computer.Here is an example of what cookie data might look like:
Name: _ga
Value: GA1.2.1326744211.152112279866-9
Purpose: Distinguishing Between Website Visitors
Expiration Date: After 2 yearsA browser should be able to support these minimum sizes:
- At least 4,096 bytes per cookie
- At least 50 cookies per domain
- At least 3,000 cookies in total
What types of cookies are there?
The specific cookies we use depend on the services we employ and are explained in the following sections of this Privacy Policy. At this point, we would like to briefly discuss the different types of HTTP cookies.There are four types of cookies:
Essential Cookies
These cookies are necessary to ensure the website's basic functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues browsing other pages, and only proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.
Functional Cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the website's loading time and performance across different browsers.
Targeted Cookies
These cookies improve the user experience. For example, they save locations you've entered, font sizes, and form data.
Advertising Cookies
These cookies are also called targeting cookies. They are used to deliver personalized ads to users. This can be very convenient, but it can also be very annoying.Usually, when you visit a website for the first time, you’ll be asked which of these types of cookies you’d like to allow. And, of course, this decision is also stored in a cookie.If you’d like to learn more about cookies and don’t mind reading technical documentation, we recommend
https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”.
Purpose of Processing via Cookies
The purpose ultimately depends on the specific cookie. You can find more details below or by contacting the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are small tools that help with many different tasks. Unfortunately, it is not possible to generalize about what data is stored in cookies, but we will inform you about the data that is processed or stored in the following privacy policy.
Cookie Retention Period
The retention period depends on the specific cookie and is specified in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.You also have control over the retention period. You can manually delete all cookies at any time via your browser (see also “Right to Object” below). Furthermore, cookies that are based on your consent will be deleted at the latest upon revocation of your consent, although the lawfulness of their storage until that time remains unaffected.
Right to Object – How Can I Delete Cookies?
You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only some cookies. For example, you can block third-party cookies but allow all other cookies.If you want to see which cookies have been stored in your browser, or if you want to change or delete your cookie settings, you can find these options in your browser settings:
Chrome: Delete, Enable, and Manage Cookies in ChromeSafari: Managing Cookies and Website Data with SafariFirefox: Clear cookies to remove data that websites have stored on your computerInternet Explorer: Deleting and Managing CookiesMicrosoft Edge: Deleting and Managing CookiesIf you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. The best approach is to search for instructions on Google using the search terms “delete cookies Chrome” or “disable cookies Chrome” if you’re using the Chrome browser.
Legal Basis
The so-called „Cookie Directive“ has been in effect since 2009. It stipulates that the storage of cookies is a
Consent (Article 6(1)(a) of the GDPR) requires you to do so. However, reactions to these guidelines still vary widely among EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive was not transposed into national law. Instead, this directive was largely implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.For strictly necessary cookies, even in the absence of consent, the following apply:
legitimate interests (Article 6(1)(f) of the GDPR), which are, in most cases, of a business nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary to achieve this.To the extent that cookies other than those that are strictly necessary are used, this occurs only with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.The following sections provide more detailed information about the use of cookies, to the extent that the software used employs cookies.
Application Information
| Application Information Summary
👥 Data Subjects: Users who apply for a job with us
🤝 Purpose: To process a job application
📓 Data processed: Name, address, contact information, email address, phone number, proof of qualifications (transcripts), and, if applicable, special categories of data.
📅 Retention period: If the application is successful, until the end of the employment relationship. Otherwise, the data will be deleted after the application process or stored for a certain period of time with your consent.
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), legitimate interest (Art. 6(1)(f) GDPR), Art. 6(1)(b) GDPR (contract), Art. 9(2)(a) GDPR (processing of special categories of data) |
What is application data?
You can apply for a job at our company by email, through our online form, or via a recruiting tool. All data we receive and process from you as part of an application is considered application data. In doing so, you always provide personal data such as your name, date of birth, address, and phone number.
Why do we process job application data?
We process your data so that we can conduct a proper selection process for the advertised position. In addition, we’d be happy to keep your application materials in our applicant database. This is because it often happens that, for a variety of reasons, a collaboration for the advertised position doesn’t work out, but we’re impressed by you and your application and can definitely see a future collaboration with you. If you give us your consent to do so, we will archive your documents so that we can easily contact you for future opportunities within our company.We guarantee that we will handle your data with the utmost care and will always process it strictly within the legal framework. Even within our company, your data will only be shared with individuals directly involved in your application. In short: your data is safe with us!
What data is processed?
For example, if you apply for a position with us via email, we will, of course, receive personal data as mentioned above. Even your email address is considered personal data. However, during the application process, we only process the data that is relevant to our decision on whether or not to welcome you to our team.Exactly which data is processed depends primarily on the job posting. In most cases, however, it includes your name, date of birth, contact information, and proof of qualifications. If you submit your application via an online form, the data is transmitted to us in encrypted form. If you send us your application via email, this encryption does not take place. We therefore cannot assume any responsibility for the transmission process. However, once the data is on our servers, we are responsible for the lawful handling of your data.During the application process, in addition to the data mentioned above, we may also request information about your health or ethnic origin so that both we and you can exercise our rights under labor law, social security, and social protection, while also fulfilling our corresponding obligations. This data constitutes special categories of data.Here is a list of possible data that we receive from you and process:
- Name
- Contact Information
- Email address
- Phone number
- Date of Birth
- Information contained in the cover letter and resume
- Proof of qualifications (e.g., certificates)
- Special categories of data (e.g., ethnic origin, health data, religious beliefs)
- Usage data (websites visited, access data, etc.)
- Metadata (IP address, device information)
How long is the data stored?
If we hire you as a team member at our company, your data will be processed for the purposes of the employment relationship and retained by us at least until the employment relationship ends. All application documents will then be placed in your employee file.If we do not offer you the position, you decline our offer, or you withdraw your application, we may retain your data for up to 6 months after the conclusion of the application process based on our legitimate interest (Art. 6(1)(f) GDPR). After that, both your electronic data and all data from physical application documents will be completely deleted or destroyed. We retain your data, for example, so that we can still answer any follow-up questions or, in the event of a legal dispute, provide evidence regarding the application. If a legal dispute arises and we may still need the data after the 6-month period has expired, we will not delete the data until there is no longer any reason to retain it. If there are statutory retention requirements to be met, we must generally store the data for longer than 6 months.Furthermore, we may retain your data for a longer period if you have given us specific consent to do so. We do this, for example, if we can envision working with you in the future. In that case, it is helpful to have your data on file so that we can easily contact you. In this case, the data will be added to our applicant pool. Of course, you can revoke your consent to the extended retention of your data at any time. If you do not revoke your consent and do not provide new consent, your data will be deleted no later than 2 years from the date of consent.
Legal Basis
The legal bases for the processing of your data are Article 6(1)(a) of the GDPR (consent), Article 6(1)(b) of the GDPR (contract or pre-contractual measures), Article 6(1)(f) of the GDPR (legitimate interests), and Article 9(2)(a) of the GDPR (processing of special categories of data).If we add you to our applicant tracking system, this is done on the basis of your consent (Article 6(1)(a) of the GDPR). Please note that your inclusion in our applicant pool is voluntary, has no impact on the application process, and you may withdraw your consent at any time. The lawfulness of the processing up to the time of withdrawal remains unaffected.In cases involving the protection of vital interests, data processing is carried out in accordance with Article 9(2)(c) of the GDPR. For the purposes of healthcare, occupational medicine, medical diagnostics, care or treatment in the health or social services sector, or the administration of systems and services in the health or social services sector, the processing of personal data is carried out in accordance with Article 9(2)(h) of the GDPR. If you voluntarily provide special categories of data, the processing is based on Article 9(2)(a) of the GDPR.
Customer Data
| Customer Data Summary
👥 Data Subjects: Customers, business partners, and contractual partners
🤝 Purpose: Provision of services agreed upon in a contract or during pre-contractual negotiations, including related communication
📓 Data Processed: Name, address, contact information, email address, phone number, payment information (such as invoices and bank details), contract details (such as the term and subject matter of the contract), IP address, order details
📅 Retention period: The data will be deleted as soon as it is no longer necessary for the fulfillment of our business purposes and there is no legal obligation to retain it.
⚖️ Legal basis: Legitimate interest (Art. 6(1)(f) GDPR), Contract (Art. 6(1)(b) GDPR) |
What is customer data?
In order to provide our services and fulfill our contractual obligations, we also process data from our customers and business partners. This data always includes personal information. Customer data refers to all information processed on the basis of a contractual or pre-contractual relationship in order to provide the services we offer. Customer data, therefore, refers to all the information we collect and process about our customers.
Why do we process customer data?
There are many reasons why we collect and process customer data. The most important one is that we simply need various types of data to provide our services. Sometimes your email address is all we need, but if you purchase a product or service, for example, we also need information such as your name, address, bank details, or contract information. We also use this data for marketing and sales optimization so that we can improve our overall service for our customers. Another important aspect is our customer service, which is always a top priority for us. We want you to be able to contact us at any time with questions about our offerings, and for that, we need at least your email address.
What data is processed?
At this point, we can only describe the specific data we store in terms of categories. This is because it always depends on the services you receive from us. In some cases, you simply provide us with your email address so that we can, for example, contact you or answer your questions. In other cases, you purchase a product or service from us, and for that we need significantly more information, such as your contact information, payment details, and contract information.Here is a list of possible data we receive from you and process:
- Name
- Contact Information
- Email address
- Phone number
- Date of Birth
- Payment information (invoices, bank information, payment history, etc.)
- Contract Details (Term, Content)
- Usage data (websites visited, access data, etc.)
- Metadata (IP address, device information)
How long is the data stored?
As soon as we no longer need the customer data to fulfill our contractual obligations and for our purposes, and the data is also no longer required for any potential warranty or liability obligations, we delete the relevant customer data. This is the case, for example, when a business contract ends. After that, the statute of limitations is generally 3 years, although longer periods are possible in individual cases. Of course, we also comply with statutory retention requirements. Your customer data will definitely not be shared with third parties unless you have explicitly given your consent.
Legal Basis
The legal bases for the processing of your data are Article 6(1)(a) of the GDPR (consent), Article 6(1)(b) of the GDPR (contract or precontractual measures), Article 6(1)(f) of the GDPR (legitimate interests), and in specific cases (e.g., medical services), Article 9(2)(a) of the GDPR (processing of special categories of data).In cases involving the protection of vital interests, data processing is carried out in accordance with Article 9(2)(c) of the GDPR. For the purposes of healthcare, occupational medicine, medical diagnostics, care or treatment in the health or social services sector, or the administration of systems and services in the health or social services sector, the processing of personal data is carried out in accordance with Article 9(2)(h) of the GDPR. If you voluntarily provide special categories of data, the processing is based on Article 9(2)(a) of the GDPR.
Registration
| Registration Summary
👥 People affected: All individuals who register, create an account, log in, and use the account.
📓 Data processed: Email address, name, password, and other data collected during registration, login, and account use.
🤝 Purpose: To provide our services. To communicate with customers regarding the services.
📅 Retention period: SAs long as the company account associated with the texts remains active, and generally for 3 years thereafter.
⚖️ Legal basis: Art. 6(1)(b) of the GDPR (contract), Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests) |
When you register with us, we may process personal data if you enter personally identifiable information or if data such as your IP address is collected during the processing. You can read more below about what we mean by the rather cumbersome term “personal data.”.Please enter only the information we require for registration and for which you have a third party’s authorization, if you are registering on behalf of a third party. If possible, use a strong password that you do not use anywhere else and an email address that you check regularly.Below, we provide you with information about the specific nature of our data processing, because we want you to feel comfortable with us!What is registration?
When you register, we collect certain information from you, which allows you to easily log in online later and use your account with us. Having an account with us has the advantage that you don’t have to re-enter all your information every time. This saves time and effort and ultimately helps prevent errors in the delivery of our services.Why do we process personal data?
In short, we process personal data to enable users to create and use an account with us.
If we didn't do that, you'd have to enter all the data every time, wait for us to approve it, and then enter everything all over again. Neither we nor many, many of our customers would be very happy about that. How would you feel about that?What data is processed?
All data that you provided during registration, enter when logging in, or enter when managing your data in your account.During registration, we process the following types of data: - First Name
- Last Name
- Email address
- Company Name
- Street + House Number
- Place of Residence
- ZIP Code
- Country
When you sign up, we process the data you enter during registration—such as your username and password—as well as data collected in the background, such as device information and IP addresses.When you use your account, we process data that you enter while using the account and that is generated in connection with your use of our services.Retention period
We store the data you provide at least for as long as the account associated with that data remains active and in use with us, for as long as contractual obligations between us remain in effect, and, if the contract ends, until the respective claims arising from it become time-barred. In addition, we store your data for as long as and to the extent that we are subject to legal obligations to do so. After that, we retain accounting documents related to the contract (invoices, contract documents, account statements, etc.) as well as other relevant business records for the period required by law (usually several years).
Right to Object
Have you registered, entered your data, and now wish to revoke your consent to the processing of your data? No problem. As you can read above, under the General Data Protection Regulation, your rights remain in effect during and after registration, sign-up, or the creation of an account with us. Please contact the Data Protection Officer listed above to exercise your rights. If you already have an account with us, you can easily view and manage your data and text directly in your account.Legal Basis
By completing the registration process, you are entering into a pre-contractual relationship with us to conclude a user agreement for our platform (although this does not automatically result in an obligation to pay). SYou invest time in entering data and registering, and we provide you with our services once you have logged into our system and granted you access to your customer account. In addition, we fulfill our contractual obligations. Finally, we must keep registered users informed of important changes via email. Thus, Article 6(1)(b) of the GDPR (implementation of pre-contractual measures, performance of a contract) applies.Where applicable, we may also obtain your consent, e.g., if you voluntarily provide more data than is strictly necessary or if we are permitted to send you advertising. Article 6(1)(a) of the GDPR (consent) therefore applies.We also have a legitimate interest in knowing who we are dealing with so that we can contact them in certain cases. Furthermore, we need to know who is using our services and whether they are being used in accordance with our Terms of Use; therefore, Art. 6(1)(f) GDPR (Legitimate Interests) applies.Note: Users must check the following sections (as applicable):
Registration Using Your Real NameSince we need to know who we are dealing with in our business operations, registration is only possible using your real name (real name) and not pseudonyms.Registration Using PseudonymsYou may use a pseudonym when registering, which means you do not have to register with us using your real name. This ensures that we cannot process your name. Storage of the IP AddressDuring the registration, login, and account usage processes, we store the IP address in the background for security reasons so that we can verify legitimate use.Public ProfileUser profiles are publicly visible, meaning that parts of the profile can be viewed online even without entering a username and password.Two-Factor Authentication (2FA)Two-factor authentication (2FA) provides additional security during login, as it prevents you from logging in without a smartphone, for example. This technical measure to secure your account protects you from data loss or unauthorized access, even if your username and password were known. You can find out which 2FA method is used during registration, when logging in, and within your account itself.Web Hosting Introduction
| Web Hosting Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Professional website hosting and ensuring website operation
📓 Data Processed: IP address, time of website visit, browser used, and other data. More details can be found below or with the respective web hosting provider.
📅 Retention period: Depends on the respective provider, but generally 2 weeks
⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate Interests) |
What is web hosting?
When you visit websites these days, certain information—including personal data—is automatically generated and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only for valid reasons. By “website,” we mean the entirety of all web pages on a domain—that is, everything from the home page to the very last subpage (like this one). By “domain,” we mean, for example, example.de or sampleexample.com.If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You’re probably familiar with some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as browsers or web browsers.To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and resource-intensive task, which is why it’s usually handled by professional providers. These providers offer web hosting and ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!When the browser on your computer (desktop, laptop, tablet, or smartphone) establishes a connection and during the transfer of data to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the Internet, and the hosting provider.

Why do we process personal data?
The purposes of data processing are:
- Professional website hosting and ensuring smooth operation
- to maintain operational and IT security
- Anonymous analysis of user behavior to improve our services and, if necessary, for law enforcement or the pursuit of legal claims
What data is processed?
Even as you are visiting our website right now, our web server—the computer on which this website is hosted—typically automatically stores data such as
- the full web address (URL) of the webpage that was accessed
- Browser and browser version (e.g., Chrome 87)
- the operating system used (e.g., Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g.,. https://www.beispielquellsite.de/vondabinichgekommen/)
- the hostname and IP address of the device from which the request is being made (e.g., COMPUTERNAME and 194.23.43.121)
- Date and Time
- in files known as web server log files
How long is data stored?
As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that government authorities may access this data in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that hosts our website on special computers (servers)), but we will not share your information without your consent!
