Privacy policy
Preamble
With the following privacy policy, we would like to explain to you what types of your personal data (hereinafter also referred to as “data”) we process for what purposes and to what extent in the context of providing our application.
The terms used are not gender-specific.
Status: January 4, 2024

Table of contents
Preamble
Controller
Overview of Processing Activities
Relevant Legal Bases
Security Measures
Transfer of Personal Data
International Data Transfers
Deletion of Data
Rights of Data Subjects
Use of Cookies
Commercial Services
Providers and Services Used in the Course of Business
Payment Procedures
Provision of the Online Offer and Web Hosting
Registration, Login and User Account
Community Functions
Blogs and Publication Media
Contact and Inquiry Management
Communication via Messenger
Chatbots and Chat Functions
Push Notifications
Video Conferences, Online Meetings, Webinars and Screen Sharing
Cloud Services
Newsletter and Electronic Notifications
Promotional Communication via Email, Mail, Fax or Telephone
Surveys and Questionnaires
Web Analytics, Monitoring and Optimization
Offering an Affiliate Program
Presence on Social Networks (Social Media)
Plugins and Embedded Functions and Content
Management, Organization and Support Tools
Changes and Updates to the Privacy Policy
Person responsible
Joscha Probst
Waldsachsener Str. 11
96472 Rödental
E-Mail-address: [email protected]
Overview of processing
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
Inventory Data.
Payment Data.
Contact Data.
Content Data.
Contract Data.
Usage Data.
Metadata, Communication, and Procedural Data.
Categories of affected persons
Customers.
Employees.
Interested parties.
Communication partners.
Users.
Business and contractual partners.
Pupils/students/participants.
Participants.
Persons depicted.
Purposes of the processing
Provision of contractual services and fulfillment of contractual obligations.
Contact requests and communication.
Security measures.
Direct marketing.
Reach measurement.
Tracking.
Office and organizational procedures.
Remarketing.
Conversion measurement.
Click tracking.
Audience building.
Affiliate tracking.
A/B testing.
Management and response to inquiries.
Feedback.
Heatmaps.
Marketing.
Profiles with user-related information.
Provision of our online offering and usability.
Information technology infrastructure.
Relevant legal bases
Relevant legal bases under the General Data Protection Regulation: Below you will find an overview of the legal bases of the General Data Protection Regulation, on the basis of which we process personal data. Please note that, in addition to the provisions of the General Data Protection Regulation, national data protection regulations in your or our country of residence may also apply. Should more specific legal bases be applicable in individual cases, we will inform you about these in the privacy policy.
Consent (Article 6 Paragraph 1 Sentence 1 Letter a of the General Data Protection Regulation) - The data subject has given their consent to the processing of their personal data for a specific purpose or multiple specified purposes.
Contract fulfillment and pre-contractual requests (Article 6 Paragraph 1 Sentence 1 Letter b of the General Data Protection Regulation) - The processing is necessary for the performance of a contract to which the data subject is a party or to take pre-contractual measures requested by the data subject.
Legal obligation (Article 6 Paragraph 1 Sentence 1 Letter c of the General Data Protection Regulation) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Article 6 Paragraph 1 Sentence 1 Letter f of the General Data Protection Regulation) - The processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection provisions of the General Data Protection Regulation, national regulations on data protection in Germany apply. These include, in particular, the Federal Data Protection Act. The Federal Data Protection Act contains specific regulations on the right to information, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes, and the transmission as well as automated decision-making in individual cases including profiling. Additionally, data protection laws of individual German federal states may apply.
Relevant legal bases under the Swiss Federal Act on Data Protection: If you are located in Switzerland, we process your data based on the Federal Act on Data Protection (referred to as the "Swiss Data Protection Act"). This also applies if our processing of your data otherwise affects you in Switzerland. The Swiss Data Protection Act generally does not require (unlike the General Data Protection Regulation) a legal basis for processing personal data to be specified. We only process personal data if the processing is lawful, carried out in good faith, and proportionate (Article 6 Paragraphs 1 and 2 of the Swiss Data Protection Act). Furthermore, personal data is only collected for specific and recognizable purposes and processed in a manner consistent with these purposes (Article 6 Paragraph 3 of the Swiss Data Protection Act).
Note on the applicability of the General Data Protection Regulation and the Swiss Data Protection Act: This privacy notice serves to provide information under both the Swiss Federal Act on Data Protection and the General Data Protection Regulation. For clarity and broader applicability, the terminology of the General Data Protection Regulation is used. Specifically, instead of terms from the Swiss Data Protection Act such as "processing of personal data," "overriding interest," or "sensitive personal data," the terms "processing of personal data," "legitimate interest," and "special categories of data" from the General Data Protection Regulation are used. However, the legal meaning of these terms remains determined by the Swiss Data Protection Act within its jurisdiction.
Security measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of technology, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as varying likelihoods and severity of risks to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, entry, transmission, availability, and separation of data. We have also established procedures to ensure the exercise of data subjects' rights, deletion of data, and responses to potential data vulnerabilities. Furthermore, we consider the protection of personal data during the development or selection of hardware, software, and procedures according to the principles of data protection through technology design and privacy-friendly default settings.
Anonymization of IP addresses: If IP addresses are processed by us or by third-party providers and processing a complete IP address is unnecessary, the IP address is shortened (commonly referred to as "IP masking"). In this process, the last digits or sections of the IP address are removed or replaced with placeholders. The aim is to prevent or significantly complicate the identification of individuals based on their IP address.
TLS/SSL encryption (HTTPS): To protect user data transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting data transmitted between a website or application and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.
Transmission of personal data
In the course of our processing of personal data, it may happen that the data is transmitted to other entities, companies, legally independent organizational units, or individuals, or that it is disclosed to them. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are embedded into a website. In such cases, we comply with the legal requirements and conclude appropriate contracts or agreements with the recipients of your data to protect it.
Data transmission within the organization: We may transmit personal data to other entities within our organization or grant them access to this data. If this transfer occurs for administrative purposes, it is based on our legitimate business and operational interests, or it takes place if it is necessary for the fulfillment of our contractual obligations, or if the consent of the data subjects or legal permission is present.
International data transfers
Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if the processing occurs in the context of the use of third-party services or the disclosure or transmission of data to other persons, entities, or companies, this only happens in compliance with legal requirements. If the level of data protection in the third country has been recognized by an adequacy decision (Article 45 of the General Data Protection Regulation), this serves as the basis for the data transfer. Otherwise, data transfers will only take place if the level of data protection is otherwise ensured, in particular through standard contractual clauses (Article 46 Paragraph 2 Letter c of the General Data Protection Regulation), explicit consent, or in cases of contractual or legally required transfer (Article 49 Paragraph 1 of the General Data Protection Regulation). Furthermore, we inform you of the basis for the third-country transfer for each individual provider from the third country, where adequacy decisions take precedence. Information on third-country transfers and the adequacy decisions can be found on the European Commission's website: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de.
EU-US Trans-Atlantic Data Privacy Framework: Under the so-called "Data Privacy Framework" (DPF), the European Commission has also recognized the data protection level for certain companies in the USA as secure under its adequacy decision dated July 10, 2023. The list of certified companies as well as additional information about the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Within our privacy notices, we indicate which service providers used by us are certified under the Data Privacy Framework.
