Privacy Policy
Introduction and Overview
We have prepared this privacy policy (version 03.09.2026-113236968) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national legislation, which personal data (hereinafter referred to as data) we, as the controller, and processors we have commissioned (e.g., providers) process now and will continue to process, as well as what legal options you have. The terms used are to be understood in a gender-neutral sense.
In short: We inform you in detail about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy aims to describe the most important things to you as simply and transparently as possible. Where it serves transparency, technical terms are explained in an accessible way, links to further information are provided, and graphics are used. This way, we inform you in clear and simple language that, within the scope of our business activity, we only process personal data when there is a corresponding legal basis. This is certainly not possible if the shortest, most unclear, and legally-technical explanations are given, which are often found online on data protection topics. We hope that the following explanations will be interesting and useful to you, and perhaps you will discover information you were not aware of before.
If you still have questions, please contact the responsible body mentioned below, or in the legal notice (imprint), follow the available links, and consult further information on third-party pages. Our contact details can, of course, also be found in the legal notice.
Scope of Application
This privacy policy applies to all personal data processed by us in the company, as well as to all personal data processed by companies commissioned by us (processors). Personal data means information within the meaning of Article 4, point 1 of the GDPR, such as name, email address, and postal address of a person. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of this privacy policy includes:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile applications for smartphones and other devices
In short: The privacy policy applies to all areas where personal data is processed in a structured manner within the company through the channels mentioned. If we enter into legal relationships with you outside these channels, we will inform you about this separately if necessary.
Legal Bases
In the following privacy policy, we provide you with transparent information regarding the legal principles and regulations, i.e., the legal bases of the General Data Protection Regulation, which allow us to process personal data.
Regarding EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. This EU General Data Protection Regulation can, of course, be read online on EUR-Lex, the portal for access to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We process your data only if at least one of the following conditions is met:
- Consent (Article 6(1)(a) GDPR): You have given us consent to process data for a specific purpose. An example of this is the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) GDPR): To fulfill a contract or pre-contractual obligations with you, we process your data. If, for example, we conclude a sales contract with you, we need personal information in advance.
- Legal Obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to store invoices for accounting purposes. These usually contain personal data.
- Legitimate Interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we must process certain data to be able to operate our website securely and economically efficiently. This processing therefore represents a legitimate interest.
Other conditions, such as the performance of tasks in the public interest and the exercise of official authority, as well as the protection of vital interests, generally do not apply to us. Insofar as such a legal basis is nevertheless applicable, it will be stated at the appropriate place.
In addition to the EU regulation, national laws also apply:
- In Austria, this is the Federal Act on the Protection of Individuals with Regard to the Processing of Personal Data (Data Protection Act), in short DSG.
- In Germany, the Federal Data Protection Act, in short BDSG, applies.
Insofar as additional regional or national laws apply, we will inform you about this in the following sections.
Storage Period
A general criterion for us is that we store personal data only as long as it is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for its processing no longer applies. In some cases, we are legally obliged to store certain data even after the original purpose has ceased, for example for accounting purposes.
If you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no retention obligation.
For the specific duration of the respective data processing, we will inform you below, insofar as we have further information on the matter.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 of the GDPR, we inform you about the following rights that you are entitled to, to ensure fair and transparent data processing:
- In accordance with Article 15 of the GDPR, you have the right to access information about whether we process your data. If this is the case, you have the right to receive a copy of the data and to know the following information:
- for what purpose we carry out the processing;
- the categories, i.e., the types of data that are processed;
- who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure, or restriction of processing and the right to object to processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the origin of the data, if we have not collected it from you;
- whether profiling is carried out, i.e., whether data is processed automatically to create a personal profile about you.
- In accordance with Article 16 of the GDPR, you have the right to rectification of data, which means that we must correct the data if you discover errors.
- In accordance with Article 17 of the GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you can request the deletion of your data.
- In accordance with Article 18 of the GDPR, you have the right to restriction of processing, which means that we can only store the data but not use it further.
- In accordance with Article 20 of the GDPR, you have the right to data portability, which means that upon request, we will provide you with your data in a commonly used format.
- In accordance with Article 21 of the GDPR, you have the right to object, which, when exercised, leads to a change in processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally satisfy this objection.
- If data is used for direct marketing, you can object to this type of data processing at any time. We can then no longer use your data for direct marketing.
- If data is used for profiling, you can object to this type of data processing at any time. We can then no longer use your data for profiling.
- In accordance with Article 22 of the GDPR, in certain circumstances, you have the right not to be subject to a decision based solely on automated processing (e.g., profiling).
- In accordance with Article 77 of the GDPR, you have the right to lodge a complaint. This means that you can lodge a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights – do not hesitate to contact the responsible authority mentioned above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Cookies
|
Cookie Summary
👥 Affected persons: website visitors 🤝 Purpose: depends on the respective cookie. More details can be found below, or with the software manufacturer that sets the cookie. 📓 Processed data: depends on the respectively used cookie. More details can be found below, or with the software manufacturer that sets the cookie. 📅 Storage duration: depends on the respective cookie, can vary from hours to years ⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below, we will explain what cookies are and why they are used, so you can better understand the following privacy policy.
Whenever you browse the internet, you use a browser. Well-known browsers are, for example, Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing is clear: cookies are really helpful assistants. Almost all websites use cookies. More precisely, these are HTTP cookies, as there are also other types of cookies for other applications. HTTP cookies are small files that are stored by our website on your computer. These cookie files are automatically placed in the cookie folder, so to speak, the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as language or personal page settings. When you revisit our page, your browser sends the "user-related" information back to our page. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser, such as Chrome, and a web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our page; third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The validity period of a cookie also varies from a few minutes to several years. Cookies are not software programs and do not contain viruses, Trojans, or other "malware". Cookies also cannot access information from your computer.
Here's what a cookie's data might look like, for example:
Name: _ga
Value: GA1.2.1326744211.152113236968-9
Purpose of use: distinguishing website visitors
Expiration date: after 2 years
These minimum sizes should be supportable by a browser:
- Minimum 4096 bytes per cookie
- Minimum 50 cookies per domain
- Minimum 3000 cookies total
What types of cookies are there?
The question of which cookies we specifically use depends on the services used and will be clarified in the following sections of the privacy policy. At this point, we would like to briefly address the different types of HTTP cookies.
4 types of cookies can be distinguished:
Absolutely necessary cookies
These cookies are necessary to guarantee the basic functions of the website. For example, these cookies are necessary when a user places a product in the shopping cart, then continues to browse other pages and only later proceeds to checkout. Thanks to these cookies, the shopping cart is not deleted, even if the user closes the browser window.
Functional cookies
These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are used to measure loading times and website behavior across different browsers.
Target-oriented cookies
These cookies ensure a better user experience. For example, entered locations, font sizes, or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They serve to provide individually adapted advertising to the user. This can be very practical, but also very annoying.
Usually, when you first visit a website, you are asked which of these types of cookies you wish to allow. And of course, this decision is also stored in a cookie.
If you want to learn more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments document of the Internet Engineering Task Force (IETF), called "HTTP State Management Mechanism".
Purpose of processing through cookies
The purpose ultimately depends on the respective cookie. More details can be found below, or with the software manufacturer that sets the cookie.
What data is processed?
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize what data is stored in cookies, but we will inform you about the data processed or stored in the following privacy policy.