Legal Basis
The lawfulness of processing personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests), as the use of professional hosting services from a provider is necessary to present the company on the Internet in a secure and user-friendly manner and, if necessary, to be able to investigate attacks and claims arising therefrom.As a rule, there is a contract between us and the hosting provider regarding data processing in accordance with Article 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.
Hostinger Privacy Policy
We use Hostinger, a web hosting provider, for our website.You can learn more about the data processed through the use of Hostinger in the privacy policy at
https://www.hostinger.com/at/legal/datenschutz-bestimmungen.
Introduction to Web Analytics
| Web Analytics Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimize the website.
📓 Data Processed: Access statistics, which include data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. You can find more details about this in the documentation for the respective web analytics tool used.
📅 Retention period: Depends on the web analytics tool used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Web Analytics?
We use software on our website to analyze the behavior of website visitors, commonly referred to as web analytics. This process involves the collection of data, which is stored, managed, and processed by the respective analytics tool provider (also known as a tracking tool). This data is used to generate analyses of user behavior on our website, which are then made available to us as the website operator. In addition, most tools offer various testing options. For example, we can test which offers or content are most popular with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles may be created and the data stored in cookies.
Why do we use web analytics?
With our website, we have a clear goal in mind: we want to provide the best online experience in our industry. To achieve this goal, we aim to offer the best and most engaging content while also ensuring that you feel completely at ease on our website. Using web analytics tools, we can take a closer look at the behavior of our website visitors and then improve our website for both you and us accordingly. For example, we can determine the average age of our visitors, where they come from, when our website receives the most traffic, and which content or products are particularly popular. All of this information helps us optimize the website and tailor it as closely as possible to your needs, interests, and preferences.
What data is processed?
Exactly which data is stored depends, of course, on the analytics tools used. However, as a general rule, the data stored includes, for example, what content you view on our website, which buttons or links you click, when you visit a page, which browser you use, and which device (PC, tablet, smartphone, etc.) you use to visit the website, or which computer system you use. If you have consented to the collection of location data, this information may also be processed by the web analytics tool provider.In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are personal data. However, your IP address is generally stored in a pseudonymized form (i.e., in an unrecognizable and truncated form). For the purposes of testing, web analytics, and web optimization, no direct data—such as your name, age, address, or email address—is stored. All such data, if collected, is stored in a pseudonymized form. This ensures that you cannot be identified as an individual.The following example schematically illustrates how Google Analytics works as an example of client-based web tracking using JavaScript code.

How long the data is stored depends on the provider. Some cookies store data for only a few minutes or until you leave the website, while others can store data for several years.
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be extended.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.
Legal Basis
The use of web analytics requires your consent, which we have obtained through our cookie pop-up. According to
Art. 6(1)(a) of the GDPR (Consent) This constitutes the legal basis for the processing of personal data, as may occur when such data is collected by web analytics tools.In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. With the help of web analytics, we detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is
Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools if you have given your consent.Since web analytics tools use cookies, we also recommend that you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.Information on specific web analytics tools—if available—can be found in the following sections.
Google Analytics Privacy Policy
| Google Analytics Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimize the website.
📓 Processed Data: Access statistics, which include data such as visitor locations, device information, duration and time of access, navigation behavior, and click behavior. You can find more details below in this privacy policy.
📅 Retention period: customizable; by default, Google Analytics 4 stores data for 14 months
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Google Analytics?
We use the Google Analytics tracking tool, specifically Google Analytics 4 (GA4), provided by the U.S. company Google Inc., on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your activities on our website. By combining various technologies such as cookies, device IDs, and login information, you as a user can be identified across different devices. This allows your activities to be analyzed across platforms.For example, when you click on a link, this event is stored in a cookie and sent to Google Analytics. Using the reports we receive from Google Analytics, we can better tailor our website and our service to your needs. Below, we’ll discuss the tracking tool in more detail and, most importantly, explain what data is processed and how you can prevent this.Google Analytics is a tracking tool used to analyze traffic on our website. These measurements and analyses are based on a pseudonymous user identification number. This number does not contain any personal data such as a name or address; rather, it is used to associate events with a specific device. GA4 uses an event-based model that captures detailed information on user interactions, such as page views, clicks, scrolling, and conversion events. In addition, various machine learning functions have been built into GA4 to better understand user behavior and certain trends. GA4 relies on modeling through machine learning functions. This means that, based on the collected data, missing data can be extrapolated to optimize analysis and enable forecasting.For Google Analytics to function, a tracking code is embedded in our website’s code. When you visit our website, this code records various events that you perform on our website. With GA4’s event-based data model, we as website operators can define and track specific events to analyze user interactions. This allows us to track not only general information such as clicks or page views but also specific events that are important to our business. Such specific events can include, for example, submitting a contact form or purchasing a product.As soon as you leave our website, this data is sent to the Google Analytics servers and stored there.Google processes the data, and we receive reports on your user behavior. These reports may include, among others, the following:
- Target Audience Reports: Target audience reports help us get to know our users better and understand more precisely who is interested in our service.
- Ad Reports: Ad reports make it easier for us to analyze and improve our online advertising.
- Acquisition Reports: Acquisition reports provide us with helpful information on how we can get more people interested in our service.
- Behavioral Reports: These reports tell us how you interact with our website. We can track the path you take on our site and which links you click.
- Conversion Reports: A conversion is a process in which you take a desired action in response to a marketing message. For example, when you go from being a casual website visitor to a buyer or newsletter subscriber. These reports help us learn more about how our marketing efforts are resonating with you. Our goal is to increase our conversion rate.
- Real-time reports: Here, we always find out immediately what's happening on our website. For example, we can see how many users are currently reading this text.
In addition to the analysis reports mentioned above, Google Analytics 4 also offers the following features, among others:
- Event-based data model: This model tracks very specific events that can occur on our website. For example, playing a video, purchasing a product, or signing up for our newsletter.
- Advanced analytics features: These features allow us to better understand your behavior on our website or certain general trends. For example, we can segment user groups, conduct comparative analyses of target audiences, or track your journey or path on our website.
- Predictive modeling: Based on collected data, machine learning can be used to extrapolate missing data to predict future events and trends. This can help us develop better marketing strategies.
- Cross-Platform Analysis: Data can be collected and analyzed from both websites and apps. This allows us to analyze user behavior across platforms, provided, of course, that you have consented to the processing of your data.
Why do we use Google Analytics on our website?
Our goal with this website is clear: We want to offer you the best possible service. The statistics and data from Google Analytics help us achieve this goal.The statistically analyzed data gives us a clear picture of our website’s strengths and weaknesses. On the one hand, this allows us to optimize our site so that interested people can find it more easily on Google. On the other hand, the data helps us better understand you as a visitor. We therefore know exactly what we need to improve on our website to offer you the best possible service. The data also helps us tailor our advertising and marketing efforts to be more personalized and cost-effective. After all, it only makes sense to showcase our products and services to people who are interested in them.
What data does Google Analytics store?
Google Analytics uses a tracking code to generate a random, unique ID that is linked to your browser cookie. This allows Google Analytics to recognize you as a new user and assign you a user ID. The next time you visit our site, you will be recognized as a „returning“ user. All collected data is stored together with this user ID. This is what makes it possible to analyze pseudonymous user profiles.To analyze our website using Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is set by default. Depending on the property used, data is stored for varying lengths of time.Through identifiers such as cookies, app instance IDs, user IDs, or custom event parameters, your interactions—provided you have given your consent—are measured across platforms. Interactions include all types of actions you perform on our website. If you also use other Google systems (such as a Google Account), data generated via Google Analytics may be linked to third-party cookies. Google does not share Google Analytics data unless we, as the website operator, authorize it. Exceptions may occur if required by law.According to Google, IP addresses are not logged or stored in Google Analytics 4. However, Google uses IP address data to derive location information and deletes it immediately afterward. All IP addresses collected from users in the EU are therefore deleted before the data is stored in a data center or on a server.Since Google Analytics 4 focuses on event-based data, the tool uses significantly fewer cookies compared to earlier versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies used by GA4. These include, for example:
Name: _ga
Value: 2.1326744211.152112279866-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Its primary purpose is to distinguish between website visitors.
Expiration Date: after 2 years
Name: _gid
Value: 2.1687193234.152112279866-1
Purpose: The cookie is also used to distinguish between website visitors
Expiration Date: after 24 hours
Name: _gat_gtag_UA_
Value: 1
Purpose: Used to reduce the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie is named _dc_gtm_.
Expiration Date: after 1 minute
Note: This list is not exhaustive, as Google frequently changes the types of cookies it uses. One of GA4’s goals is to improve data protection. Therefore, the tool offers several options for controlling data collection. For example, we can set the retention period ourselves and also control data collection.Here is an overview of the most important types of data collected by Google Analytics:
Heat maps: Google creates what are known as heat maps. Heat maps show exactly which areas you click on. This gives us information about where you are „navigating“ on our site.
Duration of the session: Google defines a "session" as the amount of time you spend on our site without leaving the page. If you have been inactive for 20 minutes, the session ends automatically.
Bounce Rate (Bounce rate): A bounce occurs when you view only one page on our website and then leave it.
Account Creation: When you create an account or place an order on our website, Google Analytics collects this data.
Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, it is used to derive location data.
Technical Information: Technical information includes, among other things, your browser type, your Internet service provider, and your screen resolution.
Source: Google Analytics—and, of course, we—are also interested in knowing which website or advertisement led you to our site.Other data includes contact information, any reviews you may have left, media playback (e.g., when you play a video on our site), sharing content on social media, or adding content to your favorites. This list is not exhaustive and is intended only to provide a general overview of the data collected by Google Analytics.
How long and where is the data stored?
Google has servers located all over the world. Here you can find out exactly where Google's data centers are located:
https://datacenters.google/Your data is distributed across various physical storage media. This has the advantage of making the data more readily accessible and better protected against tampering. Every Google data center has appropriate contingency plans in place for your data. For example, even if Google’s hardware fails or natural disasters cripple servers, the risk of a service interruption at Google remains low.The data retention period depends on the properties used. The retention period is always determined separately for each individual property. Google Analytics offers us four options for controlling the retention period:
- 2 months: that is the shortest retention period.
- 14 months: By default, data is stored in GA4 for 14 months.
- 26 months: You can also store the data for 26 months.
- Data is not deleted until we delete it manually
In addition, there is also the option to have data deleted only after you have not visited our website for the period we have selected. In this case, the retention period is reset each time you visit our website again within the specified period.Once the specified period has expired, the data is deleted once a month. This retention period applies to your data associated with cookies, user identification, and advertising IDs (e.g., cookies from the DoubleClick domain). Report results are based on aggregated data and are stored separately from user data. Aggregated data is a combination of individual data points into a larger unit.
How can I delete my data or prevent it from being stored?
Under European Union data protection law, you have the right to access, update, delete, or restrict the use of your data. By using the browser add-on to disable Google Analytics JavaScript (analytics.js, gtag.js), you can prevent Google Analytics 4 from using your data. You can find the browser add-on at
https://tools.google.com/dlpage/gaoptout?hl=de Download and install. Please note that this add-on only disables data collection by Google Analytics.If you want to disable, delete, or manage cookies in general, you’ll find the relevant links to instructions for the most popular browsers in the „Cookies“ section.
Legal Basis
The use of Google Analytics requires your consent, which we have obtained via our cookie pop-up. According to
Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by web analytics tools.In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. With the help of Google Analytics, we detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is
Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Analytics if you have given your consent.Google also processes your data in the United States, among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://business.safety.google/intl/de/adsprocessorterms/.We hope we've been able to provide you with the most important information about how Google Analytics processes data. If you'd like to learn more about this tracking service, we recommend these two links:
https://marketingplatform.google.com/about/analytics/terms/de/ and
https://support.google.com/analytics/answer/6004245?hl=de.If you would like to learn more about data processing, please refer to Google's Privacy Policy at
https://policies.google.com/privacy?hl=de.
Google Analytics Reports on Demographic Characteristics and Interests
We have enabled the advertising reporting features in Google Analytics. The reports on demographic characteristics and interests include information on age, gender, and interests. This allows us to gain a better understanding of our users—without being able to link this data to specific individuals. You can learn more about the advertising features at
https://support.google.com/analytics/answer/3450482?hl=de_AT&utm_id=ad.You can manage how your Google Account activities and information are used under “Ad Settings” at
https://adssettings.google.com/authenticated Close using the checkbox.
Google Analytics E-Commerce Tracking
We also use the e-commerce tracking feature of the web analytics tool Google Analytics on our website. This allows us to analyze very precisely how you and all our other customers interact with our website. E-commerce tracking focuses primarily on purchasing behavior. Based on the data collected, we can tailor and optimize our services to meet your needs and expectations. We can also target our online advertising more effectively so that our ads are seen only by people who are actually interested in our products or services. E-commerce tracking records, for example, which orders were placed, how long it took you to purchase the product, what the average order value is, and how much the shipping costs are. All of this data can be collected and stored under a specific ID.
Google Analytics, Google Signals, Privacy Policy
We have enabled Google Signals in Google Analytics. This updates the existing Google Analytics features (advertising reports, remarketing, cross-device reports, and reports on interests and demographics) to receive aggregated and anonymized data from you, provided you have enabled personalized ads in your Google Account.What makes this special is that it involves cross-device tracking. This means your data can be analyzed across devices. By enabling Google Signals, data is collected and linked to your Google Account. For example, this allows Google to recognize when you view a product on our website using a smartphone and then purchase the product later using a laptop. Thanks to the activation of Google Signals, we can launch cross-device remarketing campaigns that would otherwise not be possible in this form. Remarketing means that we can also show you our offerings on other websites.In Google Analytics, Google Signals also collects additional visitor data such as location, search history, YouTube history, and data about your actions on our website. This enables us to receive better advertising reports from Google and more useful information about your interests and demographic characteristics. This includes your age, the language you speak, where you live, and your gender. Additionally, social criteria such as your occupation, marital status, and income are also taken into account. All of these characteristics help Google Analytics define demographic groups or target audiences.The reports also help us better assess your behavior, preferences, and interests. This allows us to optimize and tailor our services and products for you. By default, this data expires after 26 months. Please note that this data collection only takes place if you have enabled personalized ads in your Google Account. The data is always aggregated and anonymous; it never includes information about individual people. You can manage or delete this data in your Google Account.
Google Analytics in Consent Mode
Depending on your consent, your personal data will be processed by Google Analytics in what is known as „Consent Mode.“ You can choose whether or not to consent to Google Analytics cookies. By doing so, you also choose which of your data Google Analytics is permitted to process. This collected data is primarily used to measure user behavior on the website, display targeted advertising, and provide us with web analytics reports. Typically, you consent to data processing by Google via a cookie consent tool. If you do not consent to data processing, only aggregated data is collected and processed. This means that data cannot be attributed to individual users, and therefore no user profile is created for you. You can also choose to consent only to statistical measurement. In this case, no personal data is processed and, consequently, it is not used for advertising or to measure advertising performance.
Google Analytics IP Anonymization
We have implemented IP address anonymization for Google Analytics on this website. This feature was developed by Google to enable this website to comply with applicable data protection regulations and the recommendations of local data protection authorities when they prohibit the storage of full IP addresses. IP anonymization or masking takes place as soon as the IP addresses enter the Google Analytics data collection network and before the data is stored or processed.For more information on IP anonymization, please visit
https://support.google.com/analytics/answer/2763052?hl=de.
Google Analytics Without Cookies
We do use Google Analytics (GA for short) on our website, but without setting cookies in your browser. We’ve already explained what cookies are above; hopefully, you still remember that explanation. Just to briefly and specifically address GA: Cookies are used to store data in your browser on your device that is helpful to GA. Since we do not use cookies, no personal data that could be used to create a user profile is stored in such cookies. Although Google Analytics can perform various measurements and web analyses, the data collected for this purpose is stored solely on Google’s servers, and your privacy is respected and protected to a much greater extent.
Google Optimize Privacy Policy
We use Google Optimize, a website optimization tool, on our website. The service provider is the U.S. company Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.Google processes your data, including in the United States. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://business.safety.google/intl/de/adsprocessorterms/.For more information about the data processed when using Google Optimize, please see the Privacy Policy at
https://policies.google.com/privacy?hl=de.
| Google Remarketing Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Business success and the optimization of our services.
📓 Data Processed: Access statistics, which include data such as access locations, device data, duration and time of access, navigation behavior, and click behavior. Personal data such as IP addresses may also be processed.
📅 Retention period: Conversion cookies typically expire after 30 days.
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Google Remarketing?