Disclosure of personal data abroad: Under the Swiss Data Protection Act, we only disclose personal data abroad if adequate protection for the affected individuals is guaranteed (Article 16 of the Swiss Data Protection Act). If the Federal Council has not established adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we implement alternative security measures. These may include international agreements, specific guarantees, data protection clauses in contracts, standard data protection clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC), or internal data protection regulations that have been recognized by the FDPIC or a competent data protection authority of another country.
According to Article 16 of the Swiss Data Protection Act, exceptions for the disclosure of data abroad are permitted if certain conditions are met, including the consent of the data subject, contract fulfillment, public interest, protection of life or physical integrity, publicly available data, or data from a legally mandated register. Such disclosures always comply with legal requirements.
Deletion of data
The data processed by us is deleted in accordance with legal requirements once the permissions for its processing are revoked or otherwise lapse (e.g., if the purpose for the data processing has been achieved or the data is no longer necessary for that purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing is restricted. This means the data is locked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for asserting, exercising, or defending legal claims or for protecting the rights of another natural or legal person. Within our privacy notices, we may provide users with additional information on the deletion and retention of data specific to the respective processing processes.
Rights of data subjects
Rights of data subjects under the General Data Protection Regulation: As a data subject, you are entitled to various rights under the General Data Protection Regulation, which are primarily detailed in Articles 15 to 21 of the General Data Protection Regulation:
Right to object: You have the right to object at any time, for reasons related to your specific situation, to the processing of personal data concerning you that is carried out based on Article 6 Paragraph 1 Letters e or f of the General Data Protection Regulation; this also applies to profiling based on these provisions. If personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such advertising purposes; this also applies to profiling insofar as it is related to such direct marketing.
Right to withdraw consent: You have the right to withdraw consent given at any time.
Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed, and if so, access to this data as well as additional information and a copy of the data in accordance with legal requirements.
Right to rectification: In accordance with legal requirements, you have the right to request the completion of incomplete data or the rectification of inaccurate data concerning you.
Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request the immediate erasure of personal data concerning you or, alternatively, to request a restriction of the processing of the data in accordance with legal requirements.
Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format or to request its transmission to another controller, in accordance with legal requirements.
Right to lodge a complaint with a supervisory authority: In accordance with legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, particularly in the Member State where you are habitually resident, where your workplace is located, or where the alleged infringement occurred, if you believe that the processing of personal data concerning you violates the General Data Protection Regulation.
Rights of data subjects under the Swiss Data Protection Act:
As a data subject, you are entitled to the following rights under the Swiss Data Protection Act:
Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed and to receive the necessary information to assert your rights under this law and ensure transparent data processing.
Right to data delivery or transfer: You have the right to request the delivery of personal data concerning you, which you have provided to us, in a commonly used electronic format.
Right to rectification: You have the right to request the rectification of incorrect personal data concerning you.
Right to object, erasure, and destruction: You have the right to object to the processing of your data and to request the erasure or destruction of personal data concerning you.
Use of cookies
Cookies are small text files or other memory markers that store information on end devices and retrieve information from end devices, for example, to save the login status in a user account, the contents of a shopping cart in an online store, the accessed content, or used functions of an online offering. Cookies may also be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings, as well as creating analyses of visitor flows.
Notes on consent: We use cookies in accordance with legal requirements. Therefore, we obtain prior consent from users, except where such consent is not legally required. Consent is not required, in particular, if the storage and retrieval of the information, including cookies, are absolutely necessary to provide a telemedia service explicitly requested by the users (i.e., our online offering). Absolutely necessary cookies generally include those with functions that relate to the display and operability of the online offering, load balancing, security, storing user preferences and selection options, or other purposes closely tied to the provision of the primary and secondary functions of the online offering requested by the users. The revocable consent is clearly communicated to users and includes information on the respective cookie usage.
Notes on data protection legal bases: The data protection legal basis on which we process the personal data of users using cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the declared consent. Otherwise, the data processed using cookies is based on our legitimate interests (e.g., in the business operation of our online offering and improving its usability) or, if this is necessary for the fulfillment of our contractual obligations, provided the use of cookies is necessary for this purpose. We clarify the purposes for which cookies are processed within this privacy policy or in the context of our consent and processing procedures.
Storage duration: Regarding the storage duration, the following types of cookies are distinguished:
Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online offering and closes their end device (e.g., browser or mobile application).
Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, login statuses can be saved, or preferred content can be displayed directly when the user revisits a website. Likewise, user data collected using cookies may be used for reach measurement. Unless users are explicitly informed otherwise about the type and storage duration of cookies (e.g., during consent collection), users should assume that cookies are permanent and that their storage duration can be up to two years.
General information on revocation and objection (so-called "opt-out"): Users can revoke the consent they have given at any time and object to the processing in accordance with legal requirements. Users can, among other things, limit the use of cookies in their browser settings (which may limit the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
Processed data types: Usage data (e.g., visited websites, interest in content, access times).
Affected persons: Users (e.g., website visitors, users of online services).
Purposes of processing: Provision of our online offering and user-friendliness.
Legal bases: Legitimate interests (Article 6 Paragraph 1 Sentence 1 Letter f of the General Data Protection Regulation). Consent (Article 6 Paragraph 1 Sentence 1 Letter a of the General Data Protection Regulation).
Further notes on processing, procedures, and services
Processing of cookie data on the basis of consent: We use a cookie consent management system in which users' consents to the use of cookies or the processing and providers named in the cookie consent management system can be obtained, managed, and revoked. The consent declaration is stored to avoid re-querying and to demonstrate the consent in accordance with legal obligations. Storage can take place on the server side and/or in a cookie (so-called opt-in cookie or comparable technologies) to be able to assign the consent to a user or their device. Subject to individual details on the providers of cookie management services, the following applies: The duration of consent storage can be up to two years. A pseudonymous user identifier is formed and stored with the time of consent, information on the scope of consent (e.g., which categories of cookies and/or service providers), as well as the browser, system, and device used; Legal bases: Consent (Article 6 Paragraph 1 Sentence 1 Letter a of the General Data Protection Regulation).
Cookie opt-out: In the footer of our website, you will find a link to change your cookie settings and revoke your consent; Legal bases: Legitimate interests (Article 6 Paragraph 1 Sentence 1 Letter f of the General Data Protection Regulation).
Business services
We process data of our contractual and business partners, such as customers and interested parties (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships and associated measures as well as within the framework of communication with the contractual partners (or pre-contractually), e.g., to respond to inquiries.
We process this data to fulfill our contractual obligations. These include, in particular, the obligations to provide the agreed services, any update obligations, and remedies in case of warranty and other service disruptions. In addition, we process the data to safeguard our rights and for administrative tasks associated with these obligations as well as business organization. Furthermore, we process the data based on our legitimate interests in proper and economic business management as well as security measures to protect our contractual partners and business operations from misuse, endangerment of their data, secrets, information, and rights (e.g., involvement of telecommunications, transport, and other auxiliary services, as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Under applicable law, we only disclose data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed about further forms of processing, e.g., for marketing purposes, within this privacy policy.
We inform contractual partners which data is required for the aforementioned purposes before or during data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks), or personally.
We delete the data after the expiration of legal warranty and comparable obligations, i.e., as a rule, after four years, unless the data is stored in a customer account, e.g., as long as it must be retained for legal archiving reasons. The statutory retention period is ten years for tax-relevant documents as well as commercial books, inventories, opening balances, annual financial statements, the instructions and other organizational documents necessary for understanding these documents, and booking receipts; six years for received commercial and business letters and copies of sent commercial and business letters. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance, the annual financial statement, or the management report was created, the commercial or business letter was received or sent, or the booking receipt was created, and the recording was made or the other documents were created.