Cookie storage period
The storage period depends on the respective cookie and will be specified below. Some cookies are deleted after less than an hour, others can remain stored on the computer for several years.
Furthermore, you can influence the storage period yourself. You can manually delete all cookies at any time via your browser (see also "Right to object" below). In addition, consent-based cookies are deleted at the latest after you withdraw your consent, whereby the legality of storage until that point remains unaffected.
Right to object – how can I delete cookies?
How and whether you want to use cookies is up to you. Regardless of which service or website the cookies originate from, you always have the option to delete, deactivate or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to determine which cookies are stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable, and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Clear cookies and site data in Firefox
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want cookies, you can set your browser so that it always informs you when a cookie is to be set. This way you can decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It is best to look for instructions on Google by searching for "delete cookies Chrome" or "disable cookies Chrome" for the Chrome browser.
Legal basis
Since 2009, there have been so-called "Cookie Directives". These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). However, within EU countries, reactions to these directives still vary significantly. In Austria, however, the transposition of this directive has been carried out in § 165 para. 3 of the Telecommunications Act (2021). In Germany, the cookie directives have not been transposed into national law. Instead, the transposition of this directive has primarily been carried out in § 15 para. 3 of the Telemedia Act (TMG), which has been replaced by the Digital Services Act (DDG) since May 2024.
For absolutely necessary cookies, even if consent is not available, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to provide website visitors with a pleasant user experience, and for this purpose certain cookies are often absolutely necessary.
Insofar as cookies are used that are not absolutely necessary, this only happens with your consent. The legal basis in this regard is Art. 6 para. 1 lit. a GDPR.
In the following sections, you will be informed in detail about the use of cookies, insofar as the software used utilizes cookies.
Introduction to Web Analytics
|
Summary of the privacy policy regarding web analytics
👥 Data subjects: website visitors 🤝 Purpose: analysis of visitor information to optimize the online offering. 📓 Data processed: access statistics containing data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. Further details can be found with the respective web analytics tool used. 📅 Storage period: depends on the web analytics tool used ⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is web analytics?
On our website, we use software to analyze the behavior of website visitors, in short, web analytics. This involves collecting data that the respective analysis tool provider (also called a tracking tool) stores, manages, and processes. The data is used to create analyses of user behavior on our website and make them available to us as the website operator. In addition, most tools offer various testing options. This allows us to test, for example, which offers or content are best received by our visitors. For this purpose, we show you two different offers for a certain period of time. After the test (a so-called A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analysis procedures, user profiles can be created and data stored in cookies.
Why do we conduct web analytics?
With our website, we have a clear goal: we want to offer the best online offering on the market for our industry. To achieve this goal, we want to offer the best and most interesting content on the one hand, and on the other hand, ensure that you feel completely comfortable on our website. With the help of web analytics tools, we can examine the behavior of visitors to our website more closely and then improve our online offering for you and for us accordingly. For example, we can determine the average age of our visitors, where they come from, when our website is most visited, or which content or products are particularly popular. All this information helps us to optimize the website and thus adapt it as best as possible to your needs, interests, and wishes.
What data is processed?
Exactly what data is stored depends, of course, on the analysis tools used. But as a rule, for example, what content you view on our website, which buttons or links you click on, when you open a page, which browser you use, with which device (PC, tablet, smartphone, etc.) you visit the website, or what computer system you use is stored. If you have also agreed to the collection of location data, this can also be processed by the web analytics tool provider.
In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are personal data. However, your IP address is usually stored pseudonymized (i.e., in an unrecognizable and shortened form). For the purposes of testing, web analysis, and website optimization, direct data such as your name, age, address, or email address are generally not stored. All this data, insofar as it is collected, is stored pseudonymized. Thus, you cannot be identified as a person.
The following example schematically shows how Google Analytics works as an example of client-based web tracking with JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data for only a few minutes, or until you leave the website again, other cookies can store data for several years.
Duration of data processing
We will inform you below about the duration of data processing, insofar as we have further information on the matter. In principle, we process personal data only as long as it is absolutely necessary for the provision of our services and products. If, as in the case of accounting, this is legally prescribed, the storage period can also be longer.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies, or third-party providers. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent the collection of data via cookies by managing, deactivating, or deleting cookies in your browser.
Legal basis
The use of web analytics requires your consent, which we have obtained through our cookie pop-up. This consent represents, according to Art. 6 para. 1 lit. a GDPR (consent), the legal basis for the processing of personal data, which may arise from collection via web analytics tools.
In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors and thus improving our offering technically and economically. With the help of web analytics, we detect errors on the website, can identify attacks, and improve economic efficiency. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). However, we only use the tools insofar as consent has been given.
Since cookies are used in web analytics tools, we recommend that you also read our general privacy policy on cookies. To understand exactly what data is stored and processed about you, you should read the privacy policies of the respective tools.
Information on specific web analytics tools can be found – if available – in the following sections.
Google Analytics Privacy Policy
|
Summary of the Google Analytics Privacy Policy
👥 Data subjects: website visitors 🤝 Purpose: analysis of visitor information to optimize the online offering. 📓 Data processed: access statistics containing data such as access locations, device data, duration and time of access, navigation behavior and click behavior. Further details can be found below in this privacy policy. 📅 Storage period: individually configurable, by default Google Analytics 4 stores data for 14 months ⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is Google Analytics?
On our website, we use the analysis and tracking tool Google Analytics in the Google Analytics 4 (GA4) version from the American company Google Inc. For the European area, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. Through the combination of various technologies, such as cookies, device identifiers, and login data, you as a user can be identified across different devices. This allows your actions to be analyzed across different platforms.
For example, if you click on a link, this event is stored in a cookie and sent to Google Analytics. With the help of the reports we receive from Google Analytics, we can better adapt our website and our service to your wishes. Below, we will look at the tracking tool in more detail and, above all, inform you what data is processed and how you can prevent this.
Google Analytics is a tracking tool that serves to analyze the traffic on our website. The basis for these measurements and analyses is a pseudonymous user ID. This number does not contain personal data such as name or address, but serves to link events to an end device. GA4 uses an event-based model that collects detailed information about user interactions, such as page views, clicks, scrolls, conversion events. In addition, various machine learning functions are integrated into GA4 to better understand user behavior and certain trends. GA4 relies on modeling using machine learning functions. This means that based on the collected data, missing data can also be extrapolated to optimize the analysis and make predictions.
For Google Analytics to function in principle, a tracking code is embedded in the code of our website. When you visit our website, this code records various events that you perform on our website. With the event-based data model of GA4, we as website operators can define and track specific events to obtain analyses of user interactions. Thus, in addition to general information such as clicks or page views, special events important for our business can also be tracked. Such special events can be, for example, sending a contact form or purchasing a product.
As soon as you leave our website, this data is sent to the Google Analytics servers and stored there.
Google processes the data, and we receive reports on your user behavior. These can include the following reports:
- Audience reports: through audience reports, we get to know our users better and know more precisely who is interested in our service.
- Advertising reports: through advertising reports, we can more easily analyze and improve our online advertising.
- Acquisition reports: acquisition reports give us useful information on how we can get more people interested in our service.
- Behavior reports: here we understand how you interact with our website. We can track what path you take on our page and which links you click on.
- Conversion reports: a conversion is the process by which you perform a desired action as a result of a marketing message. For example, when you become a buyer or newsletter subscriber from a regular website visitor. With the help of these reports, we learn more about how our marketing measures affect you. In this way, we want to increase our conversion rate.