We use Google Remarketing as an online marketing tool to promote our products and services. Our goal is to make more people online aware of the high quality of our offerings. As part of our advertising efforts, we use Google Remarketing from Google Inc. on our website. In Europe, however, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. With the help of this retargeting tool, we can better tailor our advertising to your interests and needs and deliver it in a more targeted manner. In the following article, we’ll explain in more detail why we use Google Remarketing, what data is stored in the process, and how you can prevent this data storage.Google Remarketing is a specialized online advertising method in which targeted ads are displayed to users who have previously visited a specific website or app. This means that, for example, after you’ve visited our website, the system recognizes which pages you’ve viewed and what interests you, and can use this information to display targeted online ads to you. This works through the use of cookies and other tracking technologies that track your user behavior on our site and then display relevant ads on other Google platforms (such as YouTube).We are confident in the quality of our offerings and want as many people as possible to discover our website. In the online space, Google Ads and its integrated Google Remarketing feature offer the best platform for this. Of course, we also want to gain a precise overview of the cost-benefit ratio of our advertising campaigns. That’s why we use the conversion tracking tool from Google Ads.
Why do we use Google Remarketing on our website?
We use Google Remarketing to draw attention to our offerings on other websites and Google platforms. The goal is to ensure that our advertising campaigns reach only those people who are interested in our offerings. With Google Remarketing, we can deliver targeted ads to you if you’ve previously visited our website but haven’t yet taken the desired action. Through these ads, we may be able to convince you that we do, in fact, have what you’re looking for. Our goal is to increase the likelihood of a repeat interaction or conversion. But what exactly is a conversion? A conversion occurs when you go from being a merely interested website visitor to a visitor who takes action. This happens whenever you click on our ad and then perform another action, such as visiting our website.This data allows us to calculate our cost-benefit ratio, measure the success of individual advertising campaigns, and consequently optimize our online marketing efforts. Furthermore, using the data we collect, we can make our website more interesting for you and tailor our advertising offerings even more specifically to your needs.
What data is stored by Google Remarketing?
We have integrated Google Remarketing into our website to better analyze certain user actions and display targeted advertising. The data collected varies depending on the features used and individual settings. Generally, information is collected about which subpages you visit on our website, which products you view or have purchased, how long you stay on a page, whether you have abandoned certain actions, or what other conversions (purchases, button clicks, etc.) you have made.As you can see, Google Remarketing generally processes only data regarding your user behavior and no personal data, such as your name or email address. However, your IP address is processed by Google Remarketing, which is considered personal data under the GDPR. Furthermore, information about your devices (browser, operating system, device type, etc.) and demographic data such as age or gender may be stored via cookies or other tracking technologies. All data is anonymized and aggregated to protect user privacy.If you click on one of our Google Ads, the „Conversion“ cookie from a Google domain is stored on your computer (usually in your browser) or mobile device. Cookies are small text files that store information on your computer.Here is the data for the most important cookies that can be used for remarketing:
Name: Conversion
Value: EhMI_aySuoyv4gIVled3Ch0llweVGAEgt-mr6aXd7dYlSAGQ112279866-3
Purpose: This cookie tracks every conversion you make on our site after arriving here via a Google ad.
Expiration Date: after 3 months
Name: _gac
Value: 1.1558695989.EAIaIQobChMIiOmEgYO04gIVj5AYCh2CBAPrEAAYASAAEgIYQfD_BwE
Purpose: This is a standard Google Analytics cookie used to track various actions on our website.
Expiration Date: after 3 months
Note: The _gac cookie appears only in connection with Google Analytics. The list above is not exhaustive, as Google frequently uses other cookies for analytical purposes.As soon as you complete an action on our website, Google recognizes the cookie and records your action as a so-called conversion. As long as you are browsing our website and the cookie has not yet expired, we and Google recognize that you found your way back to us via our Google Ads ad. The cookie is read and sent back to Google Ads along with the conversion data. It is also possible that other cookies are used to measure conversions. Google Remarketing and the tracking often associated with it can be further refined and improved using Google Analytics. For ads that Google displays in various locations across the web, cookies named “__gads” or “_gac” may be set under our domain. Since September 2017, various campaign details have been stored by analytics.js using the _gac cookie. The cookie stores this data as soon as you visit one of our pages for which Google Ads’ automatic tagging has been set up. Unlike cookies set for Google domains, Google can only read these conversion cookies when you are on our website.
How long and where is the data stored?
Google has servers located all over the world. Here you can find out exactly where Google's data centers are located:
https://datacenters.google/As a general rule, Google processes data only for as long as is necessary to fulfill the purposes for which it was collected and as required by law. We would like to point out here that we have no control over how Google uses the collected data. According to Google, the data is encrypted and stored on secure servers. In most cases, conversion cookies expire after 30 days and do not transmit any personal data. The cookies named „Conversion“ and „_gac“ (which is used in conjunction with Google Analytics) have an expiration period of 3 months.
How can I delete my data or prevent it from being stored?
You have the option to opt out of Google Remarketing. If you disable Google Remarketing in your browser, you will block tracking. In this case, you will not be included in the tool’s statistics. You can also change your browser’s cookie settings at any time. This works slightly differently for each browser. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.If you do not want to accept cookies at all, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. By downloading and installing this browser plug-in at
https://support.google.com/ads/answer/7395996 All „advertising cookies“ will also be disabled. Please note that disabling these cookies does not prevent ads from appearing; it only prevents personalized advertising.In your Google Account settings, under “Ads” or “Advertising,” you can disable personalized ads based on Google Remarketing. If you do not consent to data processing by Google Remarketing via the Consent Management Tool on our website, no data will be collected through this process.
Legal Basis
If you have consented to the use of Google Remarketing, the legal basis for the corresponding data processing is this consent. According to
Art. 6(1)(a) of the GDPR (Consent) This constitutes the legal basis for the processing of personal data, such as that collected by Google Remarketing (IP address).We also have a legitimate interest in using Google Remarketing to optimize our online service and our marketing activities. The corresponding legal basis for this is
Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Remarketing if you have given your consent.Google also processes your data in the United States, among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the United States. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deGoogle has a data processing agreement in place pursuant to Article 28 of the GDPR, which serves as the legal basis for our customer relationship with Google under data protection law. The content of this agreement refers to the EU Standard Contractual Clauses. You can find the data processing terms here:
https://business.safety.google/intl/de/adsprocessorterms/For more information about the data processed through the use of Google Remarketing, please see the Privacy Policy at
https://policies.google.com/privacy?hl=de.
Google Tag Manager Privacy Policy
| Google Tag Manager Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Organization of the individual tracking tools
📓 Data processed: Google Tag Manager does not store any data itself. The data is collected by the tags of the web analytics tools used.
📅 Retention period: Depends on the web analytics tool used
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests) |
What is Google Tag Manager?
We use Google Tag Manager, provided by Google Inc., on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. This Tag Manager is one of many helpful marketing products offered by Google. Google Tag Manager allows us to centrally integrate and manage code snippets from various tracking tools that we use on our website.In this privacy policy, we’d like to explain in more detail what Google Tag Manager does, why we use it, and how data is processed.Google Tag Manager is an organizational tool that allows us to integrate and manage website tags centrally via a user interface. Tags are small code snippets that, for example, track your activities on our website. To do this, JavaScript code snippets are inserted into the source code of our site. The tags often come from Google’s own products, such as Google Ads or Google Analytics, but tags from other companies can also be integrated and managed through the Manager. These tags perform various functions. They can collect browser data, feed data into marketing tools, embed buttons, set cookies, and track users across multiple websites.
Why do we use Google Tag Manager for our website?
As the saying goes: Organization is half the battle! And of course, this also applies to maintaining our website. To make our website as user-friendly as possible for you and everyone interested in our products and services, we need various tracking tools, such as Google Analytics. The data collected by these tools shows us what interests you most, where we can improve our services, and which other people we should be targeting with our offers. And for this tracking to work, we need to embed the corresponding JavaScript code into our website. In principle, we could embed each code snippet from the individual tracking tools separately into our source code. However, that takes a relatively long time, and it’s easy to lose track of everything. That’s why we use Google Tag Manager. We can easily integrate the necessary scripts and manage them all from one place. In addition, Google Tag Manager offers an easy-to-use interface and requires no programming knowledge. This is how we manage to keep our tag jungle organized.
What data does Google Tag Manager store?
Google Tag Manager itself is a domain that does not set cookies or store data. It acts merely as an „administrator“ of the implemented tags. The data is collected by the individual tags of the various web analytics tools. In Google Tag Manager, the data is essentially routed to the individual tracking tools and is not stored.However, the situation is quite different with the integrated tags from various web analytics tools, such as Google Analytics. Depending on the analytics tool, various data about your web behavior is typically collected, stored, and processed using cookies. For more information, please read our privacy policies for the individual analytics and tracking tools we use on our website.In the Tag Manager account settings, we have authorized Google to receive anonymized data from us. However, this pertains solely to the use of our Tag Manager and does not involve your data, which is stored via the code snippets. We allow Google and others to receive selected data in anonymized form. We therefore consent to the anonymous sharing of our website data. Despite extensive research, we were unable to determine exactly which aggregated and anonymous data is shared. In any case, Google deletes all information that could identify our website. Google aggregates the data with hundreds of other anonymous website data sets and uses it to identify user trends as part of benchmarking activities. Benchmarking involves comparing a company’s own results with those of its competitors. Processes can be optimized based on the information collected.
How long and where is the data stored?
When Google stores data, that data is stored on Google's own servers. The servers are located all over the world. Most of them are in the United States. Under
https://datacenters.google/ You can find detailed information about the locations of Google's servers here.For information on how long each tracking tool stores your data, please refer to our individual privacy policies for each tool.
How can I delete my data or prevent it from being stored?
Google Tag Manager itself does not set any cookies; rather, it manages tags from various tracking websites. In our privacy policies for the individual tracking tools, you will find detailed information on how to delete or manage your data.Please note that when using this tool, your data may also be stored and processed outside the EU. Under current European data protection law, most non-EU countries (including the U.S.) are considered unsafe. Therefore, data may not simply be transferred to, stored in, or processed in non-secure third countries unless there are appropriate safeguards (such as EU Standard Contractual Clauses) in place between us and the non-European service provider.
Legal Basis
The use of Google Tag Manager requires your consent, which we have obtained through our cookie pop-up. According to
Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by web analytics tools.In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. With the help of Google Tag Manager, we can improve our economic efficiency. The legal basis for this is
Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Tag Manager if you have given your consent.Google also processes your data in the U.S., among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://business.safety.google/intl/de/adsprocessorterms/.If you'd like to learn more about Google Tag Manager, we recommend checking out the FAQs at
https://support.google.com/tagmanager/?hl=de#topic=3441530.You can find out what data Google generally collects and how it uses that data at
https://policies.google.com/privacy?hl=de read more.
| Meta Conversions API Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as customer data, user behavior data, information about your device, and your IP address.
You can find more details below in the Privacy Policy.
📅 Retention period: until the data is no longer useful for Meta’s purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is a Meta Conversions API?
We use the Meta Conversions API, a server-side event tracking tool, on our website. The service provider is the U.S.-based company Meta Platforms Inc. For the European region, Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is responsible.The Meta Conversions API is a tool or feature that can measure the performance of our advertising campaigns in real time. The API is an interface that connects our website to Meta and thereby tracks specific actions on our website. A conversion occurs when you, as a website visitor, perform a desired action. This could be, for example, clicking a button or filling out a registration form. This conversion tracking method is an alternative to the Meta Pixel and aims to optimize conversion tracking through precision and reliability. The API sends data directly from our server to Meta on the server side. This process may also involve the processing of personal data. In this privacy policy, we provide further details regarding data processing by us and by Meta.
Why do we use the Meta Conversions API on our website?
We use the Meta Conversions API to improve the quality of our website, our offerings, and our advertising campaigns. Our goal is to provide you with the best possible service. We want you to feel comfortable on our website and get exactly what you expect. To do this, we naturally need to tailor our offerings as closely as possible to your wishes and requirements. The Meta Conversions API allows us to respond effectively to these needs and customize content and offers individually. This flexibility helps us accommodate different needs while simultaneously improving our website. The data also helps us run our advertising campaigns more cost-effectively and with greater precision. After all, we naturally want to show our offerings only to people who are actually interested in them.
What data is stored by the Meta Conversions API?
Using the Meta Conversions API, we can collect various data about events on our website and send it to Meta. Exactly which data is stored and processed depends on our individual settings and the specific events and parameters. Generally, event data, user data, device data, and the time at which an event (e.g., a button click) occurred are stored and sent to Meta. Event data includes actions such as logins, product purchases, page views, or button clicks that can be performed on our website. User data may also include personal data such as IP address, name, address, or email address. Device data refers to your device type, operating system, browser, and screen resolution.
How long and where is the data stored?
In general, Meta stores data until it is no longer needed for its own services and Meta products. Meta has servers located around the world where data is stored. However, customer data is deleted within 48 hours after it has been matched with the user’s own data.
How can I delete my data or prevent it from being stored?
You have the right and the option to access your personal data at any time and to object to its use and processing. You may also file a complaint with a government supervisory authority at any time. You can generally prevent data storage by not consenting to data processing via the Consent Management Tool. The Meta Conversions API operates on the server side, so the process for deleting data differs from client-side methods. Nevertheless, you can check the privacy and security settings in your browser and, if possible, block tracking resources (pixels, cookies, scripts).
Legal Basis
If you have consented to the processing and storage of your data by the Meta Conversions API, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the Meta Conversions API to the extent that you have given your consent.Meta also processes your data in the United States, among other places. Meta Platforms is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. You can find more information on this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Meta uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Meta commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe metadata processing terms, which refer to the standard contractual clauses, can be found at
https://www.facebook.com/legal/terms/dataprocessing.For more information about the data processed through the use of the Meta Conversions API, please see the Privacy Policy at
https://www.facebook.com/about/privacy.
We use the Meta Pixel (formerly the Facebook Pixel) from Facebook, or Meta Platforms, Inc., on our website. To do this, we have implemented a code snippet on our website. The Meta Pixel is a snippet of JavaScript code that loads a set of functions that allow Facebook to track your user actions if you arrived at our website via Facebook Ads. For example, if you purchase a product on our website, the Meta Pixel is triggered and stores your actions on our website in one or more cookies. These cookies enable Facebook to match your user data (customer data such as IP address and user ID) with the data in your Facebook account. Facebook then deletes this data. The collected data is anonymous to us and cannot be viewed by us; it is used solely for the purpose of serving advertisements. If you are a Facebook user and are logged in, your visit to our website is automatically associated with your Facebook account.We want to show our services and products only to those people who are genuinely interested in them. With the help of Meta Pixel, our advertising efforts can be better tailored to your preferences and interests. This way, Facebook users (provided they have enabled personalized ads) see relevant advertisements. Furthermore, Facebook uses the collected data for analytical purposes and to display its own advertisements.Below, we list the cookies that were set by embedding Meta Pixel on a test page. Please note that these are only example cookies. Different cookies are set depending on your interaction with our website.
Name: _fbp
Value: fb.1.1568287647279.257405483-6112279866-7
Purpose: Facebook uses this cookie to display advertisements.
Expiration Date: after 3 months
Name: fr
Value: 0aPf312HOS5Pboo2r..Bdeiuf…1.0.Bdeiuf.
Purpose: This cookie is used to ensure that Meta Pixel works properly.
Expiration Date: after 3 months
Name: comment_author_50ae8267e2bdf1253ec1a5769f48e062112279866-3
Value: Author's Name
Purpose: This cookie stores the text and name of a user who, for example, leaves a comment.
Expiration Date: after 12 months
Name: comment_author_url_50ae8267e2bdf1253ec1a5769f48e062
Value: https%3A%2F%2Fwww.testseite…%2F (URL des Autors)
Purpose: This cookie stores the URL of the website that the user enters in a text field on our website.
Expiration Date: after 12 months
Name: comment_author_email_50ae8267e2bdf1253ec1a5769f48e062
Value: Author's email address
Purpose: This cookie stores the user's email address, provided the user has entered it on the website.
Expiration Date: after 12 months
Note: The cookies mentioned above are based on individual user behavior. When it comes to the use of cookies in particular, changes on Facebook can never be ruled out.If you are logged in to Facebook, you can adjust your ad settings at
https://www.facebook.com/adpreferences/advertisers/ change it yourself. If you're not a Facebook user, you can go to
https://www.youronlinechoices.com/de/praferenzmanagement/ You can generally manage your usage-based online advertising there. There, you have the option to disable or enable providers.Facebook also processes your data in the U.S., among other places. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Facebook uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://www.facebook.com/legal/terms/dataprocessing.If you'd like to learn more about Facebook's privacy practices, we recommend reviewing the company's privacy policy at
https://www.facebook.com/privacy/policy.
Facebook Automatic Advanced Matching Privacy Policy
We have also enabled Automatic Advanced Matching as part of the Facebook Pixel feature. This feature of the pixel allows us to send hashed email addresses, names, gender, city, state, ZIP code, and date of birth or phone number to Facebook as additional information, provided that you have provided us with this data. Enabling this feature allows us to tailor our advertising campaigns on Facebook even more precisely to people who are interested in our services or products.