If we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply in the relationship between users and providers.
Processed Data Types: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email, phone numbers); contract data (e.g., subject of the contract, duration, customer category); usage data (e.g., visited websites, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Data Subjects: Customers; prospective customers; business and contractual partners; students/participants.
Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; handling of contact inquiries and communication; office and organizational procedures; management and response to inquiries; conversion measurement (evaluation of the effectiveness of marketing measures).
Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further notes on processing activities, procedures, and services:
Kundenkonto: Customers can create an account within our online offering (e.g., customer or user account, hereinafter referred to as "customer account"). If the registration of a customer account is required, customers will be informed accordingly, as well as about the information required for registration. The customer accounts are not public and cannot be indexed by search engines. During registration, subsequent logins, and use of the customer account, we store the IP addresses of customers along with the times of access to provide evidence of registration and prevent misuse of the customer account. If the customer account is terminated, the data of the customer account will be deleted, unless retention is required for other purposes, such as providing contractual services or fulfilling legal obligations (e.g., internal storage of customer data, orders, or invoices). It is the responsibility of the customers to back up their data upon termination of the customer account. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Merkliste/Wunschliste: Customers can create a product/wishlist. In this case, the products will be stored as part of our contractual obligations until the account is deleted, unless the product list entries are removed by the customer, or we explicitly inform the customer of differing retention periods. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Kundentreueprogramm/Kundenkarte: We process customer data as part of our loyalty program to fulfill the services provided to participating customers. To this end, the information collected from customers, as required, is stored in a customer profile. The profile also includes information about the use of the loyalty program and the associated benefits and services. These details are shared with third parties (e.g., service providers) only when necessary for the aforementioned purposes. Customer profiles are deleted after the end of participation in the loyalty program, with data retained only as required for legal retention purposes or for fulfilling statutory (up to 11 years for tax-related information from the end of the year in which they were created) or contractual obligations (up to three years from the end of the year of termination). Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Shop und E-Commerce: We process the data of our customers to enable them to select, purchase, or order the desired products, goods, and related services, as well as their payment and delivery or execution. If necessary for fulfilling an order, we engage service providers, particularly postal, freight, and shipping companies, to deliver or execute the service to customers. To process payment transactions, we utilize the services of banks and payment service providers. The required information is identified during the ordering process and includes details necessary for delivery, provision, and billing, as well as contact details for any necessary clarifications. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Education- and Training-services: We process the data of participants in our educational and training offerings (collectively referred to as "trainees") to provide our training services to them. The data processed in this context, the type, scope, purpose, and necessity of its processing are determined by the underlying contractual and training relationship. Processing includes performance evaluation and the assessment of our services as well as those of the trainers. As part of our activities, we may also process special categories of data, particularly health information of trainees or data revealing ethnic origin, political opinions, religious or ideological beliefs. Where required, we obtain explicit consent from the trainees and otherwise process such special categories of data only when necessary for the provision of training services, health care purposes, social protection, or the protection of vital interests of the trainees. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Online-Courses and Online-Trainings: We process the data of participants in our online courses and online training sessions (collectively referred to as "participants") to provide them with our course and training services. The data processed in this context, the type, scope, purpose, and necessity of its processing are determined by the underlying contractual relationship. The data generally includes information about the courses and services used, and where part of our service offering, individual specifications and results of the participants. Processing includes performance evaluation and the assessment of our services as well as those of the course and training instructors. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Offering software and platform services: We process the data of our users, registered and test users (hereinafter collectively referred to as "users"), to provide our contractual services to them and, based on legitimate interests, to ensure the security of our offering and further develop it. The required information is marked during the order, registration, or comparable conclusion of the contract and includes the information necessary for service provision and billing as well as contact information to enable potential queries. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Happenings and Events: We process the data of participants in the events, activities, and similar gatherings that we offer or host (hereinafter collectively referred to as "participants" and "events") to enable their participation and access to related services or actions. If we process health data, religious, political, or other special categories of data in this context, it is done transparently (e.g., at thematically oriented events) or for health care, security purposes, or with the explicit consent of the participants. The required information is marked during the order, registration, or comparable conclusion of the contract and includes the information necessary for service provision and billing as well as contact information to enable potential queries. If we access information related to the end customers, employees, or other individuals, we process this data in compliance with legal and contractual requirements. Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Agency services: We process the information provided by interested parties as part of their mediation requests to establish, execute, and potentially terminate a contract for the mediation of offers from providers of the requested products or services. We use the contact details of the interested parties to refine their inquiries through the agreed or otherwise permitted communication channels (e.g., phone or email) and to suggest appropriate providers or offers based on the refined inquiry. Furthermore, we may follow up with interested parties at a later time, in compliance with legal provisions, to ask about the success of our mediation services. We process the data of interested parties and providers to fulfill our contractual obligations, linking the inquiries from the interested parties with matching offers from providers and suggesting or forwarding the relevant providers to them. We may log inputs in the online forms submitted by interested parties to demonstrate the existence of the contractual relationship and consent of the interested parties in accordance with the accountability obligations of the GDPR (Art. 5 para. 2 GDPR). This information is stored for three to four years in case the initial request needs to be evidenced (e.g., to substantiate the permission for contacting interested parties). Rechtsgrundlagen: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Providers and Services Used in Business Operations
As part of our business operations, we use additional services, platforms, interfaces, or plug-ins from third-party providers (hereinafter collectively referred to as "services") while complying with legal requirements. Their use is based on our interest in conducting our business operations and internal organization in a proper, lawful, and economical manner.
Processed Data Types: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); contract data (e.g., subject matter of the contract, duration, customer category).
Affected Individuals: Customers; interested parties; users (e.g., website visitors, users of online services); business and contractual partners; employees (e.g., staff, applicants, former employees).
Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
DATEV: Software for accounting, communication with tax consultants and authorities, and document storage; Service Provider: DATEV eG, Paumgartnerstr. 6 - 14, 90429 Nuremberg, Germany; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://www.datev.de; Privacy Policy: https://www.datev.de/web/de/m/ueber-datev/datenschutz/. Data Processing Agreement: Provided by the service provider.
sevDesk: Online software for invoicing, accounting, banking, and tax submission with document storage; Service Provider: sevDesk GmbH, Hauptstraße 115, 77652 Offenburg, Germany; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://sevdesk.de/; Privacy Policy: https://sevdesk.de/datenschutz/. Data Processing Agreement: https://sevdesk.de/sicherheit-datenschutz/.
Payment Procedures
As part of contractual and other legal relationships, due to legal obligations, or based on our legitimate interests, we offer efficient and secure payment options to affected individuals and utilize additional service providers, including banks and payment service providers, for this purpose.
The data processed by payment service providers includes inventory data, such as name and address, payment data, such as account numbers or credit card numbers, passwords, TANs, and checksums, as well as contract-, total-, and recipient-related information. The information is necessary to carry out the transactions. However, the inputted data is only processed and stored by the payment service providers. This means we do not receive any account or credit card information, only information confirming or denying the payment. In some cases, the payment service providers transmit the data to credit reporting agencies to verify identity and creditworthiness. For this, we refer to the general terms and conditions and privacy notices of the respective payment service providers.