- Real-time reports: here we always immediately learn what is currently happening on our website. For example, we see how many users are currently reading this text.
- Event-based data model: this model records very specific events that can occur on our website. For example, playing a video, purchasing a product, or signing up for our newsletter.
- Enhanced analytical functions: with these functions, we can understand your behavior on our website or certain general trends even better. For example, we can segment user groups, perform comparative audience analyses, or track your path or route on our website.
- Predictive modeling: based on the collected data, missing data can be extrapolated using machine learning to predict future events and trends. This can help us develop better marketing strategies.
- Cross-platform analysis: data collection and analysis are possible from both websites and apps. This enables us to analyze user behavior across different platforms, of course, to the extent that you have consented to data processing.
- 2 months: this is the shortest retention period.
- 14 months: by default, data in GA4 is stored for 14 months.
- 26 months: data can also be stored for 26 months.
- Data is only deleted when we manually delete it
- Facebook Pixel
- social plugins (such as "Like" or "Share" buttons)
- Facebook Login
- Account Kit
- API (application programming interface)
- SDK (software development kit)
- platform integrations
- plugins
- codes
- specifications
- documentation
- technologies and services
- Name
- Address
- Email address
- Postal address
- Phone number
- Date of birth
- Identification numbers such as social security number, tax ID, ID card number, or matriculation number
- Bank data such as account number, credit information, account balances, etc.
- racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data, such as data derived from blood or saliva samples
- biometric data (this is information about mental, physical, or behavioral characteristics that identify a person).
Health data - data concerning sexual orientation or sexual life
In addition to the analytical reports mentioned above, Google Analytics 4 also offers the following features, among others:
Why do we use Google Analytics on our website?
Our goal with this website is clear: we want to offer you the best possible service. The statistics and data from Google Analytics help us achieve this goal.
The statistically analyzed data gives us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimize our page so that it can be found more easily by interested people on Google. On the other hand, the data helps us to understand you better as a visitor. This way, we know very precisely what we need to improve on our website to offer you the best possible service. The data also serves us to carry out our advertising and marketing measures more individually and cost-effectively. Ultimately, it makes sense to show our products and services only to people who are interested in them.
What data does Google Analytics store?
Google Analytics uses a tracking code to create a random, unique identifier linked to your browser cookie. This way, Google Analytics recognizes you as a new user and assigns you a user ID. The next time you visit our page, you are recognized as a "returning" user. All collected data is stored together with this user ID. This is the only way to analyze pseudonymous user profiles.
In order for us to analyze our website with Google Analytics, a Property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, a Google Analytics 4 property is used by default. Depending on the property used, the data is stored for different periods of time.
Through identifiers such as cookies, app instance IDs, user IDs, or, for example, custom event parameters, your interactions, to the extent that you have consented, are measured across different platforms. Interactions are all types of actions you perform on our website. If you also use other Google systems (such as a Google account), the data generated by Google Analytics can be linked to third-party cookies. Google does not transmit data from Google Analytics unless we, as website operators, approve it. Exceptions may occur if legally required.
According to Google, IP addresses are not recorded or stored in Google Analytics 4. However, Google uses IP address data to derive location data and deletes it immediately thereafter. All IP addresses collected from users in the EU are deleted before the data is stored in a data center or on a server.
Since Google Analytics 4 focuses on event-based data, the tool uses significantly fewer cookies compared to previous versions (such as Google Universal Analytics). However, there are some specific cookies used by GA4. These include, for example:
Name: _ga
Value: 2.1326744211.152113236968-5
Purpose of use: by default, analytics.js uses the _ga cookie to store the user ID. It generally serves to distinguish website visitors.
Expiration date: after 2 years
Name: _gid
Value: 2.1687193234.152113236968-1
Purpose of use: the cookie also serves to distinguish website visitors
Expiration date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose of use: used to reduce the request rate. If Google Analytics is provided via Google Tag Manager, this cookie is named _dc_gtm_<property-id>.
Expiration date: after 1 minute
Note: This list does not claim to be exhaustive, as Google constantly changes its selection of cookies. The goal of GA4 is also to improve data protection. Therefore, the tool offers some options for controlling data collection. For example, we can determine the storage period ourselves and manage data collection.
Here we show you an overview of the most important types of data collected with Google Analytics:
Heatmaps: Google creates so-called heatmaps. Heatmaps show exactly which areas you click on. This gives us information about where you "move" on our page.
Session duration: Google refers to the time you spend on our page without leaving it as session duration. If you have been inactive for 20 minutes, the session automatically ends.
Bounce rate: a bounce occurs when you view only one page of our website and then leave it again.
Account creation: when you create an account on our website or place an order, Google Analytics collects this data.
Location: IP addresses are not recorded or stored in Google Analytics. However, derived location data is used immediately before the IP address is deleted.
Technical information: technical information includes, among other things, your browser type, your internet provider, or your screen resolution.
Source of origin: Google Analytics, or rather us, is also interested in which website or advertisement led you to our page.
Other data include contact data, possible ratings, media playback (e.g., when you play a video through our page), sharing content via social media, or adding to your favorites. This list is not exhaustive and serves only as a general orientation regarding the storage of data by Google Analytics.
How long and where is the data stored?
Google has servers distributed worldwide. Here you can read exactly where Google's data centers are located: https://datacenters.google/
Your data is distributed across various physical data carriers. This has the advantage that the data is more quickly accessible and better protected against manipulation. In each Google data center, there are corresponding emergency programs for your data. If, for example, Google's hardware fails or natural disasters disable servers, the risk of service interruption at Google remains low nevertheless.
The data retention period depends on the properties used. The retention period is always determined separately for each individual property. Google Analytics offers us four options for controlling the retention period:
In addition, there is also the option that data is only deleted when you no longer visit our website within the period we have selected. In this case, the retention period is reset every time you visit our website again within the defined period.
When the defined period expires, the data is deleted once a month. This retention period applies to your data related to cookies, user recognition, and advertising identifiers (e.g., DoubleClick domain cookies). Report results are based on aggregated data and are stored independently of user data. Aggregated data is a merger of individual data into a larger unit.
How can I delete my data or prevent data storage?
According to EU data protection legislation, you have the right to obtain information about your data, update, delete, or restrict it. By using the Google Analytics JavaScript deactivation browser extension (analytics.js, gtag.js), you prevent Google Analytics 4 from using your data. You can download and install the browser extension from https://tools.google.com/dlpage/gaoptout?hl=de. Please note that this extension only deactivates data collection by Google Analytics.
If you generally want to deactivate, delete, or manage cookies, you will find the corresponding links to instructions for the most popular browsers in the "Cookies" section.
Legal basis
The use of Google Analytics requires your consent, which we have obtained through our cookie pop-up. This consent, according to Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may arise from collection by web analysis tools.
In addition to your consent, we have a legitimate interest in analyzing the behavior of website visitors and thus improving our offering technically and economically. With the help of Google Analytics, we detect website errors, can identify attacks, and improve economic efficiency. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Google Analytics to the extent that you have given your consent.
Google processes your data, among other places, in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
Furthermore, Google uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and standard contractual clauses, Google commits to complying with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the corresponding standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data processing terms for Google advertising products (Google Ads Data Processing Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
We hope we have been able to provide you with the most important information regarding data processing by Google Analytics. If you would like to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.