Email Marketing Introduction
| Email Marketing Summary
👥 Data Subjects: Newsletter subscribers
🤝 Purpose: Direct marketing via email, notifications about system-related events
📓 Data Processed: Data entered during registration, but at a minimum the email address. You can find more details on this in the respective email marketing tool used.
📅 Retention period: For the duration of the subscription
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is email marketing?
To keep you up to date, we also use email marketing. In this context, provided you have consented to receiving our emails or newsletters, we also process and store your data. Email marketing is a subset of online marketing. It involves sending news or general information about a company, products, or services via email to a specific group of people who are interested in them.If you’d like to participate in our email marketing (usually via newsletter), you typically just need to sign up with your email address. To do so, you fill out an online form and submit it. However, we may also ask you for your title and name so that we can address you personally.Generally, signing up for newsletters works using the so-called „double opt-in process.“ After you sign up for our newsletter on our website, you’ll receive an email asking you to confirm your subscription. This ensures that the email address belongs to you and that no one has subscribed using someone else’s email address. We, or a notification tool we use, log every single subscription. This is necessary so that we can verify that the subscription process was carried out in accordance with the law. Typically, the time of registration, the time of the registration confirmation, and your IP address are stored. Additionally, any changes you make to your stored data are also logged.
Why do we use email marketing?
Of course, we want to stay in touch with you and keep you updated on the most important news about our company. To that end, we use email marketing—often simply referred to as “newsletters”—as a key component of our online marketing efforts. Provided you consent or it is permitted by law, we will send you newsletters, system emails, or other notifications via email. When we use the term „newsletter“ in the following text, we are primarily referring to emails sent on a regular basis. Of course, we do not want to bother you in any way with our newsletters. That is why we always strive to provide only relevant and interesting content. For example, you’ll learn more about our company, our services, or our products. Since we’re constantly improving our offerings, our newsletter will also keep you informed whenever there’s news or when we’re running special, lucrative promotions. If we engage a service provider that offers a professional email distribution tool for our email marketing, we do so to ensure we can deliver newsletters to you quickly and securely. The primary purpose of our email marketing is to inform you about new offers and to help us achieve our business goals.
What data is processed?
If you subscribe to our newsletter through our website, you will confirm your membership in an email list via email. In addition to your IP address and email address, your title, name, address, and phone number may also be stored—but only if you consent to this data storage. The data marked as such is necessary for you to participate in the service we offer. Providing this information is voluntary; however, failure to do so will prevent you from using the service. In addition, information about your device or your preferred content on our website may also be stored. For more information on data storage when you visit a website, see the section “Automatic Data Storage.” We record your declaration of consent so that we can always demonstrate that it complies with our laws.
Duration of Data Processing
If you unsubscribe from our email/newsletter mailing list, we may store your email address for up to three years based on our legitimate interests so that we can still prove your consent at that time. We may process this data only if we need to defend ourselves against any potential claims.However, if you confirm that you gave us your consent to subscribe to the newsletter, you may submit an individual request for deletion at any time. If you permanently revoke your consent, we reserve the right to add your email address to a block list. As long as you have voluntarily subscribed to our newsletter, we will, of course, continue to retain your email address.
Right to Object
You can unsubscribe from our newsletter at any time. To do so, simply revoke your consent to receive the newsletter. This usually takes just a few seconds or one or two clicks. In most cases, you’ll find a link to unsubscribe from the newsletter right at the bottom of each email. If you really can’t find the link in the newsletter, please contact us by email and we’ll cancel your newsletter subscription immediately.
Legal Basis
We send our newsletter based on your consent (Article 6(1)(a) of the GDPR). This means that we may only send you a newsletter if you have actively subscribed to it beforehand. We may also send you promotional messages, provided that you have become a customer of ours and have not objected to the use of your email address for direct marketing.Information about specific email marketing services and how they process personal data can be found—where available—in the following sections.
Brevo Privacy Policy
| Brevo Privacy Policy Summary
👥 Data Subjects: Newsletter subscribers
🤝 Purpose: Direct marketing via email, notifications about system-related events
📓 Data Processed: Data entered during registration, but at a minimum the email address.
📅 Retention period: For the duration of the subscription
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Brevo?
You can sign up for our newsletter for free on our website. To make this work, we use the email marketing service Brevo for our newsletter. This is a service provided by the German company Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin. Among other things, Brevo is an email marketing tool that allows us to send you personalized newsletters. With Brevo, we don’t have to install anything and can still draw on a wide range of truly useful features. Below, we’ll take a closer look at Brevo’s email marketing service and inform you about the most important data protection-related aspects.
Why do we use Brevo?
The newsletter service also provides us with helpful analytics. This means that when we send out a newsletter, we can see, for example, whether and when you opened it. The software also detects and records whether you click on any links in the newsletter and which ones you click on. This information is extremely helpful in tailoring and optimizing our service to your needs and preferences. After all, we naturally want to offer you the best possible service. In addition to the data mentioned above, we therefore also store data regarding your user behavior.
What data does Brevo process?
We’re, of course, very happy that you’ve decided to subscribe to our newsletter. This way, we can keep you up to date with the latest news and give you firsthand insights into what’s happening at our company. However, you should be aware that during the newsletter sign-up process, all data you enter (such as your email address or your first and last name) is stored and managed on our server and by Brevo. This data is also considered personal information. For example, in addition to the time and date of your registration, your IP address is also stored. During the registration process, you consent to our sending you the newsletter, and you are also made aware of this privacy policy. Furthermore, data such as your click behavior within the newsletter may also be processed.
How long and where is the data stored?
The data for the newsletter tool is stored on servers in Germany. The data collected that identifies you as an individual (i.e., personal data) is generally deleted by Brevo no later than two years after the termination of your contractual relationship with us. However, you may also request the deletion of your data at any time. Requests are processed within 30 days. Data that we collect and send to Brevo is deleted by us as soon as you unsubscribe from our newsletter.
Right to Object
You can unsubscribe from our newsletter at any time. To do so, simply revoke your consent to receive the newsletter. This usually takes just a few seconds or one or two clicks. In most cases, you’ll find a link to unsubscribe from the newsletter right at the bottom of each email. If you really can’t find the link in the newsletter, please contact us by email and we’ll cancel your newsletter subscription immediately. After you unsubscribe, your personal data will be deleted from our server and from the Brevo servers, which are located in Germany. You have the right to receive information about your stored data free of charge and, if applicable, the right to have it deleted, blocked, or corrected.
Legal Basis
Brevo sends our newsletter based on your
Consent (Article 6(1)(a) of the GDPR). This means we may only send you a newsletter if you have actively subscribed to it beforehand. If consent is not required, the newsletter is sent on the basis of the
legitimate interest in direct marketing (Article 6(1)(f)), to the extent permitted by law. We record your registration process so that we can always demonstrate that it complies with our laws.If you would like more information about data processing, we recommend that you review the company’s Privacy Policy at
https://www.brevo.com/de/legal/privacypolicy/.
| Social Media Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To present and optimize our services, contact visitors and prospective customers, among other things, and for advertising
📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.
You can find more details about this in the information provided by the respective social media tool.
📅 Retention period: Depends on the social media platforms used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is social media?
In addition to our website, we are also active on various social media platforms. In doing so, we may process user data so that we can specifically target users who are interested in us through social networks. Furthermore, elements of a social media platform may be embedded directly into our website. This is the case, for example, when you click on a so-called social button on our website and are redirected directly to our social media presence. “Social media” refers to websites and apps through which registered members can create content, share content publicly or within specific groups, and connect with other members.
Why do we use social media?
For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to potential customers. The social media elements integrated into our website help you quickly and easily access our social media content.The data stored and processed through your use of a social media channel is primarily intended to enable web analytics. The goal of these analyses is to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, the analyzed data can be used to draw conclusions about your interests and create so-called user profiles. This also enables the platforms to present you with tailored advertisements. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.We generally assume that we remain the data controller under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Article 26 of the GDPR. Where this is the case, we will indicate this separately and operate on the basis of a relevant agreement. The key terms of the agreement are then outlined below for the respective platform.Please note that when you use social media platforms or our embedded features, your data may also be processed outside the European Union, as many social media channels—such as Facebook or Twitter—are U.S. companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.
What data is processed?
Exactly which data is stored and processed depends on the specific social media platform provider. But typically, this includes data such as phone numbers, email addresses, information you enter into a contact form, user data—such as which buttons you click, who you like or follow, and when you visited which pages—as well as information about your device and your IP address. Most of this data is stored in cookies. Especially if you have a profile on the social media platform you’re visiting and are logged in, data can be linked to your profile.All data collected via a social media platform is also stored on the providers’ servers. Consequently, only the providers have access to the data and can provide you with the relevant information or make changes.If you want to know exactly what data is stored and processed by social media providers and how you can object to data processing, you should carefully read the company’s privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the provider directly.
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details. For example, the social media platform Facebook stores data until it is no longer needed for its own purposes. However, customer data that is matched with a user’s own data is deleted within two days. In general, we process personal data only for as long as is absolutely necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be extended.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers, such as embedded social media elements. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.Since social media tools may use cookies, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, if you have given your consent, your data will also be processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.Information about specific social media platforms—if available—can be found in the following sections.
Facebook Privacy Policy
| Facebook Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as customer data, user behavior data, information about your device, and your IP address.
You can find more details below in the Privacy Policy.
📅 Retention period: until the data is no longer useful for Facebook’s purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are Facebook tools?
We use selected Facebook tools on our website. Facebook is a social media network operated by Meta Platforms Inc. or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. These tools enable us to provide you and others interested in our products and services with the best possible experience.If data is collected from you and transmitted via our embedded Facebook elements or through our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook bears sole responsibility for the further processing of this data. Our joint obligations are also set forth in a publicly available agreement at
https://www.facebook.com/legal/controller_addendum enshrined. Among other things, it stipulates that we must clearly inform you about the use of Facebook tools on our site. Furthermore, we are also responsible for ensuring that these tools are integrated into our website in a manner that complies with data protection laws. Facebook, on the other hand, is responsible for the data security of Facebook products, for example. If you have any questions regarding data collection and processing by Facebook, you can contact the company directly. If you direct your question to us, we are obligated to forward it to Facebook.Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.In addition to many other products, Facebook also offers what are known as “Facebook Business Tools.” This is Facebook’s official term. However, since the term is not widely known, we have decided to simply refer to them as Facebook tools. These include, among others:
- Facebook Pixel
- social media plugins (such as the „Like“ or „Share“ button)
- Facebook Login
- Account Kit
- APIs (Application Programming Interfaces)
- SDKs (Software Development Kits)
- Platform Integrations
- Plugins
- Codes
- Specifications
- Documentation
- Technologies and Services
Through these tools, Facebook expands its services and is able to obtain information about user activity outside of Facebook.
Why do we use Facebook tools on our website?
We want to show our services and products only to people who are genuinely interested in them. With the help of ads (Facebook Ads), we can reach exactly those people. However, in order to show users relevant ads, Facebook needs information about people’s preferences and needs. As a result, information about user behavior (and contact information) on our website is made available to the company. This allows Facebook to collect more relevant user data and display appropriate ads about our products and services to interested people. These tools thus enable tailored advertising campaigns on Facebook.Facebook refers to data about your behavior on our website as „event data.“ This data is also used for measurement and analytics services. Facebook can thus create „campaign reports“ on our behalf to assess the effectiveness of our advertising campaigns. Furthermore, analytics provide us with better insight into how you use our services, website, or products. We use some of these tools to optimize your user experience on our website. For example, you can use the social plugins to share content from our site directly on Facebook.
What data is stored by Facebook tools?
When using certain Facebook tools, personal data (customer data) may be sent to Facebook. Depending on the tools used, customer data such as name, address, phone number, and IP address may be transmitted.Facebook uses this information to match the data with the information it already has about you (provided you are a Facebook member). Before customer data is transmitted to Facebook, a process known as „hashing“ takes place. This means that a data set of any size is transformed into a string of characters. This also serves to encrypt the data.In addition to contact information, „event data“ is also transmitted. „Event data“ refers to the information we collect about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information it receives with third parties (such as advertisers) unless the company has explicit permission or is legally required to do so. „Event data“ can also be linked to contact information. This enables Facebook to offer better personalized advertising. After the aforementioned matching process, Facebook deletes the contact information.To deliver optimized ads, Facebook uses event data only if it has been aggregated with other data (collected by Facebook through other means). Facebook also uses this event data for security, protection, development, and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, a varying number of cookies are stored in your browser. We discuss individual Facebook cookies in more detail in the descriptions of the various Facebook tools. You can also find general information about the use of Facebook cookies at
https://www.facebook.com/policies/cookies.
How long and where is the data stored?
In general, Facebook stores data until it is no longer needed for its own services and Facebook products. Facebook has servers located all over the world where its data is stored. However, customer data is deleted within 48 hours after it has been matched with the user’s own data.
How can I delete my data or prevent it from being stored?
In accordance with the General Data Protection Regulation, you have the right to access, correct, transfer, and delete your data.Your data will only be completely deleted if you permanently delete your Facebook account. Here’s how to delete your Facebook account:1) Click „Settings“ on the right side of Facebook.2) Next, click “Your Facebook Information” in the left column.3) Now click „Deactivation and Deletion.“4) Select „Delete Account“ and then click „Continue and Delete Account.“5) Enter your password, click „Continue,“ and then click „Delete Account.“The data that Facebook receives through our site is stored, among other things, via cookies (e.g., through social plugins). In your browser, you can disable, delete, or manage individual or all cookies. Depending on which browser you use, this works in different ways. Under the “Cookies” section, you’ll find links to the instructions for the most popular browsers.If you generally prefer not to have cookies, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
Legal Basis
If you have consented to the processing and storage of your data by integrated Facebook tools, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review Facebook’s privacy policy or cookie guidelines.Facebook also processes your data in the U.S., among other places. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Facebook uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://www.facebook.com/legal/terms/dataprocessing.We hope we've helped you better understand the key information about the use and processing of data by Facebook tools. If you'd like to learn more about how Facebook uses your data, we recommend reviewing the privacy policy at
https://www.facebook.com/privacy/policy/.
Facebook Social Plug-ins Privacy Policy
Our website incorporates so-called social plug-ins from Meta Platforms Inc. You can recognize these buttons by the classic Facebook logo, such as the „Like“ button (the hand with a thumbs-up), or by a clear „Facebook Plug-in“ label. A social plug-in is a small component of Facebook that is integrated into our site. Each plug-in has its own function. The most commonly used functions are the familiar “Like” and “Share” buttons.Facebook offers the following social plug-ins:
- “Save” button
- “Like” button, Share, Send, and Quote
- Page Plugin
- Comments
- Messenger Plug-in
- Embedded posts and video players
- Group Plug-in
On
https://developers.facebook.com/docs/plugins you'll find more detailed information on how to use each plug-in. We use social plug-ins both to offer you a better user experience on our site and to allow Facebook to optimize our ads.If you have a Facebook account or
https://www.facebook.com/ If you have visited our site before, Facebook has already placed at least one cookie in your browser. In this case, your browser sends information to Facebook via this cookie as soon as you visit our site or interact with social plugins (e.g., the „Like“ button).The information received is deleted or anonymized within 90 days. According to Facebook, this data includes your IP address, the website you visited, the date, the time, and other information related to your browser.To prevent Facebook from collecting a large amount of data during your visit to our website and linking it to your Facebook data, you must log out of Facebook while visiting the website.If you are not logged in to Facebook or do not have a Facebook account, your browser sends less information to Facebook because you have fewer Facebook cookies. However, data such as your IP address or the website you are visiting may still be transmitted to Facebook. We would also like to expressly point out that we do not know the exact contents of the data. However, we strive to inform you as best as possible about data processing based on our current knowledge. You can also find out how Facebook uses the data in the company’s Privacy Policy at
https://www.facebook.com/about/privacy/update Read more.At a minimum, the following cookies are set in your browser when you visit a website with Facebook social plugins:
Name: dpr
Value: Not specified
Purpose: This cookie is used to ensure that the social media plugins on our website work properly.
Expiration Date: after the meeting ends
Name: fr
Value: 0jieyh4112279866c2GnlufEJ9..Bde09j…1.0.Bde09j
Purpose: This cookie is also necessary for the plug-ins to work properly.
Expiration Date:: after 3 months
Note: These cookies were set after a test, even if you are not a Facebook member.If you are logged in to Facebook, you can adjust your ad settings at
https://www.facebook.com/adpreferences/advertisers/ change it yourself. If you're not a Facebook user, you can go to
https://www.youronlinechoices.com/de/praferenzmanagement/?tid=112279866 You can generally manage your usage-based online advertising there. There, you have the option to disable or enable providers.If you would like to learn more about Facebook's data protection practices, we recommend reviewing the company's own privacy policy at
https://www.facebook.com/privacy/policy/.