For payment transactions, the general terms and conditions and the privacy notices of the respective payment service providers apply, which can be accessed within the respective websites or transaction applications. We also refer you to these for further information and for the assertion of rights of withdrawal, information, and other data subject rights.
Processed Data Types: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contract data (e.g., subject matter of the contract, duration, customer category); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Customers; interested parties.
Purposes of Processing: Fulfillment of contractual services and obligations.
Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Further Notes on Processing, Procedures, and Services:
Stripe: Payment services (technical integration of online payment methods); Service Provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR); Website: https://stripe.com; Privacy Policy: https://stripe.com/de/privacy. Third-country transfer basis: EU-US Data Privacy Framework (DPF).
Provision of the Online Offer and Web Hosting
We process the data of users to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary to deliver the contents and functionalities of our online services to the user's browser or device.
Processed Data Types: Usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status); content data (e.g., entries in online forms).
Affected Individuals: Users (e.g., website visitors, users of online services); business and contractual partners; customers.
Purposes of Processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment, such as computers, servers, etc.); security measures; fulfillment of contractual services and obligations.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Provision of Online Offer on Rented Storage Space: To provide our online offering, we use storage space, computing capacity, and software that we rent or otherwise obtain from an appropriate server provider (also known as a "web host"); Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Collection of Access Data and Log Files: Access to our online offering is logged in the form of so-called "server log files." The server log files may include the address and name of the accessed web pages and files, the date and time of access, transmitted data volumes, messages about successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), and typically IP addresses and the requesting provider. The server log files may be used for security purposes, e.g., to avoid overloading the servers (especially in the event of abusive attacks, such as DDoS attacks), and also to ensure server utilization and stability; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR). Deletion of Data: Log file information is stored for a maximum duration of 30 days and then deleted or anonymized. Data whose further retention is necessary for evidentiary purposes is excluded from deletion until the respective incident is definitively resolved.
Email Sending and Hosting: The web hosting services we utilize also include the sending, receiving, and storage of emails. For these purposes, the recipient and sender addresses, as well as other information related to the email dispatch (e.g., the involved providers) and the content of the respective emails, are processed. The aforementioned data may also be processed for SPAM detection purposes. Please note that emails on the internet are generally not encrypted. While emails are usually encrypted during transport, they are not encrypted on the servers from which they are sent and received (unless an end-to-end encryption process is used). Therefore, we cannot assume responsibility for the transmission path of emails between the sender and the reception on our server; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Content-Delivery-Network (CDN): We use a "content delivery network" (CDN). A CDN is a service that helps deliver content from an online offering, especially large media files such as graphics or program scripts, faster and more securely via regionally distributed and internet-connected servers; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
ALL-INKL: Services in the area of providing information technology infrastructure and related services (e.g., storage space and/or computing capacities); Service Provider: ALL-INKL.COM - Neue Medien Münnich, Owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://all-inkl.com/; Privacy Policy: https://all-inkl.com/datenschutzinformationen/. Data Processing Agreement: Provided by the service provider.
Amazon Web Services (AWS): Services in the area of providing information technology infrastructure and related services (e.g., storage space and/or computing capacities); Service Provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://aws.amazon.com/de/; Privacy Policy: https://aws.amazon.com/de/privacy/; Data Processing Agreement: https://aws.amazon.com/de/compliance/gdpr-center/. Third-country transfer basis: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://aws.amazon.com/service-terms/).
Sentry: Monitoring system stability and detecting code errors—device information or error timing is collected pseudonymously and then deleted; Service Provider: Functional Software Inc., Sentry, 132 Hawthorne Street, San Francisco, California 94107, USA; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://sentry.io; Security measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://sentry.io/privacy; Data Processing Agreement: https://sentry.io/legal/dpa/. Third-country transfer basis: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://sentry.io/legal/dpa/).
Cloudinary: Cloud storage, cloud infrastructure services, and cloud-based application software; Service Provider: Cloudinary UK Ltd., 8-14 Meard St., London W1F 0EQ, United Kingdom; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://cloudinary.com; Privacy Policy: https://cloudinary.com/privacy.
Registration, Login, and User Account
Users can create a user account. As part of the registration process, users are informed of the required mandatory information and their processing for the purpose of providing the user account is based on contractual fulfillment. The processed data includes, in particular, login information (username, password, and an email address).
As part of the use of our registration and login functions and the use of the user account, we store the IP address and the time of each user action. The storage is based on our legitimate interests as well as those of the users in protection against misuse and other unauthorized use. In principle, these data are not passed on to third parties unless it is necessary for pursuing our claims or there is a legal obligation to do so.
Users may be informed via email about processes that are relevant to their user account, such as technical changes.
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Users (e.g., website visitors, users of online services).
Purposes of Processing: Fulfillment of contractual services and obligations; security measures; management and response to inquiries; provision of our online offering and user-friendliness.
Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Registration with Real Names: Due to the nature of our community, we ask users to use our offering only under their real names. This means the use of pseudonyms is not permitted; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Setting the Visibility of Profiles: Users can determine through settings to what extent their profiles are visible or accessible to the public or only to certain groups of people; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Deletion of Data After Termination: If users terminate their user accounts, their data with regard to the user account, subject to legal permission, obligation, or user consent, is deleted; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
No Retention Obligation for Data: It is the responsibility of users to secure their data before the end of the contract. We are entitled to irreversibly delete all user data stored during the contract period after termination; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Community Features
The community features we provide allow users to engage in conversations or otherwise interact with each other. Please note that the use of community features is permitted only in compliance with applicable laws, our terms and conditions, and guidelines, as well as the rights of other users and third parties.
Processed Data Types: Usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Users (e.g., website visitors, users of online services).
Purposes of Processing: Fulfillment of contractual services and obligations; security measures.
Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Further Notes on Processing, Procedures, and Services:
User Contributions are Public: Contributions and content created by users are publicly visible and accessible; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Storage of Data for Security Purposes: User contributions and other inputs are processed for purposes of community and conversation features and, unless legally required or permitted, are not disclosed to third parties. Disclosure obligations may arise, in particular, in cases of unlawful contributions for purposes of legal prosecution. In addition to the content of the contributions, their time and the IP address of users are stored to take appropriate measures for protecting other users and the community; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Right to Delete Content and Information: Deletion of contributions, content, or information provided by users is permitted to an appropriate extent after proper consideration if there are concrete indications of violations of legal rules, our provisions, or third-party rights; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Blogs and Publication Media
We utilize blogs or similar means of online communication and publication (hereinafter referred to as "publication medium"). The data of readers are processed for the purposes of the publication medium only to the extent necessary for its presentation and communication between authors and readers or for security reasons. For further information, we refer to the information on the processing of visitors to our publication medium as part of this privacy notice.
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Users (e.g., website visitors, users of online services).
Purposes of Processing: Fulfillment of contractual services and obligations; feedback (e.g., collecting feedback via online forms); provision of our online offering and user-friendliness; security measures; management and response to inquiries.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Comments and Contributions: When users leave comments or other contributions, their IP addresses may be stored based on our legitimate interests. This is for our security in case someone leaves unlawful content in comments and contributions (e.g., insults, forbidden political propaganda, etc.). In such cases, we can be held liable for the comment or contribution and are therefore interested in the identity of the author.
Furthermore, we reserve the right to process user data for the purpose of SPAM detection based on our legitimate interests.