If you would like to learn more about data processing, please refer to Google's privacy policy at https://policies.google.com/privacy?hl=de.
Meta Conversions API Privacy Policy
|
Summary of the Meta Conversions API Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: optimization of our service 📓 Processed data: data such as customer data, user behavior data, information about your device and your IP address. More details can be found below in the privacy policy. 📅 Storage period: as long as the data is useful for Meta's purposes ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is the Meta Conversions API?
We use the Meta Conversions API on our website, a server-side tool for event tracking. The service provider is the American company Meta Platforms Inc. For the European area, the responsible company is Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).
The Meta Conversions API is a tool or function that can measure the effectiveness of our advertising campaigns in real time. The API is an interface that connects our website to Meta and thus measures certain actions on our website. A conversion occurs when you, as a website visitor, perform a desired action. This can be, for example, clicking a button or filling out a registration form. This method of conversion tracking is an alternative to Meta Pixel and aims to optimize conversion tracking through precision and reliability. The API sends data from our server directly to Meta. Personal data may also be processed in this process. In this privacy policy, we will discuss in more detail the data processing by us, or by Meta.
Why do we use the Meta Conversions API on our website?
We use the Meta Conversions API to improve the quality of our website, our offering, and our advertising campaigns. Our goal is to provide you with the best possible service. We want you to feel comfortable on our website and get exactly what you expect. To do this, we naturally need to adapt our offering as best as possible to your wishes and requirements. With the Meta Conversions API, we can respond very well to this and individually adapt content and offers. This flexibility helps us to take different needs into account and thus simultaneously improve our online offering. The data also helps us to conduct our advertising measures more cost-effectively and more individually. Because we naturally only want to show our offer to people who are genuinely interested in it.
What data is stored by the Meta Conversions API?
With the help of the Meta Conversions API, we can collect various event data on our website and provide it to Meta. Exactly which data is stored and processed depends on our individual settings and the specific events and parameters. As a rule, event data, user data, device data, and the time at which an event occurred (e.g., clicking a button) are stored and sent to Meta. Event data includes actions such as registration, product purchase, page views, or button clicks that can be performed on our website. User data may also include personal data such as IP address, name, address, or email address. Device data refers to your device type, operating system, browser, and screen resolution.
How long and where is the data stored?
In principle, Meta stores data as long as it is no longer necessary for Meta's own services and products. Meta has servers distributed worldwide where data is stored. Customer data, however, is deleted within 48 hours after being matched with Meta's own user data.
How can I delete my data or prevent data storage?
You have the right and the opportunity at any time to access your personal data and to object to its use and processing. You can also file a complaint with a state supervisory authority at any time. In principle, you prevent data storage by not agreeing to data processing via the consent management tool. The Meta Conversions API works server-side, and therefore data deletion differs from client-side methods. However, you can check the privacy and security settings in your browser and, if possible, block tracking resources (pixels, cookies, scripts).
Legal basis
If you have consented to your data being processed and stored via the Meta Conversions API, this consent is considered the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or with other customers and business partners. However, we only use the Meta Conversions API to the extent that you have given your consent.
Meta processes your data, among other places, in the USA. Meta Platforms is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Meta uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model clauses provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the standard contractual clauses, Meta commits to complying with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the relevant standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find Meta's data processing terms, which refer to the standard contractual clauses, at https://www.facebook.com/legal/terms/dataprocessing.
You can learn more about the data processed through the use of Meta Conversions API in the privacy policy at https://www.facebook.com/about/privacy.
Introduction to Messengers and Communication
|
Summary of the Privacy Policy on Messengers and Communication
👥 Data subjects: website visitors 🤝 Purpose: contact requests and general communication between us and you 📓 Processed data: data such as name, address, email address, telephone number, general content data, possibly IP address More details can be found for the respective tools used. 📅 Storage period: depends on the messenger and communication functions used ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1) sentence 1(b) GDPR (contractual or pre-contractual obligations) |
What are messenger and communication functions?
We offer various options on our website (e.g., messenger and chat functions, online or contact forms, email, telephone) for you to communicate with us. In doing so, your data is also processed and stored, to the extent necessary to respond to your request and our subsequent actions.
In addition to classic communication methods such as email, contact forms, or telephone, we also use chats and messengers. Currently, the most commonly used messenger function is WhatsApp, but of course there are many different providers specialized in offering messenger functions specifically for websites. If content is end-to-end encrypted, this is indicated in the individual data protection texts or in the privacy policy of the respective provider. End-to-end encryption means nothing more than that the content of a message is not visible even to the provider. However, information about your device, location settings, and other technical data may still be processed and stored.
Why do we use messenger and communication functions?
The possibilities for communication with you are of great importance to us. Ultimately, we want to talk to you and answer all possible questions about our service as best as possible. Well-functioning communication is an important part of our service. With the practical messenger and communication functions, you can choose your preferred ones at any time. In exceptional cases, however, it may happen that we do not answer certain questions via chat or messenger. This is the case, for example, when it comes to internal contractual matters. In such cases, we recommend other communication options, such as email or telephone.
In principle, we assume that we remain responsible for data protection, even when using the services of a social media platform. However, the Court of Justice of the European Union has ruled that in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Art. 26 GDPR. To the extent that this is the case, we will indicate this separately and work on the basis of a corresponding agreement on this matter. The essence of the agreement is presented below for the respective affected platform.
Please note that when using our embedded elements, your data may also be processed outside the European Union, as many providers, such as Facebook Messenger or WhatsApp, are American companies. It is therefore possible that you may not be able to assert or enforce your rights regarding your personal data as easily.
What data is processed?
Exactly what data is stored and processed depends on the respective provider of the messenger and communication functions. In principle, it concerns data such as name, address, telephone number, email address, and content data, such as all information you enter into a contact form. Information about your device and the IP address are usually also stored. The data collected through a messenger and communication function is also stored on the providers' servers.
If you want to know exactly what data is stored and processed by the respective providers and how you can object to the data processing, you should carefully read the respective company's privacy policy.
How long is the data stored?
How long the data is processed and stored depends primarily on the tools we use. Below, you will learn more about the data processing of the individual tools. The privacy policies of the providers usually specify exactly which data is stored and processed for how long. In principle, personal data is only processed for as long as necessary to provide our services. If data is stored in cookies, the storage period varies greatly. Data can be deleted immediately after leaving the website, but can also remain stored for several years. Therefore, you should examine each individual cookie in detail if you want to know more precisely about data storage. Usually, you will also find useful information about individual cookies in the privacy policies of the individual providers.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies or third-party providers. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating, or deleting cookies in your browser. For more information, we refer to the section on consent.
Since cookies may be used for messenger and communication functions, we also recommend our general privacy policy on cookies. To understand exactly what data is stored and processed for you, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to your data being processed and stored through embedded messenger and communication functions, this consent is considered the legal basis for data processing (Art. 6(1)(a) GDPR). We process your request and manage your data within the framework of contractual or pre-contractual relations to fulfill our pre-contractual and contractual obligations or to respond to requests. The basis for this is Art. 6(1) sentence 1(b) GDPR. In principle, your data, with your consent, is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or with other clients and business partners.
Facebook Messenger Privacy Policy
|
Summary of the Facebook Messenger Privacy Policy
👥 Data subjects: Facebook Messenger users 🤝 Purpose: communication 📓 Processed data: contact data, messages, media 📅 Storage period: after account deletion ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Facebook Messenger?