Facebook Fan Page Privacy Policy
We also have a Facebook fan page for our website. The service provider is the U.S. company Meta Platforms Inc. For the European region, Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is responsible.Facebook processes your data in the U.S., among other places. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Facebook uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://www.facebook.com/legal/terms/dataprocessing.For more information about the data processed when using Facebook, please see the Privacy Policy at
https://www.facebook.com/about/privacy.
LinkedIn Privacy Policy
| LinkedIn Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as user behavior data, information about your device, and your IP address.
You can find more details below in the Privacy Policy.
📅 Retention period: The data is generally deleted within 30 days
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is LinkedIn?
On our website, we use social plug-ins from the social media network LinkedIn, operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. These social plugins may include feeds, content sharing, or links to our LinkedIn page. The social plugins are clearly marked with the familiar LinkedIn logo and allow you, for example, to share interesting content directly from our website. For the European Economic Area and Switzerland, LinkedIn Ireland Unlimited Company, located at Wilton Place in Dublin, is responsible for data processing.Embedding such plug-ins may result in data being sent to, stored by, and processed by LinkedIn. In this privacy policy, we aim to inform you about what data is involved, how the network uses this data, and how you can manage or prevent data storage.LinkedIn is the largest social network for professional connections. Unlike Facebook, for example, the company focuses exclusively on building professional connections. Companies can use the platform to showcase services and products and establish business relationships. Many people also use LinkedIn to search for jobs or to find suitable employees for their own companies. In Germany alone, the network has over 11 million members. In Austria, there are about 1.3 million.
Why do we use LinkedIn on our website?
We know how busy you are. It’s not possible to keep track of all social media channels individually. Even though, as in our case, it would be worth the effort. We regularly post interesting news or articles that are worth sharing. That’s why we’ve added a feature to our website that lets you share interesting content directly on LinkedIn or link directly to our LinkedIn page. We view built-in social plugins as an added service on our website. The data that LinkedIn collects also helps us ensure that any advertising we run is shown only to people who are interested in what we have to offer.
What data does LinkedIn store?
LinkedIn does not store any personal data simply by embedding social plug-ins. LinkedIn refers to this data, which is generated by plug-ins, as „passive impressions.“ However, if you click on a social plug-in—for example, to share our content—the platform stores personal data as so-called „active impressions.“ This happens regardless of whether you have a LinkedIn account or not. If you are logged in, the data collected is associated with your account.Your browser establishes a direct connection to LinkedIn’s servers when you interact with our plug-ins. In this way, the company logs various usage data. In addition to your IP address, this may include, for example, login data, device information, or details about your internet or mobile service provider. If you access LinkedIn services via your smartphone, your location may also be determined (after you have given your consent). LinkedIn may also share this data in “hashed” form with third-party advertisers. Hashing means that a data record is converted into a string of characters. This allows the data to be encrypted in such a way that individuals can no longer be identified.Most data regarding your user behavior is stored in cookies. These are small text files that are typically placed in your browser. However, LinkedIn may also use web beacons, pixel tags, ad tags, and other device identifiers.Various tests also show which cookies are set when a user interacts with a social plugin. The data found is not intended to be exhaustive and serves merely as an example. The following cookies were set without being logged in to LinkedIn:
Name: bcookie
Value: =2&34aab2aa-2ae1-4d2a-8baf-c2e2d7235c16112279866-
Purpose: This cookie is what is known as a „browser ID cookie“ and therefore stores your identification number (ID).
Expiration Date: After 2 years
Name: long
Value: v=2&lang=de-de
Purpose: This cookie stores your default or preferred language.
Expiration Date: after the meeting ends
Name: lidc
Value: 1818367:t=1571904767:s=AQF6KNnJ0G112279866…
Purpose: This cookie is used for routing. Routing tracks how you arrived at LinkedIn and how you navigate through the website.
Expiration Date: after 24 hours
Name: rtc
Value: kt0lrv3NF3x3t6xvDgGrZGDKkX
Purpose: No further information could be obtained about this cookie.
Expiration Date: after 2 minutes
Name: JSESSIONID
Value: ajax:1122798662900777718326218137
Purpose: This is a session cookie that LinkedIn uses to maintain anonymous user sessions on the server.
Expiration Date: after the meeting ends
Name: bscookie
Value: “v=1&201910230812…
Purpose: This cookie is a security cookie. LinkedIn describes it as a Secure Browser ID cookie.
Expiration Date: after 2 years
Name: fid
Value: AQHj7Ii23ZBcqAAAA…
Purpose: No further information could be found about this cookie.
Expiration Date: after 7 days
Note: LinkedIn also works with third-party providers. That's why we detected the two Google Analytics cookies, _ga and _gat, during our test.
How long and where is the data stored?
In general, LinkedIn retains your personal data for as long as the company deems necessary to provide its services. However, LinkedIn deletes your personal data when you delete your account. In some exceptional cases, LinkedIn retains certain data in aggregated and anonymized form even after you delete your account. As soon as you delete your account, other people will no longer be able to view your data within one day. LinkedIn generally deletes the data within 30 days. However, LinkedIn retains data if required to do so by law. Data that can no longer be linked to specific individuals remains stored even after the account is closed. The data is stored on various servers in the United States and presumably also in Europe.
How can I delete my data or prevent it from being stored?
You have the right to access and delete your personal data at any time. You can manage, edit, and delete your data in your LinkedIn account. You can also request a copy of your personal data from LinkedIn.Here’s how to access your account data in your LinkedIn profile:On LinkedIn, click your profile icon and select „Settings & Privacy.“ Now click „Privacy,“ and then click „Change„ in the “How LinkedIn uses your data„ section. In just a few moments, you can download selected data about your web activity and account history.You also have the option to prevent LinkedIn from processing your data directly in your browser. As mentioned above, LinkedIn stores most data via cookies that are set in your browser. You can manage, disable, or delete these cookies. Depending on which browser you use, the process works slightly differently. Under the “Cookies” section, you’ll find links to the respective guides for the most popular browsers.You can also generally configure your browser so that you are always notified when a cookie is about to be set. This allows you to decide on a case-by-case basis whether you want to allow the cookie or not.
Legal Basis
If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of fast and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.LinkedIn also processes your data in the U.S., among other places. LinkedIn is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, LinkedIn uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, LinkedIn commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.For more information about the standard contractual clauses on LinkedIn, visit
https://de.linkedin.com/legal/l/dpa or
https://www.linkedin.com/legal/l/eu-sccs.We have tried to provide you with the most important information about how LinkedIn processes data. On
https://www.linkedin.com/legal/privacy-policy Learn more about how the social media network LinkedIn processes data.
Pinterest Privacy Policy
| Pinterest Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as user behavior data, information about your device, your IP address, and search terms.
You can find more details below in the Privacy Policy.
📅 Retention period: until Pinterest no longer needs the data for its own purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Pinterest?
We use buttons and widgets from the social media network Pinterest, operated by Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103, USA, on our website. For the European region, the Irish company Pinterest Europe Ltd. (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland) is responsible for all data protection-related matters.Pinterest is a social network that specializes in visual content and photographs. The name is a combination of the words „pin“ and „interest.“ Users can use Pinterest to share their hobbies and interests and view each other’s profiles—featuring images—either publicly or within specific groups.
Why do we use Pinterest?
Pinterest has been around for several years now, and this social media platform remains one of the most visited and valued platforms. Pinterest is particularly well-suited for our industry because the platform is primarily known for its beautiful and interesting images. That’s why we’re naturally active on Pinterest and want to showcase our content there as well, beyond our website. The data collected may also be used for advertising purposes, so that we can show promotional messages to exactly those people who are interested in our services or products.
What data does Pinterest process?
So-called log data may be stored. This includes information about your browser, IP address, the address of our website, and the activities you perform on it (for example, when you click the “Save” or “Pin” button), search histories, the date and time of the request, and cookie and device data. When you interact with an embedded Pinterest feature, cookies that store various types of data may also be set in your browser. In most cases, the log data mentioned above, default language settings, and clickstream data are stored in cookies. Pinterest defines clickstream data as information about your website behavior.If you have a Pinterest account and are logged in, the data collected through our site may be added to your account and used for advertising purposes. When you interact with our embedded Pinterest features, you are usually redirected to the Pinterest site. Here is a sample list of cookies that will then be set in your browser.
Name: _auth
Value: 0
Purpose: The cookie is used for authentication. It can store, for example, a value such as your “username.”.
Expiration Date: after a year
Name: _pinterest_referrer
Value: 1
Purpose: The cookie records that you arrived at Pinterest via our website. This means that the URL of our website is stored.
Expiration Date: after the meeting ends
Name: _pinterest_sess
Value: …9HRHZvVE0rQlUxdG89
Purpose: This cookie is used for logging in to Pinterest and contains user IDs, authentication tokens, and timestamps.
Expiration Date: after a year
Name: _routing_id
Value: “8d850ddd-4fb8-499c-961c-77efae9d4065112279866-8”
Purpose: The cookie contains an assigned value that is used to identify a specific routing destination.
Expiration Date: after one day
Name: cm_sub
Value: denied
Purpose: This cookie stores a user ID and a timestamp.
Expiration Date: after a year
Name: csrftoken
Value: 9e49145c82a93d34fd933b0fd8446165112279866-1
Purpose: This cookie is most likely set for security reasons to prevent forged requests. However, we were unable to determine the exact reason.
Expiration Date: after a year
Name: sessionFunnelEventLogged
Value: 1
Purpose: We have not yet been able to find any further information about this cookie.
Expiration Date: after one day
How long and where is the data stored?
Pinterest generally stores the collected data until it is no longer needed for the company’s purposes. As soon as data retention is no longer necessary—for example, to comply with legal requirements—the data is either deleted or anonymized so that you can no longer be identified as an individual. The data may also be stored on servers in the United States.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party providers such as Pinterest at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.Since cookies may be used in embedded Pinterest elements, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) for the purpose of fast and effective communication with you or other customers and business partners. However, we only use this tool if you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.Pinterest also processes your data in the United States, among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.Pinterest uses so-called standard contractual clauses (= Art. 46. (2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, Pinterest commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.For more information about Pinterest's standard contractual clauses, visit
https://policy.pinterest.com/de/privacy-policy#section-residents-of-the-eea.We have tried to provide you with the most important information about how Pinterest processes data. On
https://policy.pinterest.com/de/privacy-policy You can learn more about Pinterest's data policies.
| X (formerly Twitter) Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as user behavior data, information about your device, and your IP address.
You can find more details below in the Privacy Policy.
📅 Retention period: X deletes data collected from other websites after 30 days at the latest
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests) |
What is X?
We have incorporated X features into our website. These include, for example, embedded tweets, timelines, buttons, and hashtags. X is a microblogging service and social media platform operated by the American company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For the European region, Twitter International Unlimited Company (One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland) is responsible for the processing of personal data.To the best of our knowledge, simply embedding X features does not result in the transfer of any personal data or data regarding your web activities to X within the European Economic Area or Switzerland. Only when you interact with X features—such as by clicking a button—can data be sent to X, where it is stored and processed. We have no control over this data processing and bear no responsibility for it. In this Privacy Policy, we aim to provide you with an overview of what data X stores, what X does with this data, and how you can largely protect yourself from data transmission.For some, X is a messaging service; for others, a social media platform; and still others refer to it as a microblogging service. All of these terms are valid and mean more or less the same thing.Both individuals and businesses use X to communicate with interested people via short messages. X allows only 280 characters per message. These messages are called „tweets.“ Unlike Facebook, for example, the service does not focus on building a network of “friends,” but rather aims to be seen as a global and open messaging platform. On X, you can also maintain an anonymous account, and tweets can be deleted either by the company or by the users themselves.
Why do we use X on our website?
Like many other websites and companies, we strive to offer our services and communicate with our customers through various channels. X, in particular—which many people probably know better as Twitter—has become a favorite of ours as a useful „small“ messaging service. We regularly tweet or retweet exciting, funny, or interesting content. We realize that you can’t follow every channel separately. After all, you have other things to do as well. That’s why we’ve integrated X features into our website. You can follow our X activity „right here“ or access our X page via a direct link. By integrating these features, we aim to enhance our service and improve the user experience on our website.
What data does X store?
On some of our subpages, you’ll find built-in X features. When you interact with X content—such as by clicking a button—X may collect and store data, even if you don’t have an X account yourself. X refers to this data as “log data.” This includes demographic data, browser cookie IDs, your smartphone’s ID, hashed email addresses, and information about which pages you’ve visited on X and what actions you’ve taken. Of course, X stores more data if you have an X account and are logged in. Until now, this data has been stored using cookies. Cookies are small text files that are usually placed in your browser and transmit various types of information to X.We’ll now show you which cookies are set when you’re not logged into X but visit a website with built-in X features. Please consider this list as an example. We cannot guarantee that it is exhaustive, as the selection of cookies is constantly changing and depends on your individual interactions with X content.These cookies were used in our test:
Name: personalization_id
Value: “v1_cSJIsogU51SeE112279866”
Purpose: This cookie stores information about how you use the website and which advertisement may have led you to X.
Expiration Date: after 2 years
Name: long
Value: de
Purpose: This cookie stores your default or preferred language.
Expiration Date: after the meeting ends
Name: guest_id
Value: 112279866v1%3A157132626
Purpose: This cookie is set to identify you as a guest.
Expiration Date: after 2 years
Name: fm
Value: 0
Purpose: Unfortunately, we were unable to determine the purpose of this cookie.
Expiration Date: after the meeting ends
Name: external_referer
Value: 1122798662beTA0sf5lkMrlGt
Purpose: This cookie collects anonymous data, such as how often you visit X and how long you stay on X.
Expiration Date: After 6 days
Name: eu_cn
Value: 1
Purpose: This cookie tracks user activity and is used for various advertising purposes by X.
Expiration Date: After a year
Name: ct0
Value: c1179f07163a365d2ed7aad84c99d966
Purpose: Unfortunately, we were unable to find any information about this cookie.
Expiration Date: after 6 hours
Name: _twitter_sess
Value: 53D%253D–dd0248112279866-
Purpose: This cookie allows you to use features on the X website.
Expiration Date: after the meeting ends
Note: X also works with third-party providers. That is why we detected the three Google Analytics cookies—_ga, _gat, and _gid—during our test.X uses the collected data, on the one hand, to better understand user behavior and thereby improve its own services and advertising offerings; on the other hand, the data is also used for internal security measures.
How long and where is the data stored?
When X collects data from other websites, that data is deleted, aggregated, or otherwise anonymized after a maximum of 30 days. X’s servers are located in various data centers in the United States. Accordingly, it can be assumed that the collected data is gathered and stored in the United States. Based on our research, we were unable to determine conclusively whether X also has its own servers in Europe. In general, X may store the collected data until it is no longer useful to the company, until you delete the data, or until a statutory retention period expires.
How can I delete my data or prevent it from being stored?
In its privacy policy, X repeatedly emphasizes that it does not store any data from visits to external websites if you or your browser are located in the European Economic Area or Switzerland. However, if you interact directly with X, X will of course also store data about you.If you have an X account, you can manage your data by clicking „More“ under the „Profile“ button. Then click „Settings and Privacy.“ Here, you can customize your data processing settings.If you do not have an X account, you can go to
twitter.com Go to that page and then click on „Personalization.“ Under the „Personalization and Data“ section, you can manage the data we’ve collected about you.As mentioned above, most data is stored via cookies, which you can manage, disable, or delete in your browser. Please note that you can only “manage” cookies in the browser you’ve selected. This means that if you use a different browser in the future, you’ll need to manage your cookies there again according to your preferences. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.You can also configure your browser to notify you about each individual cookie. This allows you to decide on a case-by-case basis whether to accept a cookie or not.X also uses the data for personalized advertising both on and off X. In the settings, under „Personalization and Data,“ you can turn off personalized advertising. If you use X in a browser, you can turn off personalized advertising under
https://optout.aboutads.info/?c=2&lang=EN Disable.
Legal Basis
If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of fast and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.X also processes your data in the United States, among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the United States) or for data transfers to those countries, X uses so-called standard contractual clauses (= Art. 46. (2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, X commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deFor more information on the standard contractual clauses at X, see
https://gdpr.twitter.com/en/controller-to-controller-transfers.html.We hope we have provided you with a general overview of how X processes data. We do not receive any data from X, nor are we responsible for what X does with your data. If you have any further questions on this topic, we recommend that you review X’s privacy policy at
https://twitter.com/de/privacy.
Blogs and Publications: Introduction
| Blogs and Publications Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To present and optimize our services, facilitate communication among website visitors, implement security measures, and manage the website
📓 Data Processed: Data such as contact information, IP addresses, and published content.