On the same legal basis, we reserve the right, in the case of surveys, to store the IP addresses of users for the duration of the survey and to use cookies to avoid multiple votes.
The information provided in the context of the comments and contributions, any contact and website information, as well as the content details, will be permanently stored by us until the user objects; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Contact and Inquiry Management
When contacting us (e.g., by post, contact form, email, telephone, or via social media) and within the framework of existing user and business relationships, the information provided by the inquiring individuals is processed to the extent necessary to respond to the contact requests and any requested measures.
Processed Data Types: Contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners.
Purposes of Processing: Contact requests and communication; management and response to inquiries; feedback (e.g., collecting feedback via online forms); provision of our online offering and user-friendliness.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Further Notes on Processing, Procedures, and Services:
Contact Form: When users contact us via our contact form, email, or other communication channels, we process the information provided in this context to handle the communicated request; Legal Basis: Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Communication via Messenger
We use messengers for communication purposes and kindly ask you to take note of the following information regarding the functionality of the messengers, encryption, the use of metadata in communication, and your rights to object.
You may also contact us through alternative means, e.g., by telephone or email. Please use the contact details provided or those specified within our online offering.
In the case of end-to-end encryption of content (i.e., the content of your messages and attachments), we note that the communication content (i.e., the content of the message and attached images) is encrypted from end to end. This means that the content of messages is not visible, not even by the messenger providers themselves. Always use an up-to-date version of the messenger with encryption enabled to ensure message content is protected.
However, we also inform our communication partners that while the content of communications is not accessible, the messenger providers can learn that and when communication partners communicate with us, as well as technical information about the devices used by communication partners and, depending on the settings of their devices, location information (so-called metadata).
Legal Basis: If we request communication partners’ permission prior to communicating with them via Messenger, the legal basis for processing their data is their consent. Otherwise, if we do not request consent and they contact us, we use Messenger in relation to our contractual partners and in the pre-contractual phase as a contractual measure and, in the case of other interested parties and communication partners, based on our legitimate interests in fast and efficient communication and the fulfillment of the communication needs of our communication partners. Furthermore, we point out that we do not transmit contact data provided to us to the messengers for the first time without your consent.
Revocation, Objection, and Deletion: You can revoke any consent given or object to communication with us via Messenger at any time. If you object to communication via Messenger, we will delete messages following our general deletion policies (e.g., as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) or as soon as we can assume that any queries from the communication partner have been answered, provided no legal storage obligations prevent deletion.
Reservation of Reference to Other Communication Channels: To conclude, we point out that for your safety, we reserve the right not to answer inquiries via Messenger. This applies if, for example, contractual details require special confidentiality or if an answer via Messenger does not meet formal requirements. In such cases, we refer to more appropriate communication channels.
Processed Data Types: Contact data (e.g., email addresses, phone numbers); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners.
Purposes of Processing: Contact requests and communication; direct marketing (e.g., by email or post).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
WhatsApp: WhatsApp Messenger with end-to-end encryption; Service Provider: WhatsApp Ireland Limited, 4 Grand Canal Quay, Dublin 2, D02 KH28, Ireland; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://www.whatsapp.com/; Privacy Policy: https://www.whatsapp.com/legal. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
Chatbots and Chat Functions
We offer online chat and chatbot functions as a means of communication (hereinafter referred to as "chat services"). A chat is an online interaction conducted in real time. A chatbot is software that answers user questions or informs them through messages. If you use our chat functions, we may process your personal data.
If you use our chat services within an online platform, your identification number within the respective platform is also stored. We may also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via chat services and log registration and consent processes to demonstrate compliance with legal requirements.
We inform users that the respective platform provider may learn that and when users interact with our chat services, as well as process technical information about the devices used by users and, depending on the settings of their devices, location information (so-called metadata) for purposes of optimizing their services and ensuring security. The metadata of communication via chat services (e.g., information on who communicated with whom) may also be used by platform providers for marketing purposes or personalized advertising in accordance with their terms.
If users agree to a chatbot regularly sending them messages, they may unsubscribe from the messages at any time in the future. The chatbot informs users on how and with which keywords they can unsubscribe from messages. When users unsubscribe from chatbot messages, their data is deleted from the message recipient directory.
We use the aforementioned data to operate our chat services, e.g., to address users personally, respond to their inquiries, send any requested content, and improve our chat services (e.g., to teach chatbots answers to frequently asked questions or identify unanswered inquiries).
Legal Basis: We use chat services based on user consent if we obtain their permission to process their data as part of our chat services (this applies to cases where users are asked for consent, e.g., so that a chatbot sends them regular messages). If we use chat services to respond to user inquiries about our services or our company, this is done as part of contractual or pre-contractual communication. Otherwise, we use chat services based on our legitimate interests in optimizing the chat services, their economic efficiency, and enhancing the user experience.
Revocation, Objection, and Deletion: You may revoke consent at any time or object to the processing of your data within our chat services.
Processed Data Types: Contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners.
Purposes of Processing: Contact requests and communication; direct marketing (e.g., by email or post).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Push Notifications
With the users' consent, we can send so-called "push notifications." These are messages displayed on users' screens, devices, or browsers, even when our online service is not actively in use.
To register for push notifications, users must confirm the prompt of their browser or device to receive push notifications. This consent process is documented and stored. The storage is necessary to recognize whether users have agreed to receive push notifications and to be able to prove their consent. For these purposes, a pseudonymous identifier of the browser (so-called "push token") or the device ID of a device is stored.
Push notifications may be necessary for fulfilling contractual obligations (e.g., technical and organizational information relevant to the use of our online service) and are otherwise sent, unless otherwise specified below, based on user consent. Users can change their notification settings at any time using their browser or device notification settings.
Processed Data Types: Usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners.
Purposes of Processing: Provision of our online offering and user-friendliness; reach measurement (e.g., access statistics, recognition of returning visitors); direct marketing (e.g., by email or post).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Further Notes on Processing, Procedures, and Services:
Push Notifications with Promotional Content: The push notifications we send may include promotional information. Promotional push notifications are processed based on user consent. If the content of promotional push notifications is specifically described in the context of the consent, such descriptions are decisive for user consent. Otherwise, our newsletters contain information about our services and us; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR).
Analysis and Success Measurement: We evaluate push notifications statistically and can thus recognize if and when push notifications were displayed and clicked. This information is used for technical improvements to our push notifications based on technical data or target groups and their retrieval behavior or retrieval times. This analysis also includes determining whether push notifications are opened, when they are opened, and whether users interact with their content or buttons. This information can, for technical reasons, be assigned to individual push notification recipients. However, it is neither our intention nor, where used, that of the push notification service provider to monitor individual users. Instead, the analyses serve us to identify the usage habits of our users and to adapt our push notifications to them or to send different push notifications according to the interests of our users.
The analysis of push notifications and success measurement is carried out based on the explicit consent of the users, which is obtained with their agreement to receive push notifications. Users can object to the analysis and success measurement by unsubscribing from push notifications. Unfortunately, it is not possible to withdraw the analysis and success measurement separately; in this case, the entire push notification subscription must be canceled or objected to. In this case, the profile information stored with the service provider will be deleted; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR).
Video Conferences, Online Meetings, Webinars, and Screen Sharing
We use platforms and applications from other providers (hereinafter referred to as "conference platforms") for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as "conferences"). When selecting the conference platforms and their services, we comply with legal requirements.