We use the instant messaging service Facebook Messenger on our website. The service provider is the American company Meta Platforms Inc. For the European area, the company Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is responsible.
Facebook Messenger is a chat messaging function developed by Facebook through which you can send and receive text messages, voice and video calls, photos, and other media files to other Facebook users.
When you use Facebook Messenger, your personal data is also processed on Facebook's servers. This includes, in addition to your phone number and chat messages, among other things, sent photos, videos, profile data, your address or your location.
Why do we use Facebook Messenger?
We want to stay in touch with you, and this works best through messaging services like Facebook Messenger. On the one hand, because the service works flawlessly, on the other hand, because Facebook is still one of the most famous social media platforms. The service is practical and allows for simple and fast communication with you.
What data is processed by Facebook Messenger?
Through the use of Facebook Messenger, various types of data can be processed, including personal data. This includes account information such as your phone number, your profile picture, your username, or other information you provide to Facebook when creating and managing your account. Of course, Facebook also stores the content of your messages (text, photos, videos, voice messages). Facebook also stores so-called metadata, such as the date and time a message was sent or received. Facebook Messenger can also access your contacts to enable communication with your contacts. In addition, technical data such as device type, operating system, or location data are also stored.
How long and where is the data stored?
In principle, Facebook stores data until it is no longer necessary for Facebook's own services and products. Facebook has servers distributed all over the world where its data is stored. However, customer data is deleted within 48 hours after being matched with its own user data.
How can I delete my data or prevent data storage?
You have the right to access, rectify, delete, and restrict the processing of your personal data at any time. In addition, you can withdraw your consent to data processing at any time. Data is definitively deleted only if you delete your Facebook account.
Follow these steps to completely delete your Facebook account:
1) Log in to Facebook and then click "Settings" in the upper right corner.
2) Then click "Your Facebook Information" in the left column.
3) Now click "Deactivation and Deletion."
4) Select "Delete Account" and then click "Continue to Account Deletion."
5) Now enter your password, click "Continue," and then "Delete Account."
Legal Basis
The use of Facebook Messenger requires your consent, which we have obtained through our consent tool (pop-up window). This consent constitutes the legal basis for the processing of personal data, which may arise from collection through Facebook Messenger, in accordance with Art. 6(1)(a) GDPR (consent).
In addition to consent, we have a legitimate interest in improving our service. With Facebook Messenger, we can communicate with you faster and better. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Facebook Messenger if you have given your consent.
Facebook processes your data, among other places, in the USA. Facebook, or Meta Platforms, is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Facebook uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model clauses provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the standard contractual clauses, Facebook commits to complying with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the relevant standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find Facebook's data processing terms, which refer to the standard contractual clauses, at https://www.facebook.com/legal/terms/dataprocessing.
You can learn more about the data processed through the use of Facebook in the privacy policy at https://www.facebook.com/about/privacy.
Signal Messenger Privacy Policy
We use the messenger service Signal Messenger on our website. The service provider is the American company Signal Messenger LLC, 650 Castro Street, Suite 120-223 Mountain View, CA 94041, USA.
What is Signal Messenger?
Signal Messenger is an open-source application through which we can conduct secure and private communication via text messages, voice, or video calls. The tool was founded in 2014 by Moxie Marlinspike and Stuart Anderson. Signal works on iOS, Android, and desktop computers. An important feature of Signal is end-to-end encryption. This encryption ensures that messages or calls can only be read, seen, or heard by the involved parties. Even Signal developers cannot decrypt messages.
Why do we use Signal Messenger?
Of course, we want to stay in communication with you. When we had to choose a messenger, our choice quickly fell on Signal Messenger. Since data security is important to us, we highly value the possibility of encrypted communication that the tool offers us. In addition, there are additional security settings, such as automatic data deletion or two-factor authentication.
How secure is data transfer with Signal Messenger?
Signal processes data, among other places, in the USA. We note that, in the opinion of the Court of Justice of the European Union, there is currently no adequate level of protection for data transfers to the USA. This can be associated with various risks for the lawfulness and security of data processing.
As a basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, therefore especially in the USA) or data transfer there, Signal uses standard contractual clauses approved by the European Commission (= Art. 46(2) and (3) GDPR). These clauses oblige Signal to comply with the EU data protection level when processing the relevant data outside the EU. These clauses are based on an implementing decision of the European Commission. The decision, as well as the clauses, can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can learn more about the data processed through the use of Signal in the privacy policy at https://signal.org/legal/.
Telegram Privacy Policy
|
Summary of Telegram Privacy Policy
👥 Data subjects: Telegram users 🤝 Purpose: communication 📓 Processed data: contact data, messages, media 📅 Retention period: after account deletion or deactivation ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Telegram?
We also use the instant messaging service Telegram. The service provider is the international company Telegram Messenger LLP, managed from a London address (71-75 Shelton Street, Covent Garden, London, UK) and developed in Russia.
Telegram was founded in 2013 by Nikolai and Pavel Durov. Since the Telegram team considers itself to be so-called digital nomads, it is never entirely clear where the team works. The Telegram website also lacks legal information (impressum).
Like other messaging services, such as WhatsApp, messages, photos, videos, and other files can be sent via Telegram, and phone calls can also be made. This messaging service has been gaining increasing popularity in recent years. In 2022, it already had over 700 million users.
When using Telegram, personal data is also processed and stored on Telegram's servers. This includes chat messages, as well as sent photos, videos, profile data, IP address, and synchronized contacts. Telegram encrypts data between the server and your end device, but can only offer end-to-end encryption for secret chats. Data stored in the cloud can be viewed by the company and also by third-party providers.
Why do we use Telegram?
Many people already use Telegram as an alternative to other messaging services, such as WhatsApp. We want to stay in touch with you, and this works best through an instant messaging service that many of our customers also use. The service functions flawlessly, is practical, and allows for uncomplicated communication with you.
What data is processed by Telegram?
By using Telegram, various types of data can be processed, including personal data. This includes account information such as your phone number, your profile picture, your username, or other information you provide to Telegram when creating and managing your account. Of course, Telegram also stores the content of your messages (text, photos, videos, voice messages). Telegram also stores so-called metadata, such as the date and time a message was sent or received. Telegram may also access your contacts to enable communication with your contacts. In addition, technical data such as device type, operating system, or location data are also stored.
How long and where is the data stored?
In principle, data on Telegram is stored as long as necessary for legitimate purposes and the fulfillment of legal obligations. Exactly how long the data is stored cannot be specifically answered here, as this heavily depends on the type of data. According to Telegram, data is stored for up to 12 months. The data is stored on Telegram's own servers, distributed worldwide. Unfortunately, the exact location of these servers is not known.
How can I delete my data or prevent data storage?
You have the right at any time to access, correct, delete, and restrict the processing of your personal data. In addition, you can withdraw your consent to data processing at any time. Individual messages, as well as entire chat conversations, can be deleted directly in Telegram. In addition, you have the option to deactivate or delete your account in the settings. Initially, a copy of the data is deleted, and it may take some time for the data to be deleted from Telegram's servers as well.
Legal Basis
The use of Telegram requires your consent, which we have obtained through our consent tool (pop-up). This consent, in accordance with Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may arise from collection via Telegram.
In addition to consent, we have a legitimate interest in improving our communication offering. With the help of Telegram, we can respond to your inquiries faster and better, communicate important messages to you, and thus elevate our service to the next level. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Telegram if you have given your consent.