You can find more details in the descriptions of the tools used.
📅 Retention period: Depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract) |
What are blogs and publishing platforms?
We use blogs and other communication tools on our website that allow us to communicate with you and you to communicate with us. In doing so, we may store and process data about you. This may be necessary so that we can display content appropriately, ensure that communication works properly, and enhance security. Our privacy policy provides a general overview of what data we may process from you. Specific details regarding data processing always depend on the tools and features used. You can find detailed information about data processing in the privacy policies of the individual providers.
Why do we use blogs and publishing platforms?
Our main goal with this website is to provide you with interesting and engaging content, and at the same time, your opinions and contributions are important to us. That’s why we want to foster a meaningful interactive exchange between us and you. With a variety of blogs and opportunities to publish, we can achieve exactly that. For example, you can write comments on our content, respond to other comments, or, in some cases, even write your own posts.
What data is processed?
Exactly which data is processed always depends on the communication features we use. Very often, the IP address, username, and published content are stored. This is done primarily to ensure security, prevent spam, and take action against illegal content. Cookies may also be used for data storage. These are small text files that are stored in your browser along with information. For more details on the data collected and stored, please refer to our individual sections and the privacy policy of the respective provider.
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. For example, post and comment features store data until you revoke your consent to data storage. In general, personal data is stored only for as long as is strictly necessary to provide our services.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party communication tools at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.Since cookies may also be used in publishing media, we recommend that you also review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.
Legal Basis
We use these communication tools primarily based on our legitimate interests (Art. 6(1)(f) GDPR) in maintaining prompt and effective communication with you or other customers, business partners, and visitors. To the extent that such use serves to fulfill or initiate contractual relationships, the legal basis is also Article 6(1), sentence 1(b) of the GDPR.Certain processing activities, in particular the use of cookies and the use of comment or messaging features, require your consent. If and to the extent that you have consented to the processing and storage of your data through integrated publishing media, this consent serves as the legal basis for data processing (Article 6(1)(a) of the GDPR). Most of the communication features we use set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.Information about specific tools—if available—can be found in the following sections.
Blog Posts and Comment Features | Privacy Policy
There are various online communication tools that we can use on our website. For example, we use blog posts and comment features. This gives you the opportunity to comment on content or write posts. If you use this feature, your IP address may be stored for security reasons. This helps us protect against unlawful content, such as insults, unauthorized advertising, or prohibited political propaganda. To determine whether comments are spam, we may also store and process user information based on our legitimate interest. If we launch a survey, we also store your IP address for the duration of the survey to ensure that all participants vote only once. Cookies may also be used for storage purposes. All data we store about you (such as content or personal information) will remain stored until you object.
WordPress Emojis Privacy Policy
We also use so-called emojis and smileys on our blog. We probably don’t need to explain exactly what emojis are here. You’re familiar with these smiling, angry, or sad faces. They are graphic elements or files that we make available and that are loaded from another server. The service provider for retrieving WordPress emojis and smileys is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. This third-party provider stores your IP address in order to transmit the emoji files to your browser.Automattic processes your data, including in the United States. Automattic is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Automattic uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Automattic commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.The Data Processing Agreements, which are based on the Standard Contractual Clauses, can be found at
https://wordpress.com/support/data-processing-agreements/.You can learn more about the data processed when using WordPress emojis in the Privacy Policy at
https://automattic.com/privacy/.
| Cookie Consent Management Platform Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To obtain and manage consent for specific cookies and, consequently, the use of specific tools
📓 Data Processed: Data used to manage cookie settings, such as IP address, time of consent, type of consent, and individual consents. You can find more details on this under the respective tool used.
📅 Retention period: Depends on the tool used; you should expect periods of several years
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is a cookie consent management platform?
We use Consent Management Platform (CMP) software on our website, which makes it easier for both us and you to handle scripts and cookies correctly and securely. The software automatically generates a cookie pop-up, scans and monitors all scripts and cookies, provides you with the cookie consent required under data protection laws, and helps both us and you keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide for yourself whether and which scripts and cookies you allow or do not allow. The following diagram illustrates the relationship between the browser, web server, and CMP.

Why do we use a cookie management tool?
Our goal is to provide you with the highest possible level of transparency regarding data protection. We are also legally required to do so. We want to inform you as thoroughly as possible about all tools and cookies that may store and process your data. It is also your right to decide for yourself which cookies you accept and which you do not. To grant you this right, we first need to know exactly which cookies are present on our website. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we are aware of all cookies and can provide you with GDPR-compliant information about them. You can then accept or reject cookies using the consent system.
What data is processed?
Using our cookie management tool, you can manage each individual cookie yourself and have full control over the storage and processing of your data. Your consent is stored so that we do not have to ask for it every time you visit our website and so that we can provide proof of your consent if required by law. This information is stored either in an opt-in cookie or on a server. The retention period for your cookie consent varies depending on the provider of the cookie management tool. In most cases, this data (such as a pseudonymous user ID, the time of consent, details regarding cookie categories or tools, browser, and device information) is stored for up to two years.
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases, you should expect a storage period of several years. You can usually find detailed information about the duration of data processing in the respective privacy policies of the individual providers.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.Information on specific cookie management tools—if available—can be found in the following sections.
Legal Basis
If you consent to cookies, your personal data will be processed and stored via these cookies. If, as a result of your
Consent (Article 6(1)(a) of the GDPR) Since we are permitted to use cookies, this consent also serves as the legal basis for the use of cookies and the processing of your data. To manage consent for cookies and enable you to provide your consent, we use cookie consent management platform software. The use of this software allows us to operate the website efficiently and in compliance with the law, which is a
legitimate interest (Article 6(1)(f) of the GDPR).
Cookiebot Privacy Policy
| Cookiebot Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To obtain consent for certain cookies and, consequently, the use of certain tools
📓 Data Processed: Data used to manage cookie settings, such as IP address, time of consent, type of consent, and individual consents. You can find more details about this under the respective tool used.
📅 Retention period: The data is deleted after one year
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Cookiebot?
We use features from the provider Cookiebot on our website. Cookiebot is operated by Cybot A/S, Havnegade 39, 1058 Copenhagen, DK. Among other things, Cookiebot allows us to provide you with a comprehensive cookie notice (also known as a cookie banner or cookie notice). By using this feature, your data may be sent to, stored by, and processed by Cookiebot or Cybot. In this privacy policy, we explain why we use Cookiebot, what data is transmitted, and how you can prevent this data transmission.Cookiebot is a software product developed by Cybot. The software automatically generates a GDPR-compliant cookie notice for our website visitors. In addition, the technology behind Cookiebot scans, monitors, and evaluates all cookies and tracking measures on our website.
Why do we use Cookiebot on our website?
We take data protection very seriously. We want to show you exactly what happens on our website and which of your data is stored. Cookiebot helps us maintain a clear overview of all our cookies (first-party and third-party cookies). This allows us to provide you with accurate and transparent information about the use of cookies on our website. You’ll always receive an up-to-date cookie notice that complies with data protection regulations, and you can decide for yourself which cookies to allow and which to block.
What data does Cookiebot store?
If you allow cookies, the following data will be transmitted to Cybot, stored, and processed.
- IP address (in anonymized form; the last 3 digits are set to 0)
- Date and time of your consent
- our website URL
- technical browser data
- encrypted, anonymous key
- the cookies you have accepted (as proof of consent)
The following cookies are set by Cookiebot if you have consented to the use of cookies:
Name: CookieConsent
Value: {stamp:’P7to4eNgIHvJvDerjKneBsmJQd9112279866-2
Purpose: This cookie stores your consent status. This allows our website to read and honor your current status during future visits.
Expiration Date: after a year
Name: CookieConsentBulkTicket
Value: kDSPWpA%2fjhljZKClPqsncfR8SveTnNWhys5NojaxdFYBPjZ2PaDnUw%3d%3112279866-6
Purpose: This cookie is set when you allow all cookies and have thus enabled “collective consent.” The cookie then stores its own random and unique ID.
Expiration Date: after a year
Note: Please note that this is a sample list and we cannot guarantee that it is complete. In the cookie policy at
https://www.cookiebot.com/de/cookie-declaration/ See which other cookies may be used.According to Cybot’s privacy policy, the company does not sell personal data. However, Cybot does share data with trusted third parties or subcontractors who help the company achieve its business objectives. Data is also shared when required by law.
How long and where is the data stored?
All collected data is transmitted, stored, and forwarded exclusively within the European Union. The data is stored in an Azure data center (Microsoft is the cloud provider). On
https://azure.microsoft.com/de-de/explore/global-infrastructure/geographies/ Learn more about all „Azure regions.“ All user data is deleted by Cookiebot 12 months after registration (cookie consent) or immediately after cancellation of the Cookiebot service.
How can I delete my data or prevent it from being stored?
You have the right to access and delete your personal data at any time. For example, you can prevent the collection and storage of data by rejecting the use of cookies via the cookie notice. Your browser also offers another way to prevent data processing or manage it according to your preferences. Cookie management works slightly differently depending on the browser. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.
Legal Basis
If you consent to cookies, your personal data will be processed and stored via these cookies. If, as a result of your
Consent (Article 6(1)(a) of the GDPR) Since we are permitted to use cookies, this consent also serves as the legal basis for the use of cookies and the processing of your data. We use the Cookiebot to manage consent to cookies and to enable you to provide your consent. The use of this software enables us to operate the website efficiently and in compliance with the law, which is a
legitimate interest (Article 6(1)(f) of the GDPR).If you would like to learn more about the privacy policy of „Cookiebot“ or its parent company, Cybot, we recommend that you review the privacy policy at
https://www.cookiebot.com/de/privacy-policy/ to read through.
Payment Providers: Introduction
| Payment Provider Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To enable and optimize the payment process on our website
📓 Data Processed: Data such as name, address, banking information (account number, credit card number, passwords, TANs, etc.), IP address, and contract details
You can find more details about this in the information provided by the respective payment provider tool.
📅 Retention period: Depends on the payment provider used
⚖️ Legal basis: Art. 6(1)(b) GDPR (performance of a contract) |
What is a payment provider?
We use online payment systems on our website that enable us and you to complete the payment process securely and smoothly. In the course of this, personal data may, among other things, be sent to, stored by, and processed by the respective payment provider. Payment providers are online payment systems that allow you to place an order via online banking. The payment transaction is processed by the payment provider you select. We then receive notification of the completed payment. Any user with an active online banking account that includes a PIN and TAN can use this method. There are very few banks left that do not offer or accept such payment methods.
Why do we use payment providers on our website?
Of course, we want to provide the best possible service through our website and integrated online store so that you feel comfortable on our site and take advantage of our offerings. We know that your time is valuable and that payment processing, in particular, needs to be quick and seamless. For these reasons, we offer a variety of payment providers. You can choose your preferred payment provider and pay in the way you’re used to.
What data is processed?
Exactly which data is processed depends, of course, on the specific payment provider. However, in general, data such as your name, address, and banking information (account number, credit card number, passwords, TANs, etc.) is stored. This data is necessary to carry out a transaction at all. In addition, certain contractual and user data—such as when you visit our website, what content you’re interested in, or which subpages you click on—may also be stored. Most payment providers also store your IP address and information about the computer you’re using.The data is generally stored and processed on the payment providers’ servers. We, as the website operator, do not receive this data. We are only informed whether the payment was successful or not. For identity and credit checks, payment providers may forward data to the appropriate authorities. The terms of service and privacy policies of the respective provider always apply to all payment transactions. Therefore, please always review the payment provider’s Terms of Service and Privacy Policy. You also have the right at any time, for example, to have data deleted or corrected. Please contact the respective service provider regarding your rights (right of withdrawal, right to access information, and right to object).
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details. In general, we process personal data only for as long as is strictly necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be exceeded. For example, we retain accounting documents related to a contract (invoices, contract documents, bank statements, etc.) for 10 years (Section 147 of the German Fiscal Code [AO]) and other relevant business records for 6 years (Section 247 of the German Commercial Code [HGB]) from the date they are generated.
Right to Object
You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the data controller of the payment provider you are using at any time. You can find contact information either in our specific privacy policy or on the website of the respective payment provider.You can delete, disable, or manage the cookies that payment providers use for their functions in your browser. The process varies depending on which browser you use. Please note, however, that doing so may prevent the payment process from working properly.
Legal Basis
We therefore offer the following services for the management of contractual and legal relationships:
(Art. 6(1)(b) of the GDPR) In addition to traditional banks and credit institutions, there are also other payment service providers. In the privacy policies of the individual payment providers (such as, for example,
Amazon Payments,
Apple Pay or
Discover) provides you with a detailed overview of data processing and data storage. In addition, if you have any questions regarding data protection, you can always contact the responsible parties.Information about specific payment providers—if available—can be found in the following sections.
PayPal Privacy Policy
| PayPal Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize the payment process on our website
📓 Data Processed: Data such as name, address, banking information (account number, credit card number, passwords, TANs, etc.), IP address, and contract details may be processed.
You can find more details on this further down in this Privacy Policy.
📅 Retention period: Data is generally stored until the partnership with PayPal is terminated
⚖️ Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(a) GDPR (consent) |
What is PayPal?
We use the online payment service PayPal on our website. The service provider is the American company PayPal Inc. PayPal Europe (S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg) is responsible for the European region.PayPal allows all users to send and receive money electronically. The company was founded in 1998 and, with over 325 million active customers, is now one of the best-known and largest online payment service providers worldwide.
Why do we use PayPal on our website?
There are several reasons why we use PayPal and offer it on our website. Since PayPal is one of the best-known online payment providers, many of our website visitors also use and trust this service. PayPal also offers high security standards for digital money transfers. The service uses various encryption methods to protect your personal data as effectively as possible. We also appreciate PayPal’s ease of use and the ability to make international payments in different currencies. Transactions are typically processed very quickly, which is another benefit for both us and you as a customer.
What data does PayPal process?
In its Privacy Policy, PayPal distinguishes between various categories of personal data that may be processed through the use of the service. These include registration and contact information, identification and signature data, payment information, information about imported contacts, data from your account profile, device data such as your IP address, location data, and so-called derived data. This refers to information that can be derived from transactions or other data. This may include, for example, purchasing habits, behavioral patterns, creditworthiness, or personal preferences.There is also personal data collected by third parties (such as identity verification providers, fraud detection providers, or your bank). This data includes information from credit bureaus, transaction data, information regarding legal requirements, technical usage data, location data, and, once again, derived data.PayPal and its partners also use tracking technologies such as cookies, pixel tags, web beacons, and widgets to recognize you as a user, customize content, and perform analytics for interest-based advertising.
How long and where is the data stored?
In general, PayPal retains data for as long as necessary to fulfill its obligations and within the scope of the intended purpose. Personal data necessary for the customer relationship is retained for up to 10 years after the relationship ends. If PayPal is subject to a legal obligation, the retention period for personal data is determined by the applicable law (e.g., insolvency law). PayPal also retains personal data for as long as necessary if retention is advisable in light of potential legal disputes.Since PayPal is a global company, the service also has data centers worldwide where your data may be stored. This means that your data may be stored on PayPal servers outside your country and outside the scope of the GDPR.
How can I delete my data or prevent it from being stored?
You have the right at any time to access, correct, or delete your personal data, as well as to restrict its processing. You may also withdraw your consent to the processing of your data at any time.If you wish to disable, delete, or manage cookies in general, you will find the relevant links to the instructions for the most popular browsers in the „Cookies“ section.
Legal Basis
We have a legitimate interest in integrating PayPal as an external payment service to make our offerings more attractive and to improve them both technically and economically. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). Please note that you can only use PayPal if you enter into a contractual relationship with PayPal. In this case, it may be necessary to provide additional data protection and contractual declarations (e.g., consent).PayPal also processes your data in the United States, among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the United States) or for data transfers to those countries, PayPal uses so-called standard contractual clauses (= Art. 46. (2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, PayPal commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deFor more information about the standard contractual clauses and the data processed when using PayPal, please see the Privacy Policy at
https://www.paypal.com/webapps/mpp/ua/privacy-full.
Stripe Privacy Policy
| Stripe Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize the payment process on our website
📓 Data Processed: Data such as name, address, banking information (account number, credit card number, passwords, TANs, etc.), IP address, and contract details
You can find more details on this further down in this Privacy Policy
📅 Retention period: Data is stored until the partnership with Stripe is terminated
⚖️ Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(a) GDPR (consent) |
What is Stripe?
We use a payment tool on our website provided by Stripe, an American technology company and online payment service. For customers within the EU, Stripe Payments Europe (Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) is responsible. This means that if you choose Stripe as your payment method, your payment will be processed through Stripe Payments. In this process, data necessary for the payment transaction is transmitted to and stored by Stripe. In this privacy policy, we provide an overview of this data processing and storage by Stripe and explain why we use Stripe on our website.The technology company Stripe offers payment solutions for online transactions. Stripe allows us to accept credit and debit card payments in our online store. Stripe handles the entire payment process. One major advantage of Stripe is that you never have to leave our website or the online store during the payment process, and payments are processed very quickly.