Data Processed by Conference Platforms: As part of participation in a conference, the conference platforms process the following personal data of participants. The scope of the processing depends, on the one hand, on what data is required for a specific conference (e.g., providing access data or real names) and what optional information is provided by the participants. In addition to processing for conducting the conference, the participants' data may also be processed by the conference platforms for security purposes or service optimization. The data processed includes personal data (first name, last name), contact information (email address, phone number), access data (access codes or passwords), profile pictures, information on the professional position/function, the IP address of the internet connection, information about the participants' devices, their operating system, browser and its technical and language settings, information about the content of communications (e.g., entries in chats, as well as audio and video data), as well as the use of other available features (e.g., surveys). Communication content is encrypted within the framework of what is technically provided by the conference providers. If participants are registered users of the conference platforms, additional data may be processed according to the agreement with the respective conference provider.
Recording and Logging: If text entries, participation results (e.g., from surveys), or video and audio recordings are logged, participants will be transparently informed in advance and, if necessary, asked for their consent.
Privacy Measures for Participants: Please refer to the privacy policies of the respective conference platforms for details on how your data is processed and choose the privacy and security settings optimal for you. During video conferences, please also ensure data and privacy protection in the background of your recording (e.g., informing cohabitants, locking doors, and using the feature to blur backgrounds, where technically possible). Links to conference rooms and access data should not be shared with unauthorized third parties.
Legal Basis: If, in addition to the conference platforms, we also process the users' data and ask for their consent for using the conference platforms or certain functions (e.g., consent to recording conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary to fulfill contractual obligations (e.g., participant lists, post-processing of meeting results, etc.). Otherwise, the users' data will be processed based on our legitimate interest in efficient and secure communication with our communication partners.
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners; users (e.g., website visitors, users of online services); depicted persons.
Purposes of Processing: Fulfillment of contractual obligations; contact requests and communication; office and organizational procedures.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Google Hangouts / Meet: Conference and communication software; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://hangouts.google.com/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause).
Cloud Services
We use software services accessible via the internet and executed on the servers of their providers (referred to as "cloud services" or "Software as a Service") for the storage and management of content (e.g., document storage and management, exchange of documents, content, and information with specific recipients, or publication of content and information).
In this context, personal data may be processed and stored on the servers of the providers, provided that they are part of communication processes with us or are otherwise processed as described in this privacy policy. This data may include, in particular, users' inventory and contact data, data on processes, contracts, other procedures, and their content. The providers of cloud services may also process usage data and metadata that they use for security purposes and service optimization.
If we make forms or other documents and content available to other users or publicly accessible websites via cloud services, the providers of these services may store cookies on the users' devices for the purposes of web analytics or to remember user preferences (e.g., in the case of media control).
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Customers; employees (e.g., employees, applicants, former employees); prospects; communication partners; users (e.g., website visitors, users of online services).
Purposes of Processing: Office and organizational procedures; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.).
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Google Cloud Storage: Cloud storage, cloud infrastructure services, and cloud-based application software; Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://cloud.google.com/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum; Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause). Additional Information: https://cloud.google.com/privacy.
Google Workspace: Cloud-based application software (e.g., text and spreadsheet processing, calendar, and contact management), cloud storage, and cloud infrastructure services; Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://workspace.google.com/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum; Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause). Additional Information: https://cloud.google.com/privacy.
Newsletter and Electronic Notifications
We send newsletters, emails, and other electronic notifications (hereinafter referred to as "newsletters") only with the consent of the recipients or a legal authorization. If the content of the newsletter is specifically described as part of a registration process, this content is decisive for the users' consent. Otherwise, our newsletters contain information about our services and us.
To sign up for our newsletters, it is generally sufficient for you to provide your email address. However, we may ask you to provide a name for personal address purposes in the newsletter or other details, as far as necessary for the purposes of the newsletter.
Double Opt-In Procedure: The registration for our newsletter generally takes place in a so-called double opt-in procedure. This means you will receive an email after registration asking you to confirm your registration. This confirmation is necessary to ensure that no one can register with external email addresses. The registrations for the newsletter are logged to prove the registration process in accordance with legal requirements. This includes the storage of the registration and confirmation times and the IP address. Changes to your data stored by the mailing service provider are also logged.
Deletion and Limitation of Processing: We can store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them to provide evidence of previously given consent. The processing of this data is limited to the purpose of potential defense against claims. An individual deletion request is possible at any time, provided that the former existence of consent is confirmed. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a suppression list (so-called "blocklist").
The logging of the registration process is based on our legitimate interests to demonstrate its proper execution. If we commission a service provider to send emails, this is done based on our legitimate interests in an efficient and secure email system.
Content:
Information about us, our services, promotions, and offers.
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status); usage data (e.g., visited websites, interest in content, access times).
Affected Individuals: Communication partners; users (e.g., website visitors, users of online services).
Purposes of Processing: Direct marketing (e.g., by email or post); reach measurement (e.g., access statistics, recognition of returning visitors); fulfillment of contractual obligations and pre-contractual inquiries.
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Opt-Out Option: You can cancel the receipt of our newsletter at any time, i.e., revoke your consent or object to further receipt. A link to cancel the newsletter can be found at the end of each newsletter or you can otherwise use one of the above-mentioned contact options, preferably email, for this purpose.
Further Notes on Processing, Procedures, and Services:
Measurement of Open and Click Rates: Newsletters contain a so-called "web-beacon," i.e., a pixel-sized file that is retrieved from our server, or if we use a mailing service provider, from their server, when the newsletter is opened. During this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, is collected.
This information is used for the technical improvement of our newsletters based on the technical data or target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. This information can be assigned to individual newsletter recipients for technical reasons. However, it is neither our intention nor, if used, the mailing service provider's, to observe individual users. The evaluations instead serve to recognize the reading habits of our users and adapt our content to them or send different content according to our users' interests.
The measurement of open and click rates as well as storage of measurement results in user profiles and their further processing is based on the users' explicit consent.
Unfortunately, a separate revocation of the success measurement is not possible; in this case, the entire newsletter subscription must be canceled, or objected to. In this case, the profile information stored with the service provider will be deleted; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR).Requirement for Access to Free Services: Consent to receive mailings may be made a prerequisite for access to free services (e.g., access to specific content or participation in specific promotions). If users wish to access the free service without subscribing to the newsletter, we ask them to contact us.
Brevo: Email delivery and automation services; Service Provider: Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://www.brevo.com/; Privacy Policy: https://www.brevo.com/legal/privacypolicy/. Data Processing Agreement: Provided by the service provider.
Advertising Communication via Email, Post, Fax, or Telephone
We process personal data for advertising communication purposes, which can be conducted via various channels, such as email, telephone, post, or fax, in accordance with legal requirements.
Recipients have the right to revoke granted consents at any time or to object to advertising communication at any time.
Following revocation or objection, we store the data required to prove prior authorization for contact or mailing for up to three years based on our legitimate interests. The processing of this data is limited to the purpose of defending against possible claims. Based on the legitimate interest of permanently observing the revocation or objection of users, we may also store the necessary data (e.g., email address, phone number, name) in a suppression list solely for this purpose.
Processed Data Types: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, phone numbers).
Affected Individuals: Communication partners.