You can find more about the data processed through the use of Telegram in the privacy policy at https://telegram.org/privacy.
WhatsApp Privacy Policy
|
Summary of WhatsApp Privacy Policy
👥 Data subjects: WhatsApp users 🤝 Purpose: communication 📓 Processed data: contact data, messages, media 📅 Retention period: after account deletion or deactivation ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is WhatsApp?
We use the instant messaging service WhatsApp on our website. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. (until October 2021, Facebook Inc.). For the European area, WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, is responsible.
It's likely unnecessary to introduce WhatsApp to you in detail. The probability that you yourself use this well-known messaging service on your smartphone is relatively high. For many years, there have been voices criticizing WhatsApp, or rather its parent company Meta Platforms, regarding its handling of personal data. The main criticism in recent years concerned the merging of WhatsApp user data with Facebook. Consequently, Facebook reacted in 2021 and adapted its terms of use. Facebook stated in them that personal data of WhatsApp users is currently (as of 2021) not shared with Facebook.
Nevertheless, of course, a lot of your personal data is processed in WhatsApp, as long as you use WhatsApp and have agreed to the data processing. This includes your phone number and chat messages, as well as sent photos, videos, and profile data. Photos and videos, however, should only be stored temporarily for a short period, and all messages and phone calls are end-to-end encrypted. Therefore, they should not be visible even to Meta itself. In addition, information from your address book and additional metadata are also stored in WhatsApp.
Why do we use WhatsApp?
We want to stay in touch with you, and this works best through WhatsApp. On the one hand, because the service works flawlessly, on the other hand, because WhatsApp is still the most widely used instant messaging tool worldwide. The service is practical and allows for uncomplicated and quick communication with you.
What data is processed by WhatsApp?
By using WhatsApp, various types of data can be processed, including personal data. This includes account information such as your phone number, your profile picture, your username, or other information you provide to WhatsApp when creating and managing your WhatsApp account. Of course, WhatsApp also stores the content of your messages (text, photos, videos, voice messages). WhatsApp also stores so-called metadata, such as the date and time a message was sent or received. Phone numbers of the participants and technical data such as device type, operating system, or location data are also stored.
How long and where is the data stored?
In principle, data on WhatsApp is stored as long as necessary for legitimate purposes and the fulfillment of legal obligations. Exactly how long the data is stored cannot be specifically answered here, as this heavily depends on the type of data. As a rule, messages are stored in WhatsApp only during delivery in encrypted form, and as soon as the message is delivered, they are deleted from the servers. Messages are stored longer only on your own end device. When media is sent, WhatsApp stores this data in encrypted form for up to 30 days to optimize delivery. Account data is stored as long as you have an active WhatsApp account. If you delete or deactivate the account, your account data is usually also deleted. The data stored in WhatsApp is stored by the company on its own servers, distributed worldwide. To enable the web-based services of WhatsApp, data is also collected using cookies.
How can I delete my data or prevent data storage?
You have the right at any time to access, correct, delete, and restrict the processing of your personal data. In addition, you can withdraw your consent to data processing at any time.
If you do not want cookies to be set in the desktop version and thus data to be stored, you can prevent cookies from being set in your browser. Because in your browser, you can manage, deactivate, or delete cookies. Depending on your browser, this always works a little differently. You can find more information about this in our cookie section.
Legal Basis
The use of WhatsApp requires your consent, which we have obtained through our consent tool (pop-up). This consent, in accordance with Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may arise from collection via WhatsApp.
In addition to consent, we have a legitimate interest in improving our communication offering. With the help of WhatsApp, we can respond to your inquiries faster and better, communicate important messages to you, and thus elevate our service to the next level. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use WhatsApp if you have given your consent.
WhatsApp processes your data, among other things, in the USA. WhatsApp is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, WhatsApp uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are sample templates provided by the European Commission and are intended to ensure that your data meets European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and through the standard contractual clauses, WhatsApp commits to comply with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the corresponding standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
Information regarding data transfer in WhatsApp, compliant with standard contractual clauses, can be found at https://www.whatsapp.com/legal/business-data-transfer-addendum-20210927
We hope that we have been able to provide you with the most important information regarding the use and data processing by WhatsApp. You can find more about the data processed through the use of WhatsApp in the privacy policy at https://www.whatsapp.com/privacy.
Introduction to Social Media
|
Summary of Social Media Privacy Policy
👥 Data subjects: website visitors 🤝 Purpose: presentation and optimization of our service, contact with visitors, interested parties, etc., advertising 📓 Processed data: data such as phone numbers, email addresses, contact data, user behavior data, information about your device and your IP address. More details can be found with the respective social media tool used. 📅 Retention period: depends on the social media platforms used ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is social media?
In addition to our website, we are also active on various social media platforms. In doing so, user data may be processed so that we can specifically address users who are interested in us through social networks. In addition, elements of a social media platform can be directly integrated into our website. This is the case, for example, when you click on a so-called social button on our website and are redirected directly to our social media presence. So-called social media refers to websites and applications through which registered members can produce content, exchange content openly or in specific groups, and connect with other members.
Why do we use social media?
For years, social media platforms have been the place where people interact and connect online. With our social media presences, we can bring our products and services closer to interested parties. The social media elements integrated into our website help you to quickly and easily switch to our social media content.
The data stored and processed through your use of a social media channel primarily serves the purpose of conducting web analytics. The aim of these analyses is to develop more accurate and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, suitable conclusions can be drawn about your interests with the help of the analyzed data, and so-called user profiles can be created. This makes it possible for the platforms to present you with individually tailored advertising. Usually, cookies are placed in your browser for this purpose, storing data about your usage behavior.
In principle, we assume that we remain responsible for data protection, even when using the services of a social media platform. However, the European Court of Justice has ruled that in certain cases, the operator of the social media platform can be jointly responsible with us within the meaning of Art. 26 GDPR. Insofar as this is the case, we will indicate this separately and work on the basis of a corresponding agreement on this matter. The essence of the agreement is presented below with the respective affected platform.
Please note that when using social media platforms or our integrated elements, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are American companies. Therefore, it may not be as easy for you to assert or enforce your rights regarding your personal data.
What data is processed?
Exactly which data is stored and processed depends on the respective provider of the social media platform. But usually, it concerns data such as phone numbers, email addresses, data that you enter into a contact form, user data such as which buttons you click on, who you like or follow, when you visited which pages, information about your device and your IP address. Most of this data is stored in cookies. Especially if you yourself have a profile on the visited social media channel and are logged in, the data can be linked to your profile.
All data collected through a social media platform is also stored on the providers' servers. Thus, only the providers have access to the data and can provide you with the corresponding information or make changes.
If you want to know exactly what data is stored and processed by social media providers and how you can object to data processing, you should carefully read the respective company's privacy policy. Also, if you have questions about data storage and processing or want to exercise your respective rights, we recommend that you contact the provider directly.
Duration of Data Processing
We will inform you below about the duration of data processing, insofar as we have additional information on the matter. For example, the social media platform Facebook stores data until it is no longer needed for its own purpose. However, customer data, compared to their own user data, is deleted within two days. In principle, we only process personal data for as long as it is absolutely necessary for the provision of our services and products. If, as is the case for example with accounting, this is legally prescribed, the storage period may be longer.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies, or third-party providers, as embedded social media elements. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating, or deleting cookies in your browser.