Why do we use Stripe for our website?
Of course, we want to provide the best possible service through our website and our integrated online store so that you feel comfortable on our site and take advantage of our offerings. We know that your time is valuable, which is why payment processing in particular must be fast and seamless. In addition to our other payment providers, we’ve partnered with Stripe to ensure secure and fast payment processing.
What data does Stripe store?
If you choose Stripe as your payment method, your personal data will also be transmitted to Stripe and stored there. This data consists of transaction information. This data includes, for example, the payment method (i.e., credit card, debit card, or account number), bank routing number, currency, the amount, and the date of payment. During a transaction, your name, email address, billing or shipping address, and sometimes your transaction history may also be transmitted. This data is necessary for authentication. In addition, to prevent fraud, for financial reporting, and to be able to provide its services in full, Stripe may also collect your name, address, phone number, and country, in addition to technical data about your device (such as your IP address).Stripe does not sell any of your data to independent third parties, such as marketing agencies or other companies that are not affiliated with Stripe. However, the data may be shared with internal departments, a limited number of external Stripe partners, or to comply with legal requirements. Stripe also uses cookies to collect data. Here is a list of cookies that Stripe may set during the payment process:
Name: m
Value: edd716e9-d28b-46f7-8a55-e05f1779e84e040456112279866-5
Purpose: This cookie appears when you select a payment method. It stores and recognizes whether you are accessing our website from a computer, tablet, or smartphone.
Expiration Date: after 2 years
Name: __stripe_mid__
Value: fc30f52c-b006-4722-af61-a7419a5b8819875de9112279866-1
Purpose: This cookie is required to process a credit card transaction. To do so, the cookie stores your session ID.
Expiration Date: after a year
Name: __stripe_sid
Value: 6fee719a-c67c-4ed2-b583-6a9a50895b122753fe
Purpose: This cookie also stores your ID and is used by Stripe for the payment process on our website.
Expiration Date: after the meeting has ended
How long and where is the data stored?
Personal data is generally stored for the duration of the service provision. This means that the data is stored until we terminate our partnership with Stripe. However, in order to comply with legal and regulatory obligations, Stripe may store personal data beyond the duration of the service provision. Since Stripe is a global company, the data may also be stored in any country where Stripe offers services. This means that data may also be stored outside your country, for example, in the United States.
How can I delete my data or prevent it from being stored?
Please note that when you use this tool, your data may be stored and processed outside the EU. Under current European data protection law, most third countries (including the United States) are considered unsafe. Therefore, data may not simply be transferred to, stored in, or processed in non-secure third countries unless there are appropriate safeguards (such as EU Standard Contractual Clauses) in place between us and the non-European service provider.You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the Stripe team at any time via
https://support.stripe.com/contact/email Contact us.You can delete, disable, or manage the cookies that Stripe uses for its features in your browser. The process varies depending on which browser you use. In the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.
Legal Basis
We therefore offer the following services for the management of contractual and legal relationships:
(Art. 6(1)(b) of the GDPR) In addition to traditional banks and credit institutions, we also use the payment service provider Stripe. Your consent is also required for the successful use of this service.
(Art. 6(1)(a) of the GDPR), to the extent that cookies are required for the service to function.Stripe also processes your data in the U.S., among other places. Stripe is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Stripe uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Stripe commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.For more information about the Standard Contractual Clauses and the data processed when using Stripe, please see the Privacy Policy at
https://stripe.com/at/privacy.
| External Online Platforms: Privacy Policy Summary
👥 Data Subjects: Website visitors or visitors to external online platforms
🤝 Purpose: To present and optimize our services, and to contact visitors and prospective customers
📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.
You can find more details on the respective platform used.
📅 Retention period: Depends on the platforms used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are external online platforms?
In order to offer our services or products outside of our website, we also use external platforms. These are mostly online marketplaces such as Amazon or eBay. In addition to our responsibility for data protection, the privacy policies of the external platforms we use also apply. This is especially the case when our products are purchased through the platform—that is, when a payment transaction takes place. Furthermore, most platforms also use your data to optimize their own marketing efforts. For example, using the data collected, the platform can tailor advertisements precisely to the interests of customers and website visitors.
Why do we use external online platforms?
In addition to our website, we also want to offer our products on other platforms to reach more customers. External online marketplaces such as Amazon, eBay, and Digistore24 provide large sales platforms that offer our products to people who may not be familiar with our website. It may also happen that embedded elements on our site redirect users to an external online platform. Data processed and stored by the online platform in question is used by the company both to log the payment transaction and to conduct web analytics.The goal of these analyses is to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a platform, the analyzed data can be used to draw conclusions about your interests and create so-called user profiles. This also enables the platforms to present you with tailored advertisements or products. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.Please note that when you use these platforms or our integrated features, your data may also be processed outside the European Union, as online platforms such as Amazon or eBay are U.S. companies. As a result, you may no longer be able to easily assert or enforce your rights regarding your personal data.
What data is processed?
Exactly which data is stored and processed depends on the specific external platform. However, it usually includes data such as phone numbers, email addresses, information you enter into a contact form, user data (such as which buttons you click and when you visited which pages), information about your device, and your IP address. Very often, most of this data is stored in cookies. If you have your own profile on an external platform and are logged in there, data may be linked to that profile. The collected data is stored on the servers of the platforms used and processed there. You can find out exactly how an external platform stores, manages, and processes data in its respective privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the platform directly.
Duration of Data Processing
We provide information below regarding the duration of data processing, to the extent that we have further details. For example, Amazon stores data until it is no longer needed for its own purposes. In general, we process personal data only for as long as is strictly necessary to provide our services and products.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies at any time. You can do this either through our cookie management tool or through the opt-out features on the respective external platform. Furthermore, you can prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.Since cookies may be used, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective external platforms.
Legal Basis
If you have consented to the processing and storage of your data by external platforms, this applies
Consent as the legal basis for data processing
(Art. 6(1)(a) of the GDPR). In general, if consent has been given, your data will also be processed on the basis of a
legitimate interest (Art. 6(1)(f) of the GDPR) stored and processed for the purpose of ensuring prompt and effective communication with you or other customers and business partners. If we have embedded elements from external platforms on our website, we use them only to the extent that you have given your consent.You can find information about specific external platforms—if available—in the following sections.
Vercel Privacy Policy
We use Vercel, a cloud deployment platform, on our website. The service provider is the U.S. company Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789.Vercel processes your data, including in the United States. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.So-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR) serve as the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the United States) or for data transfers to those countries. Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, Vercel commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Data Processing Addendum, which is consistent with the Standard Contractual Clauses, can be found at
https://vercel.com/legal/dpa.For more information about the data processed when using Vercel, please see the Privacy Policy at
https://vercel.com/legal/privacy-policy.
Audio & Video Introduction
| Audio & Video Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.
You can find more details below in the relevant privacy policies.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are audio and video elements?
We have embedded audio and video elements on our website so that you can, for example, watch videos or listen to music and podcasts directly through our website. The content is provided by service providers. All content is therefore retrieved from the providers’ respective servers.These are embedded features from platforms such as YouTube, Vimeo, or Spotify. Use of these platforms is generally free, but paid content may also be published. With the help of these embedded features, you can listen to or watch the respective content via our website.When you use audio or video elements on our website, your personal data may also be transmitted to, processed by, and stored by the service providers.
Why do we use audio and video elements on our website?
Of course, we want to provide you with the best content on our website. And we realize that content is no longer conveyed solely through text and static images. Instead of simply giving you a link to a video, we offer audio and video formats directly on our website that are entertaining or informative—and ideally, both. This expands our service and makes it easier for you to access interesting content. Thus, in addition to our text and images, we also offer video and/or audio content.
What data is stored by audio and video elements?
When you visit a page on our website that contains, for example, an embedded video, your server connects to the service provider’s server. In the process, your data is also transmitted to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider. This usually includes your IP address, browser type, operating system, and other general information about your device. In addition, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which buttons you clicked, or which website you used to access the service. All of this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymized data is typically stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
Duration of Data Processing
You can find out exactly how long data is stored on third-party providers’ servers either further down in the privacy policy for the respective tool or in the provider’s privacy policy. As a general rule, personal data is processed only for as long as is strictly necessary to provide our services or products. This generally applies to third-party providers as well. In most cases, you can assume that certain data will be stored on third-party servers for several years. Data stored in cookies, in particular, can be retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. The lawfulness of the processing up until the time of revocation remains unaffected.Since cookies are usually also used by the embedded audio and video features on our site, you should also read our general privacy policy regarding cookies. You can find more detailed information about how your data is handled and stored in the privacy policies of the respective third-party providers.
Legal Basis
If you have consented to the processing and storage of your data through embedded audio and video elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded audio and video elements if you have given your consent.
YouTube Privacy Policy
| YouTube Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.
You can find more details below in this Privacy Policy.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is YouTube?
We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video platform that has been a subsidiary of Google since 2006. The video platform is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has an embedded YouTube video, your browser automatically connects to YouTube’s or Google’s servers. Depending on your settings, various types of data are transmitted during this process. Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing within Europe.Below, we’ll explain in more detail what data is processed, why we’ve embedded YouTube videos, and how you can manage or delete your data.On YouTube, users can watch, rate, comment on, and upload videos for free. Over the past few years, YouTube has become one of the most important social media channels worldwide. To enable us to display videos on our website, YouTube provides a code snippet that we have embedded on our site.
Why do we use YouTube videos on our website?
YouTube is the video platform with the most visitors and the best content. We strive to provide you with the best possible user experience on our website. And, of course, interesting videos are a must. Through our embedded videos, we provide you with additional helpful content alongside our text and images. In addition, the embedded videos make our website easier to find on Google. Even when we run ads through Google Ads, Google—thanks to the data it collects—can ensure that these ads are shown only to people who are interested in our offerings.
What data does YouTube store?
As soon as you visit one of our pages that has an embedded YouTube video, YouTube sets at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually associate your interactions on our website with your profile using cookies. This includes data such as session duration, bounce rate, approximate location, and technical information such as browser type, screen resolution, or your internet service provider. Additional data may include contact information, any ratings you’ve given, sharing content via social media, or adding content to your YouTube favorites.If you are not signed in to a Google or YouTube account, Google stores data using a unique identifier linked to your device, browser, or app. This ensures, for example, that your preferred language setting is retained. However, much of your interaction data cannot be stored because fewer cookies are set.In the following list, we show cookies that were set in a browser test. We list cookies that are set when you are not signed in to a YouTube account, as well as cookies that are set when you are signed in. This list is not exhaustive, as user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y112279866-1
Purpose: This cookie stores a unique ID to track statistics on the video that was viewed.
Expiration Date: after the meeting ends
Name: PREF
Value: f1=50000000
Purpose: This cookie also records your unique ID. Google uses PREF to collect statistics on how you use YouTube videos on our website.
Expiration Date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiration Date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user's bandwidth on our websites (which include embedded YouTube videos).
Expiration Date: After 8 monthsOther cookies that are set when you are signed in to your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7112279866-
Purpose: This cookie is used to create a profile based on your interests. The data is used for personalized advertisements.
Expiration Date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user's consent to use various Google services. CONSENT also serves a security purpose by verifying users and protecting user data from unauthorized attacks.
Expiration Date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile based on your interests. This data helps us display personalized ads.
Expiration Date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login details.
Expiration Date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.
Expiration Date: after 2 years
Name: SID
Value: oQfNKjAsI112279866-
Purpose: This cookie stores your Google account ID and the time of your last sign-in in a digitally signed and encrypted format.
Expiration Date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and what ads you may have seen before visiting our site.
Expiration Date: after 3 months
How long and where is the data stored?
The data that YouTube receives from you and processes is stored on Google's servers. Most of these servers are located in the United States. Under
https://datacenters.google/ See exactly where Google’s data centers are located. Your data is distributed across the servers. This makes the data more accessible and better protected against tampering.Google stores the collected data for varying lengths of time. You can delete some data at any time; other data is automatically deleted after a limited period; and still other data is stored by Google for a longer period. Some data (such as items from „My Activity,“ photos, documents, or products) stored in your Google Account remains there until you delete it. Even if you’re not signed in to a Google Account, you can delete some data associated with your device, browser, or app.
How can I delete my data or prevent it from being stored?
In general, you can manually delete data from your Google Account. With the automatic deletion feature for location and activity data introduced in 2019, information is stored for either 3 or 18 months—depending on your choice—and then deleted.Regardless of whether you have a Google Account or not, you can configure your browser to delete or disable cookies from Google. Depending on which browser you use, this works in different ways. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.If you generally prefer not to have cookies, you can set your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
Legal Basis
If you have consented to the processing and storage of your data through embedded YouTube elements, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded YouTube elements if you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.YouTube also processes your data in the United States, among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the United States. You can find more information on this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://business.safety.google/intl/de/adsprocessorterms/.Since YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to learn more about how your data is handled, we recommend that you review the privacy policy at
https://policies.google.com/privacy?hl=de.Video Conferencing & Streaming: Introduction
| Video Conferencing & Streaming Privacy Policy Summary
👥 Data subjects: Users who use our video conferencing or streaming tool
🤝 Purpose: Communication and presentation of content
📓 Data Processed: Access statistics that include data such as your name, address, contact information, email address, phone number, or IP address. You can find more details about this in the documentation for the specific video conferencing or streaming tool used.
📅 Retention period: Depends on the video conferencing or streaming tool used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract) |
What are video conferences and live streams?
We use software programs that allow us to hold video conferences, online meetings, webinars, screen-sharing sessions, and/or live streams. During a video conference or live stream, information is transmitted simultaneously via audio and video. With the help of such video conferencing or streaming tools, we can communicate quickly and easily with customers, business partners, clients, and employees over the Internet. Of course, when selecting a service provider, we ensure compliance with the applicable legal framework.In general, third-party providers may process data as soon as you interact with the software program. Third-party providers of video conferencing or streaming solutions use your data and metadata for various purposes. For example, the data helps make the tool more secure and improve the service. In most cases, the data may also be used for the third-party provider’s own marketing purposes.
Why do we use video conferencing and streaming on our website?
We want to communicate with you—our customers and business partners—quickly, easily, and securely, even online. This works best with video conferencing solutions that are very easy to use. Most tools work directly through your browser, and with just a few clicks, you’re right in the middle of a video meeting. These tools also offer helpful additional features, such as chat and screen-sharing functions, or the ability to share content among meeting participants.
What data is processed?
When you participate in our video conference or a live stream, your data is also processed and stored on the servers of the respective service provider.Exactly which data is stored depends on the solution used. Each provider stores and processes different types and amounts of data. However, most providers typically store your name, address, contact information (such as your email address or phone number), and your IP address. In addition, information about the device you’re using, as well as usage data—such as which websites you visit, when you visit a website, or which buttons you click—may also be stored. Data shared during the video conference (photos, videos, text) may also be stored.
Duration of Data Processing
We provide information on the duration of data processing below in connection with the service used, provided we have further information on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. It is possible that the provider may store your data according to its own policies, over which we have no control.
Right to Object
You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the data controllers of the video conferencing or streaming tool you are using at any time. You can find their contact information either in our specific privacy policy or on the provider’s website.You can delete, disable, or manage the cookies that providers use for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
Legal Basis
If you have consented to the processing and storage of your data by the video or streaming solution, this consent serves as the legal basis for the data processing.
(Art. 6(1)(a) of the GDPR). In addition, we can also offer video conferencing as part of our services if this has been contractually agreed upon with you in advance
(Art. 6(1)(b) of the GDPR). In general, your data is also processed based on our legitimate interest
(Art. 6(1)(f) of the GDPR) stored and processed for the purpose of fast and effective communication with you or other customers and business partners, but only to the extent that you have given your consent. Most video and streaming solutions also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.Information on specific video conferencing and streaming solutions—if available—can be found in the following sections.
Microsoft Teams Privacy Statement
We use Microsoft Teams on our website, a service for online meetings and video conferencing. The service provider is the U.S. company Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.Microsoft processes your data, including in the United States. Microsoft is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Microsoft uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Microsoft commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deFor more information about Microsoft's standard contractual clauses, see
https://learn.microsoft.com/en-us/compliance/regulatory/offering-eu-model-clausesFor more information about the data processed when using Microsoft, please see the Privacy Statement at
https://privacy.microsoft.com/de-de/privacystatement.
| Review Platforms Summary
👥 Data Subjects: Visitors to the website or a review platform
🤝 Purpose: Feedback on our products and/or services
📓 Data Processed: IP address, email address, name, and other information. You can find more details below or on the respective review platforms used.