Purposes of Processing: Direct marketing (e.g., by email or post).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Surveys and Questionnaires
We conduct surveys and questionnaires to collect information for the respective communicated purpose of the survey or questionnaire. The surveys and questionnaires (hereinafter collectively referred to as "surveys") conducted by us are evaluated anonymously. Processing of personal data only occurs to the extent necessary to provide and technically carry out the surveys (e.g., processing of the IP address to display the survey in the user's browser or using a cookie to allow the survey to be resumed).
Processed Data Types: Contact data (e.g., email addresses, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Communication partners; participants.
Purposes of Processing: Feedback (e.g., collecting feedback via online form).
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as "reach measurement") is used to evaluate visitor streams to our online offering and can encompass behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. Using reach analysis, we can, for instance, identify at which times our online offering, its features, or its content are most often used or invite re-use. Similarly, we can understand which areas require optimization.
In addition to web analytics, we may also employ testing procedures to optimize our online offering or its components, such as A/B tests. Unless otherwise stated, profiles may be created for these purposes, summarizing data on a usage process, and information may be stored in a browser or on a device and retrieved from it. The collected information may include, in particular, visited websites and elements used there, as well as technical data, such as the browser used, the computer system used, and information on usage times. If users have consented to the collection of their location data, it may also be processed.
IP addresses of users are also stored. However, we use IP masking (i.e., pseudonymization through truncation of the IP address) to protect users. Generally, no clear user data (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimization, but pseudonyms. That is, neither we nor the providers of the software used know the actual identity of the users, only the data stored in their profiles.
Processed Data Types: Usage data (e.g., visited websites, interest in content, access times); meta-, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Individuals: Users (e.g., website visitors, users of online services).
Purposes of Processing: Remarketing; audience creation; reach measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); providing our online offering and user-friendliness; tracking (e.g., interest-/behavior-based profiling, use of cookies); click tracking; A/B testing; heatmaps (mouse movements summarized into an overall picture).
Security Measures: IP masking (pseudonymization of IP address).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Google Analytics 4: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymous user identification number. This identification number does not contain unique data, such as names or email addresses. It is used to associate analysis information with a device to determine which content users accessed during one or more usage processes, which search terms they used, whether they revisited the content, or interacted with our online offering. Additionally, the time and duration of use, as well as the sources referring users to our online offering and technical aspects of their devices and browsers, are recorded. Pseudonymous profiles of users are created using information from different devices, and cookies may be employed. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographic location data by deriving the following metadata from IP addresses: city (and the associated latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU data traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, accessible, or used for any other purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before traffic is forwarded to Analytics servers for processing; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Opt-Out Option: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for displaying advertisements: https://myadcenter.google.com/personalizationoff; Additional Information: https://business.safety.google/adsservices/ (Types of processing and processed data).
Google Signals (Google Analytics feature): Google Signals refers to session data from websites and apps that Google associates with users who are logged into their Google accounts and have enabled ad personalization. This association of data with these logged-in users is used to enable cross-device reporting, cross-device remarketing, and cross-device conversion measurement. This includes: platform-crossing reports - linking data across devices and activities from different sessions using your User-ID or Google Signals data, enabling an understanding of user behavior at every step of the conversion process, from initial contact to conversion and beyond; remarketing with Google Analytics - creating remarketing audiences from Google Analytics data and sharing these audiences with linked advertising accounts; demographics and interests - Google Analytics collects additional information about user demographics and interests from users who are logged into their Google accounts and have enabled ad personalization; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Website: https://support.google.com/analytics/answer/7532985?hl=de; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms; Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Additional Information: https://business.safety.google/adsservices/ (Types of processing and processed data).
Target Group Formation with Google Analytics: We use Google Analytics to ensure that advertisements placed within Google’s advertising services and its partners are only displayed to users who have shown interest in our online offering or who meet specific criteria (e.g., interests in particular topics or products determined by the websites visited) that we communicate to Google (so-called "remarketing" or "Google Analytics Audiences"). Through the use of remarketing audiences, we also aim to ensure that our advertisements align with users' potential interests; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF); Additional Information: Types of processing and processed data: https://business.safety.google/adsservices/. Data processing terms for Google advertising products and standard contractual clauses for third-country data transfers: https://business.safety.google/adsprocessorterms.
Google Analytics in Consent Mode: In consent mode, Google processes users' personal data for measurement and advertising purposes based on users' consent. Consent is obtained from users as part of our online services. If users do not provide consent, data is processed only on an aggregated level (i.e., not attributed to individual users and summarized). If consent is limited to statistical measurement, no personal data of users is processed for ad serving or success measurement (so-called "conversion"); Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Website: https://support.google.com/analytics/answer/9976101?hl=de.
Google Tag Manager: Google Tag Manager is a solution that allows us to manage website tags via an interface and integrate other services into our online offering (refer to further details in this privacy policy). The Tag Manager itself (which implements the tags) does not create user profiles or store cookies. Google only receives users' IP addresses, which are necessary to execute the Google Tag Manager; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms; Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms).
Hotjar Observe: Software for analyzing and optimizing online offerings based on pseudonymously conducted measurements and analyses of user behavior, including A/B tests (measuring the popularity and user-friendliness of different content and features), tracking click paths and interactions with content and features of the online offering (so-called heatmaps and recordings); Service Provider: Hotjar Ltd., 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta; Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Website: https://www.hotjar.com; Privacy Policy: https://www.hotjar.com/legal/policies/privacy; Data Deletion: The cookies used by Hotjar have varying "lifespans"; some remain valid for up to 365 days, while others are only valid during the current visit; Cookie Policy: https://www.hotjar.com/legal/policies/cookie-information; Opt-Out Option: https://www.hotjar.com/legal/compliance/opt-out.
Provision of an Affiliate Program
We offer an affiliate program, i.e., commissions or other benefits (collectively referred to as "commission") for users (referred to as "affiliates") who refer to our offers and services. The referral occurs via a link assigned to the respective affiliate or other methods (e.g., discount codes) that allow us to recognize that the use of our services was based on the referral (collectively referred to as "affiliate links").
To track whether users accessed our services through the affiliate links used by affiliates, it is necessary for us to know that users followed an affiliate link. The assignment of affiliate links to the respective transactions or use of our services is solely for the purpose of commission accounting and will be removed as soon as it is no longer necessary for this purpose.
For the purposes of the aforementioned assignment of affiliate links, affiliate links may be supplemented with specific values that are part of the link or stored otherwise, e.g., in a cookie. These values may include, in particular, the referring website (referrer), the time, an online identifier of the operators of the website where the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer, and an online identifier of the user.
Notes on Legal Bases: The processing of our partners' data takes place to provide our (pre-)contractual services. The data of users is processed based on their consent.
Processed Data Types: Contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., visited websites, interest in content, access times).
Affected Persons: Users (e.g., website visitors, users of online services). Business and contractual partners.
Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations. Affiliate tracking.
Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR). Fulfillment of contracts and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Presences in Social Networks (Social Media)
We maintain online presences within social networks and process users' data in this context to communicate with active users there or to provide information about us.
We point out that user data may be processed outside the European Union. This may pose risks for users because, for example, it could make it more difficult to enforce users' rights.
Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, user behavior and resulting interests may be used to create usage profiles. These usage profiles can, in turn, be used to display advertisements inside and outside the networks that presumably correspond to users' interests. For these purposes, cookies are usually stored on users' devices, in which the usage behavior and interests of the users are stored. Furthermore, data may also be stored in the usage profiles independently of the devices used by the users (especially if the users are members of the respective platforms and logged in).