Since cookies may be used with social media tools, we also recommend our general privacy policy regarding cookies. To understand exactly what data is stored and processed about you, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to your data being processed and stored through embedded social media elements, this consent is considered the legal basis for data processing (Art. 6 (1)(a) GDPR). In principle, your data, with your consent, is also stored and processed based on our legitimate interest (Art. 6 (1)(f) GDPR) in fast and good communication with you or with other clients and business partners. However, we only use the tools to the extent you have given consent. Most social media platforms also place cookies in your browser to store data. Therefore, we recommend that you carefully read our data protection text regarding cookies and review the privacy policy or the cookie policy of the respective service provider.
Information on specific social media platforms will be found – where available – in the following sections.
Facebook Privacy Policy
|
Summary of Facebook's Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: optimizing our service 📓 Processed data: data such as customer data, user behavior data, information about your device and your IP address. More details can be found below in the privacy policy. 📅 Storage period: as long as the data is useful for Facebook's purposes ⚖️ Legal bases: Art. 6 (1)(a) GDPR (consent), Art. 6 (1)(f) GDPR (legitimate interests) |
What are Facebook Tools?
We use selected Facebook tools on our website. Facebook is a social network of Meta Platforms Inc., or for the European area of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. With the help of these tools, we can offer you and people interested in our products and services the best possible offer.
If your data is collected and transmitted through our embedded Facebook elements or through our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook is solely responsible for the further processing of this data. Our common obligations are also enshrined in a publicly accessible agreement at https://www.facebook.com/legal/controller_addendum. It stipulates, among other things, that we must clearly inform you about the use of Facebook tools on our page. In addition, we are also responsible for ensuring that the tools are embedded in our website in a data protection-secure manner. Facebook, in turn, is responsible, for example, for the data security of Facebook products. If you have any questions about data collection and processing by Facebook, you can contact the company directly. If you address the question to us, we are obliged to forward it to Facebook.
Below we give you an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.
Among many other products, Facebook also offers the so-called "Facebook Business Tools". This is the official name for Facebook. However, since the term is little known, we decided to simply call them Facebook tools. These include, among others:
Through these tools, Facebook expands its services and has the opportunity to receive information about user activities outside of Facebook.
Why do we use Facebook tools on our website?
We want to show our services and products only to people who are truly interested in them. With the help of ads (Facebook Ads), we can reach exactly these people. However, for relevant advertising to be displayed to users, Facebook needs data about people's wishes and needs. Thus, the company is provided with information about user behavior (and contact data) on our website. In this way, Facebook collects better user data and can show interested people suitable advertising for our products or services. Thus, the tools enable personalized advertising campaigns on Facebook.
Facebook calls your behavior data on our website "event data." This is also used for measurement and analysis services. Thus, Facebook can, on our behalf, create "campaign reports" on the effectiveness of our advertising campaigns. In addition, through the analyses, we get a better understanding of how you use our services, website, or products. In this way, we optimize your user experience on our website with some of these tools. For example, with social plugins, you can share content from our page directly on Facebook.
What data is stored by Facebook tools?
Through the use of individual Facebook tools, personal data (customer data) can be sent to Facebook. Depending on the tools used, customer data such as name, address, phone number, and IP address may be sent.
Facebook uses this information to match the data with the data it already holds about you (insofar as you are a Facebook member). Before customer data is transmitted to Facebook, a "hashing" process is performed. This means that a randomly large set of data is converted into a string of characters. This also serves to encrypt the data.
In addition to contact data, "event data" is also transmitted. "Event data" refers to the information we receive about you on our website. For example, which subpages you visit or which products you buy from us. Facebook does not share the information received with third-party providers (e.g., advertisers) unless the company has explicit permission or is legally obliged. "Event data" can also be linked to contact data. This allows Facebook to offer better personalized advertising. After the already mentioned matching process, Facebook deletes the contact data again.
To optimize ad delivery, Facebook only uses event data when it is combined with other data (collected by Facebook in other ways). Facebook also uses this event data for security, protection, development, and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, a different number of cookies are placed in your browser. In the descriptions of the individual Facebook tools, we will go into more detail about the individual Facebook cookies. General information about the use of cookies on Facebook can also be found at https://www.facebook.com/policies/cookies.
How long and where is the data stored?
In principle, Facebook stores data until it is no longer necessary for Facebook's own services and products. Facebook has servers located worldwide where its data is stored. However, customer data is deleted within 48 hours after being matched with its own user data.
How can I delete my data or prevent data storage?
According to the General Data Protection Regulation, you have the right to access, correct, port, and delete your data.
Full data deletion only occurs if you completely delete your Facebook account. Here's how to delete your Facebook account:
1) Click on Settings on the right in Facebook.
2) Then click on "Your Facebook information" in the left column.
3) Now click on "Deactivation and deletion".
4) Now select "Delete Account" and then click on "Continue and Delete Account".
5) Now enter your password, click on "Continue" and then on "Delete Account".
The storage of data that Facebook receives through our page occurs, among other things, through cookies (e.g., with social plugins). In your browser, you can disable, delete, or manage individual or all cookies. Depending on which browser you use, this works differently. In the "Cookies" section, you will find the corresponding links to the instructions of the most popular browsers.
If you generally do not want cookies, you can set your browser to always inform you when a cookie is to be placed. This way you can decide for each individual cookie whether to allow it or not.
Legal Basis
If you have consented to your data being processed and stored through embedded Facebook tools, this consent is considered the legal basis for data processing (Art. 6 (1)(a) GDPR). In principle, your data is also stored and processed based on our legitimate interest (Art. 6 (1)(f) GDPR) in fast and good communication with you or with other clients and business partners. However, we only use the tools to the extent you have given consent. Most social media platforms also place cookies in your browser to store data. Therefore, we recommend that you carefully read our data protection text regarding cookies and review Facebook's privacy policy or cookie policy.
Facebook also processes your data in the USA, among other places. Facebook, or Meta Platforms, is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Facebook uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard Contractual Clauses (SCCs) are sample forms provided by the European Commission and aim to ensure that your data complies with European data protection standards even when it is transmitted and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and through the standard contractual clauses, Facebook undertakes to comply with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the corresponding standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
Facebook's data processing terms, which refer to the standard contractual clauses, can be found at https://www.facebook.com/legal/terms/dataprocessing.
We hope that we have been able to provide you with the most important information regarding the use and processing of data by Facebook tools. If you want to learn more about how Facebook uses your data, we recommend the data policies at https://www.facebook.com/privacy/policy/.
Instagram Privacy Policy
|
Summary of Instagram's Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: optimizing our service 📓 Processed data: data such as user behavior data, information about your device and your IP address. More details can be found below in the privacy policy. 📅 Storage period: until Instagram no longer needs the data for its purposes ⚖️ Legal bases: Art. 6 (1)(a) GDPR (consent), Art. 6 (1)(f) GDPR (legitimate interests) |
What is Instagram?
We have embedded Instagram functions on our website. Instagram is a social media platform of Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA. Since 2012, Instagram has been a subsidiary of Meta Platforms Inc. and is part of Facebook's products. Embedding content from Instagram on our website is called embedding. This way we can show you content such as buttons, photos or videos from Instagram directly on our website. When you open pages of our online presence that have an Instagram function integrated, data is transmitted, stored and processed by Instagram. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed within all Facebook companies.