📅 Retention period: Depends on the respective platform
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), |
What are review platforms?
You can rate our products or services on various review platforms. We participate in some of these platforms so that we can receive feedback from you and thereby optimize our offerings. If you rate us via a review platform, the privacy policy and terms and conditions of the respective review service apply. Very often, you’ll also need to register to submit a review. Review technologies (widgets) may also be integrated into our website. When you use one of these integrated tools, data is also transmitted to, processed by, and stored by the respective provider.Many of these embedded programs work on a similar principle. After you have ordered a product from us or used a service, you will be asked—via email or on the website—to submit a review. You will usually be redirected to a review page via a link, where you can quickly and easily create a review. Some review systems also offer an interface to various social media channels to make the feedback accessible to a wider audience.
Why do we use review platforms?
Review platforms collect feedback and reviews about our offerings. Your reviews provide us with prompt feedback, allowing us to improve our products and/or services much more efficiently. Consequently, these reviews help us optimize our offerings, while also giving you and all our future customers a good overview of the quality of our products and services.
What data is processed?
With your consent, we transmit information about you and the services you have used to the relevant review platform. We do this to ensure that you have actually used one of our services. Only then can you provide genuine feedback. The data transmitted is used solely for user identification. Exactly which data is stored and processed depends, of course, on the providers used. In most cases, personal data such as your IP address, email address, or name is also provided to the review platforms. Even after you submit your review, order information—such as the order number of a purchased item—is forwarded to the relevant platform. If your email address is transmitted, it is so that the review platform can send you an email after you’ve purchased a product. So that we can also display your review on our website, we also inform the providers that you have visited our site. The review platform used is responsible for the personal data collected.
How long and where is the data stored?
You can find more details about the duration of data processing below in the provider’s privacy policy, provided we have further information on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Personal data mentioned in a review is typically anonymized by employees of the platform in question and is therefore visible only to the company’s administrators. The collected data is stored on the providers’ servers and, with most providers, deleted upon completion of the contract.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.
Legal Basis
If you have consented to the use of a review platform, that consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected through a review portal.We also have a legitimate interest in using a review platform to optimize our online service. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use a review platform if you have given your consent.We hope we have been able to provide you with the most important general information regarding data processing by review platforms. You can find more detailed information below in the privacy policy texts or in the linked privacy policies of the respective companies.
Online Map Services: Introduction
| Online Map Services Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Data Processed: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, location data, search terms, and/or technical data. You can find more details on this under the respective tools used.
📅 Retention period: Depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are online map services?
We also use online map services on our website as an additional feature. Google Maps is probably the service you’re most familiar with, but there are also other providers that specialize in creating digital maps. These services allow us to display locations, route maps, or other geographic information directly on our website. With an integrated map service, you no longer need to leave our website to, for example, view directions to a location. To ensure the online map works on our website, map sections are embedded using HTML code. These services can display road maps, the Earth’s surface, or aerial or satellite images. When you use the embedded map feature, data is also transmitted to and stored by the tool being used. This data may include personal information.
Why do we use online map services on our website?
Generally speaking, our goal is to ensure you have an enjoyable experience on our website. And, of course, your experience will only be enjoyable if you can easily navigate our website and find all the information you need quickly and easily. That’s why we thought an online map system could significantly improve our website service. Without leaving our website, you can easily view route descriptions, locations, and even points of interest using the map system. It’s also incredibly convenient that you can see at a glance where our headquarters are located, so you can find us quickly and easily. As you can see, there are simply many advantages, and we clearly view online map services on our website as an integral part of our customer service.
What data do online map services store?
When you open a page on our website that includes an online map feature, personal data may be transmitted to the respective service and stored there. In most cases, this involves your IP address, which can also be used to determine your approximate location. In addition to your IP address, data such as search terms you enter, as well as longitude and latitude coordinates, are also stored. For example, if you enter an address for route planning, this data is also stored. The data is not stored by us, but on the servers of the integrated tools. You can think of it something like this: Although you are on our website, when you interact with a map service, that interaction actually takes place on the service’s website. To ensure the service functions properly, at least one cookie is usually set in your browser. Google Maps, for example, also uses cookies to track user behavior in order to optimize its own service and display personalized ads. You can learn more about cookies in our „Cookies“ section.
How long and where is the data stored?
Each online mapping service processes different types of user data. If we have additional information, we will provide details on the duration of data processing below in the relevant sections for each tool. As a general rule, personal data is retained only as long as necessary to provide the service. Google Maps, for example, stores certain data for a specified period of time, while other data must be deleted by you. With Mapbox, for instance, the IP address is retained for 30 days and then deleted. As you can see, each tool stores data for different lengths of time. Therefore, we recommend that you carefully review the privacy policies of the tools we use.The providers also use cookies to store data about your user behavior with the map service. You can find more general information about cookies in our „Cookies“ section, but you can also learn which cookies may be used by reviewing the privacy policies of the individual providers. In most cases, however, these are only illustrative lists and are not exhaustive.
Right to Object
You always have the option and the right to access your personal data and to object to its use and processing. You can also revoke the consent you have given us at any time. This is usually easiest to do using the cookie consent tool. However, there are also other opt-out tools you can use. You can manage, delete, or disable any cookies set by the providers we use with just a few clicks. However, this may result in some features of the service no longer functioning as usual. How you manage cookies in your browser depends on the browser you are using. In the „Cookies“ section, you will also find links to the instructions for the most common browsers.
Legal Basis
If you have consented to the use of an online map service, that consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected by an online map service.We also have a legitimate interest in using an online map service to optimize the service we provide on our website. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use an online map service if you have given your consent. We would like to emphasize this point once again here.Information on specific online map services—if available—can be found in the following sections.
Google Maps Privacy Policy
| Google Maps Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as search terms entered, your IP address, and latitude and longitude coordinates.
You can find more details below in this Privacy Policy.
📅 Retention period: Depends on the data stored
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests) |
What is Google Maps?
We use Google Maps, provided by Google Inc., on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google Maps allows us to better show you locations and thus tailor our service to your needs. When you use Google Maps, data is transmitted to Google and stored on Google’s servers. Here, we’d like to explain in more detail what Google Maps is, why we use this Google service, what data is stored, and how you can prevent this.Google Maps is an online mapping service provided by Google. With Google Maps, you can search online via a computer, tablet, or app for the exact locations of cities, landmarks, accommodations, or businesses. If a business is listed on Google My Business, additional information about the company is displayed alongside its location. To display directions, map sections of a location can be embedded into a website using HTML code. Google Maps displays the Earth’s surface as a street map or as an aerial or satellite image. Thanks to Street View images and high-quality satellite imagery, very accurate representations are possible.
Why do we use Google Maps on our website?
All of our efforts on this page are aimed at ensuring you have a useful and meaningful experience on our website. By integrating Google Maps, we can provide you with key information about various locations. You can see at a glance where our headquarters are located. The directions always show you the best or fastest route to us. You can view directions for traveling by car, public transportation, on foot, or by bike. For us, providing Google Maps is part of our customer service.
What data does Google Maps store?
In order for Google Maps to provide its full range of services, the company must collect and store data from you. This includes, among other things, the search terms you enter, your IP address, and your latitude and longitude coordinates. If you use the route planner feature, the starting address you enter is also stored. However, this data is stored on Google Maps’ websites. We can only inform you about this; we have no control over it. Since we have integrated Google Maps into our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google uses this data primarily to optimize its own services and to provide you with individualized, personalized advertising.The following cookie is set in your browser due to the integration of Google Maps:
Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ112279866-5
Purpose: NID is used by Google to tailor ads to your Google searches. With the help of this cookie, Google „remembers“ your most frequently entered search queries or your previous interactions with ads. This ensures that you always see personalized ads. The cookie contains a unique ID that Google uses to collect your personal preferences for advertising purposes.
Expiration Date: after 6 months
Note: We cannot guarantee that the information regarding the stored data is complete. Changes can never be ruled out, especially when cookies are used. To identify the NID cookie, a separate test page was created that embedded only Google Maps.
How long and where is the data stored?
Google's servers are located in data centers around the world. However, most of the servers are in the United States. For this reason, your data is increasingly stored in the U.S. You can find out exactly where Google's data centers are located here:
https://datacenters.google/Google distributes the data across various storage media. This makes the data more readily accessible and better protected against any attempts at tampering. Each data center also has special contingency plans. For example, if there are problems with Google’s hardware or a natural disaster takes the servers offline, the data is still quite likely to remain protected.Google stores some data for a specified period of time. For other data, Google only offers the option to delete it manually. Furthermore, the company anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months, respectively.
How can I delete my data or prevent it from being stored?
With the automatic deletion feature for location and activity data introduced in 2019, information about your location and web/app activity is stored for either 3 or 18 months—depending on your choice—and then deleted. You can also manually delete this data from your history at any time via your Google Account. If you want to completely prevent location tracking, you must pause the „Web & App Activity“ setting in your Google Account. Click „Data & Personalization“ and then select the „Activity settings“ option. Here, you can turn the activity on or off.In your browser, you can also disable, delete, or manage individual cookies. Depending on which browser you use, the process works slightly differently. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.If you don’t want to accept any cookies at all, you can set your browser to always notify you when a cookie is about to be set. This allows you to decide whether to allow each individual cookie or not.
Legal Basis
If you have consented to the use of Google Maps, the legal basis for the corresponding data processing is this consent. According to
Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by Google Maps.We also have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is
Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Maps if you have given your consent.Google processes your data in the U.S., among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information about this at
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=deThe Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at
https://business.safety.google/intl/de/adsprocessorterms/.If you would like to learn more about Google's data processing practices, we recommend reviewing the company's privacy policy at
https://policies.google.com/privacy?hl=de.
Online Booking Systems: Introduction
| Online Booking Systems Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience and organization
📓 Data Processed: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, contact and payment information, and/or technical data. You can find more details on this under the respective tools used.
📅 Retention period: Depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is an online booking system?
We use one or more booking systems to allow you to make reservations through our website. This makes it very easy to schedule appointments online. A booking system is a software application integrated into our website that displays available resources (such as open appointments) and allows you to book directly online and, in most cases, pay as well. You’re probably already familiar with such booking systems from the restaurant or hotel industries. However, such systems are now used in a wide variety of industries. Depending on the tool and settings, booking systems can be used both internally by us and by customers like you. In the process, personal data about you is typically collected and stored.In most cases, the booking process works as follows: On our website, you’ll find the booking system where you can book an appointment for a service directly with a click of the mouse and by entering your information—and in most cases, pay right away. You may be able to enter various personal details via a form. Please be aware that all data you enter may be stored and managed in a database.
Why do we use an online booking system?
In a way, we also view our website as a free service for you. We want you to find helpful information and feel completely at home on our site. This includes an online service that makes booking appointments or services as easy as possible for you. Gone are the days when you had to wait days on end for a booking confirmation via phone or email. With an online booking system, you can get everything done with just a few clicks and get back to taking care of other things. The system also makes it easier for us to manage all bookings and appointments. That’s why we consider such a booking system to be absolutely beneficial for both you and us.
What data is processed?
Of course, we cannot tell you exactly what data is processed in this general information text about booking systems. That always depends on the tool used and the functions and capabilities it offers. In addition to the standard booking function, many booking systems also offer a range of other features. For example, many systems also have an integrated external online payment system (e.g., from Stripe, Klarna, or PayPal) and a calendar synchronization feature. Accordingly, depending on the features, different types and varying amounts of data may be processed. Typically, data such as your IP address, name, and contact information, as well as technical details about your device and the time of a booking, are processed. If you also make a payment through the system, banking information such as account numbers, credit card numbers, passwords, TANs, etc., is stored and shared with the respective payment provider. We recommend that you carefully read the privacy policy of the tool you are using so that you know exactly which of your data is being processed.
Duration of Data Processing
Each booking system stores data for different lengths of time. For this reason, we cannot yet provide specific details here regarding the duration of data processing. In principle, however, personal data is always stored only for as long as is strictly necessary to provide the services. Booking systems typically also use cookies, which store information for varying lengths of time. Some cookies are deleted immediately after you leave the site, while others may be stored for several years. You can learn more about this in our „Cookies“ section. Please also review the respective privacy policies of the providers. These should explain how long your data will be stored in each specific case.
Right to Object
If you have consented to data processing by a booking system, you naturally always have the option and the right to withdraw that consent. So please always be aware that you have rights regarding your personal data and that you can exercise those rights at any time. If you do not want your personal data to be processed, then no personal data may be processed. It’s that simple. The easiest way to revoke consent for data processing is through a cookie consent tool or other opt-out features provided. You can also manage data storage via cookies directly in your browser, for example. The lawfulness of data processing remains unaffected until you revoke your consent.
Legal Basis
If you have consented to the use of booking systems, that consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur through booking systems.Furthermore, we also have a legitimate interest in using booking systems because they allow us, on the one hand, to expand our customer service and, on the other hand, to optimize our internal booking processes. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools to the extent that you have given your consent. We would like to emphasize this point once again here.Information on specific booking systems—if available—can be found in the following sections.
Calendly Privacy Policy
We also use the online booking system Calendly. The service provider is the U.S. company Calendly Inc., 115 E. Main St., Ste A1B, Buford, GA 30518, USA.Calendly processes your data, including in the United States. Calendly is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.In addition, Calendly uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Calendly commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.For more information about Calendly's standard contractual clauses, see the Data Processing Terms at
https://calendly.com/dpa.We hope we've been able to provide you with a better understanding of the key information regarding data processing by Calendly. You can learn more about the data processed when using Calendly in the Privacy Policy at
https://calendly.com/privacy.
Explanation of Terms Used
We always strive to make our privacy policy as clear and understandable as possible. However, this isn’t always easy, especially when it comes to technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or certain technical terms (such as “cookies” or “IP address”). However, we do not want to use these terms without explanation. Below you will find an alphabetical list of important terms we use that we may not have addressed sufficiently in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also cite the relevant GDPR text here and, where appropriate, add our own explanations.
Data Processor
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Data Processor“ a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. Consequently, data processors may include not only service providers such as tax advisors, but also hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Consent
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Consent“ any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other clear affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her;
Explanation: On websites, this consent is typically obtained through a cookie consent tool. You’re probably familiar with this. Whenever you visit a website for the first time, you’re usually asked via a banner whether you agree to or consent to the processing of your data. In most cases, you can also configure individual settings and decide for yourself which types of data processing you allow and which you do not. If you do not give your consent, no personal data about you may be processed. In principle, of course, consent can also be given in writing—that is, not through a tool.
Health Data
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Health Data“ personal data relating to the physical or mental health of a natural person, including the provision of health care services, and from which information about that person's health status can be derived;
Explanation: Health data, therefore, includes all stored information related to your own health. This data is often the same information found in a patient’s medical record. It includes, for example, the medications you take, X-rays, your complete medical history, and, as a rule, your vaccination status.
Personal Data
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„personal data“ any information relating to an identified or identifiable natural person (hereinafter „data subject“); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
Explanation: Personal data, therefore, refers to any data that can be used to identify you as an individual. This typically includes data such as:
- Name
- Address
- Email address
- Mailing Address
- Phone number
- Date of Birth
- Identification numbers such as Social Security number, tax identification number, ID card number, or student ID number
- Banking information such as account numbers, credit information, account balances, and much more.
According to the European Court of Justice (ECJ), your
IP Address and Personal Data. IT experts can use your IP address to determine at least the approximate location of your device and, by extension, identify you as the account holder. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called
„special categories“ personal data that is also subject to special protection. This includes:
- Racial and Ethnic Origin
- political views
- religious or ideological beliefs
- union membership
- genetic data, such as data obtained from blood or saliva samples
- biometric data (information about psychological, physical, or behavioral characteristics that can identify a person).
Health data
- Information about sexual orientation or sex life
Profiling
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Profiling“ any form of automated processing of personal data that consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular aspects regarding work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements of that natural person;
Explanation: Profiling involves gathering various pieces of information about a person in order to learn more about that person. On the web, profiling is often used for advertising purposes or for credit checks. Web and advertising analytics programs, for example, collect data about your behavior and interests on a website. This results in a specific user profile that can be used to deliver targeted advertising to a specific audience.
Person in Charge
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Data Controller“ the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States;
Explanation: In our case, we are responsible for processing your personal data and are therefore the “data controller.” If we transfer collected data to other service providers for processing, they are “data processors.” A “Data Processing Agreement (DPA)” must be signed for this purpose.
Processing
Definition pursuant to Article 4 of the GDPRFor the purposes of this regulation, the term means:
„Processing“ any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure; the alignment or combination; the restriction, erasure, or destruction;
Note: When we refer to “processing” in our Privacy Policy, we mean any type of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.All texts are protected by copyright.