For a detailed presentation of the respective processing forms and the opt-out options, we refer to the privacy policies and statements of the operators of the respective networks.
In the case of information requests and the assertion of data subject rights, we also point out that these can most effectively be asserted with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. If you still need help, you can contact us.
Processed Data Types: Contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
Affected Persons: Users (e.g., website visitors, users of online services).
Purposes of Processing: Contact requests and communication; feedback (e.g., collecting feedback via online form). Marketing.
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Instagram: Social network;
Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://www.instagram.com;
Privacy Policy: https://instagram.com/about/legal/privacy.Facebook Pages: Profiles within the social network Facebook;
Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://www.facebook.com;
Privacy Policy: https://www.facebook.com/about/privacy;
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further Information: We share joint responsibility with Meta Platforms Ireland Limited for the collection (but not the further processing) of data from visitors to our Facebook page (so-called "Fanpage"). This includes information about the types of content that users view or interact with, or the actions they take (see "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g., IP addresses, operating system, browser type, language settings, cookie data; see "Device information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, known as "Page Insights," to page operators, enabling them to gain insights into how people interact with their pages and related content. We have entered into a specific agreement with Facebook ("Page Insights Information," https://www.facebook.com/legal/terms/page_controller_addendum) that specifically outlines the security measures Facebook must implement and where Facebook has agreed to fulfill data subject rights (i.e., users can submit requests for information or deletion directly to Facebook). Users' rights (particularly access, deletion, objection, and complaint to the responsible supervisory authority) are not restricted by agreements with Facebook. Further information can be found in the "Page Insights Information" (https://www.facebook.com/legal/terms/information_about_page_insights_data). Joint responsibility is limited to the collection and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data lies solely within the responsibility of Meta Platforms Ireland Limited, particularly regarding the transmission of data to the parent company Meta Platforms, Inc. in the USA.TikTok: Social network/video platform;
Service Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://www.tiktok.com;
Privacy Policy: https://www.tiktok.com/de/privacy-policy.YouTube: Social network and video platform;
Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Privacy Policy: https://policies.google.com/privacy;
Basis for third-country transfer: EU-US Data Privacy Framework (DPF);
Opt-Out Option: https://myadcenter.google.com/personalizationoff.
Plugins and Embedded Functions as well as Content:
We integrate functional and content elements into our online offering that are retrieved from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include graphics, videos, or maps (hereinafter uniformly referred to as "content").
The integration always requires that the third-party providers of this content process the users' IP addresses, as they cannot send the content to their browser without the IP address. The IP address is therefore necessary for displaying these contents or functions. We endeavor to only use content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Pixel tags allow information, such as visitor traffic on the pages of this website, to be evaluated. The pseudonymous information may also be stored in cookies on the user's device and contain technical information about the browser and operating system, referring websites, visit time, as well as other details about the use of our online offering, and may also be linked to such information from other sources.
Processed Data Types: Usage data (e.g., visited websites, interest in content, access times); Meta-, communication- and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Affected Persons: Users (e.g., website visitors, users of online services).
Purposes of Processing: Provision of our online offering and user-friendliness; Fulfillment of contractual services and performance of contractual obligations.
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
Google Fonts (Self-hosted): Provision of font files for a user-friendly display of our online offering;
Service Provider: The Google Fonts are hosted on our server, and no data is transmitted to Google;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).OpenStreetMap: We integrate maps from the "OpenStreetMap" service, which are offered on the basis of the Open Data Commons Open Database License (ODbL) by the OpenStreetMap Foundation (OSMF). The users' data is used by OpenStreetMap solely for the purpose of displaying the map functions and temporarily storing the selected settings. This data may include, in particular, IP addresses and location data of users, which, however, are not collected without their consent (usually as part of the settings of their devices or browsers);
Service Provider: OpenStreetMap Foundation (OSMF);
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://www.openstreetmap.de;
Privacy Policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy.reCAPTCHA: We integrate the "reCAPTCHA" function to detect whether entries (e.g., in online forms) are made by humans or by automatically operating machines (so-called "bots"). The data processed may include IP addresses, information about operating systems, devices, or browsers used, language settings, location, mouse movements, keystrokes, dwell time on websites, previously visited websites, interactions with reCAPTCHA on other websites, cookies, and results from manual detection tasks (e.g., answering posed questions or selecting objects in images). Data processing is based on our legitimate interest in protecting our online offering from abusive automated crawling and spam; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://www.google.com/recaptcha/;
Privacy Policy: https://policies.google.com/privacy;
Basis for third-country transfer: EU-US Data Privacy Framework (DPF);
Opt-Out Option: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.
Management, Organization, and Support Tools:
We use services, platforms, and software from other providers (hereinafter referred to as "third-party providers") for the purposes of organization, administration, planning, as well as the provision of our services. In selecting third-party providers and their services, we observe the legal requirements.
In this context, personal data may be processed and stored on the servers of the third-party providers. Various data may be affected, which we process in accordance with this privacy policy. This may include, in particular, master and contact data of users, data on processes, contracts, other processes, and their contents.
If users are referred to third-party providers or their software or platforms in the context of communication, business, or other relationships with us, the third-party providers may process usage data and metadata for security purposes, service optimization, or marketing purposes. We therefore ask that you review the privacy notices of the respective third-party providers.
Processed Data Types: Content data (e.g., entries in online forms); Usage data (e.g., visited websites, interest in content, access times); Meta-, communication-, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Affected Persons: Communication partners; Users (e.g., website visitors, users of online services).
Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; Office and organizational procedures.
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Further Notes on Processing, Procedures, and Services:
ChatGPT: AI-based service designed to understand and generate natural language and associated data inputs, analyze information, and make predictions ("AI," as defined under applicable legal standards);
Service Provider: OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, D01 YC43 Dublin 1, Ireland;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://openai.com/product;
Privacy Policy: https://openai.com/de/policies/eu-privacy-policy;
Opt-Out Option: https://docs.google.com/forms/d/e/1FAIpQLSevgtKyiSWIOj6CV6XWBHl1daPZSOcIWzcUYUXQ1xttjBgDpA/viewform.DALL-E: AI-based image editing service designed to understand and generate natural language and associated data inputs, analyze information, and make predictions ("AI," as defined under applicable legal standards);
Service Provider: OpenAI OpCo, LLC, 3180 18th St., San Francisco, CA 94110 USA;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://openai.com/product;
Privacy Policy: https://openai.com/policies/privacy-policy;
Opt-Out Option: https://docs.google.com/forms/d/e/1FAIpQLSevgtKyiSWIOj6CV6XWBHl1daPZSOcIWzcUYUXQ1xttjBgDpA/viewform.ClickUp: Project management – organizing and managing teams, groups, workflows, projects, and processes;
Service Provider: Mango Technologies, Inc., 580 Howard St, Suite 101, San Francisco, California 94105, USA;
Legal Bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR);
Website: https://clickup.com/;
Privacy Policy: https://clickup.com/privacy;
Data Processing Agreement: https://clickup.com/terms/dpa;
Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
Modification and Update of the Privacy Policy:
We kindly ask you to regularly inform yourself about the contents of our privacy policy. We adapt the privacy policy as soon as the changes in our data processing activities make this necessary. We will inform you if the changes require an action on your part (e.g., consent) or any other individual notification.
If we provide addresses and contact information for companies and organizations in this privacy policy, please note that addresses may change over time and ask you to verify the information before contacting us.