Below we want to give you a more detailed insight into why Instagram collects data, what data it is about and how you can largely control data processing. Since Instagram belongs to Meta Platforms Inc., our information comes on the one hand from Instagram's policies, and on the other hand also from Meta's own data protection policies.
Instagram is one of the most famous social networks worldwide. Instagram combines the advantages of a blog with the advantages of audio-visual platforms such as YouTube or Vimeo. On "Insta" (as many users casually call the platform) you can upload photos and short videos, edit them with various filters and distribute them on other social networks. And if you don't want to be active yourself, you can simply follow other interesting users.
Why do we use Instagram on our website?
Instagram is the social media platform that has truly seen immense growth in recent years. And of course, we have also responded to this boom. We want you to feel as comfortable as possible on our website. Therefore, a diverse presentation of our content is natural for us. Through the embedded Instagram functions, we can enrich our content with useful, entertaining, or interesting content from the world of Instagram. Since Instagram is a subsidiary of Facebook, the collected data can also be useful for personalized advertising on Facebook. Thus, our ads reach only people who are truly interested in our products or services.
Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics and thus a better insight into your wishes and interests. It is important to note that these reports do not identify you personally.
What data does Instagram store?
When you land on one of our pages with embedded Instagram functions (such as Instagram photos or plugins), your browser automatically connects to Instagram's servers. Data is then sent, stored, and processed by Instagram. This happens regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases made, ads you see, and how you use our offerings. In addition, the date and time of your interaction with Instagram are also stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.
Facebook distinguishes between customer data and event data. We assume that this is exactly the case with Instagram. Customer data includes, for example, name, address, phone number, and IP address. This customer data is transmitted to Instagram only after it has been "hashed". Hashing means that a data set is converted into a series of characters. In this way, contact data can be encrypted. In addition, the aforementioned "event data" is also transmitted. By "event data", Facebook - and therefore Instagram - understands data about your user behavior. It can also happen that contact data is combined with event data. The collected contact data is matched with the data that Instagram already has about you.
Through small text files (cookies), usually placed in your browser, the collected data is transmitted to Facebook. Depending on the Instagram functions used and whether you yourself have an Instagram account, different amounts of data are stored.
We assume that data processing on Instagram works the same way as on Facebook. This means: if you have an Instagram account or have visited www.instagram.com, Instagram has placed at least one cookie. If so, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram function. At the latest after 90 days (after matching), this data is deleted or anonymized. Although we have extensively dealt with Instagram's data processing, we cannot say exactly what data Instagram collects and stores.
Below we show you the cookies that are at least placed in your browser when you click on an Instagram feature (such as a button or an Insta photo). In our test, we assume you do not have an Instagram account. If you are logged in to Instagram, of course, significantly more cookies are placed in your browser.
These cookies were used in our test:
Name: csrftoken
Value: ""
Purpose: This cookie is probably placed for security reasons to prevent request forgery. However, we could not determine this more precisely.
Expiration date: after one year
Name: mid
Value: ""
Purpose: Instagram places this cookie to optimize its own services and offers within and outside Instagram. The cookie determines a unique user ID.
Expiration date: after the session ends
Name: fbsr_113236968124024
Value: no data
Purpose: This cookie stores the login request for Instagram app users.
Expiration date: after the session ends
Name: rur
Value: ATN
Purpose: This is an Instagram cookie that ensures functionality on Instagram.
Expiration date: after the session ends
Name: urlgen
Value: "{ "194.96.75.33": 1901}:1iEtYv:Y833k2_UjKvXgYe113236968"
Purpose: This cookie serves Instagram's marketing purposes.
Expiration date: after the session ends
Note: We cannot claim this information to be complete. Which cookies are placed in a specific case depends on the integrated features and your use of Instagram.
How long and where is data stored?
Instagram shares the information it receives among Facebook companies, with external partners, and with people you connect with globally. Data processing is carried out in compliance with its own data policies. Your data is, among other things for security reasons, distributed across Facebook's servers worldwide. Most of these servers are located in the USA.
How can I delete my data or prevent data storage?
Thanks to the General Data Protection Regulation, you have the right to access, portability, rectification, and deletion of your data. You can manage your data in Instagram settings. If you want to permanently delete your data on Instagram, you must permanently delete your Instagram account.
Here's how to delete your Instagram account:
First, open the Instagram app. On your profile page, scroll down and click "Help Section". You will now reach the company's website. Click "Manage Account" on the website and then "Delete Your Account".
If you completely delete your account, Instagram deletes posts such as your photos and status updates. Information that other people have shared about you does not belong to your account and is therefore not deleted.
As mentioned above, Instagram primarily stores your data through cookies. You can manage, deactivate, or delete these cookies in your browser. Depending on your browser, management always works a little differently. In the "Cookies" section, you will find the relevant links to instructions for the most popular browsers.
In addition, you can generally set your browser so that you are always informed when a cookie needs to be placed. Then you can always individually decide whether you want to allow the cookie or not.
Legal Basis
If you have consented to your data being processed and stored through embedded social media elements, this consent is considered the legal basis for data processing (Art. 6 para. 1 lit. a GDPR). In principle, your data is also stored and processed based on our legitimate interest (Art. 6 para. 1 lit. f GDPR) in fast and good communication with you or with other customers and business partners. However, we only use embedded social media elements to the extent that you have given your consent. Most social media platforms also place cookies in your browser to store data. Therefore, we recommend that you carefully read our data protection text on cookies and review the privacy policy or cookie policy of the respective service provider.
Instagram also processes your data in the USA. Instagram, respectively Meta Platforms, is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Instagram uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and through the standard contractual clauses, Instagram undertakes to comply with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementation decision of the European Commission. The decision and the corresponding standard contractual clauses can be found, among other things, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
We have tried to provide you with the most important information regarding Instagram's data processing. You can find more detailed information about Instagram's data policies at https://privacycenter.instagram.com/policy/.
Introduction to Online Marketing
|
Summary of the Online Marketing Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: analysis of visitor information to optimize the online offering. 📓 Processed data: access statistics containing data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed. More details can be found with the respective online marketing tool used. 📅 Storage period: depends on the online marketing tools used ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is online marketing?
Online marketing refers to all measures carried out online to achieve marketing goals, such as increasing brand awareness or closing a deal. In addition, our online marketing measures aim to draw people's attention to our website. In order to present our offer to many interested people, we carry out online marketing. This usually involves online advertising, content marketing, or search engine optimization. To be able to implement online marketing effectively and targeted, personal data is also stored and processed. The data helps us, on the one hand, to display our content only to those people who are interested in it, and on the other hand, we can measure the success of our online marketing measures.
Why do we use online marketing tools?
We want to show our website to everyone who is interested in our offer. We are aware that this is not possible without consciously taken measures. Therefore, we carry out online marketing. There are various tools that make our work on our online marketing measures easier and also constantly offer suggestions for improvement through data. This allows us to target our campaigns more precisely to our target group. The goal of these used online marketing tools is ultimately the optimization of our offering.
What data is processed?
For our online marketing to function and for the success of the measures to be measurable, user profiles are created and data is stored, for example, in cookies (these are small text files). With the help of this data, we can not only display advertising in the classic sense but also present our content directly on our website in a way that is most pleasant for you. For this purpose, various tools from third-party providers exist that offer these functions and accordingly also collect and store your data. For example, the mentioned cookies store which websites you have visited on our page, how long you have viewed these pages, which links or buttons you click, or from which website you came to us. In addition, technical information can also be stored. For example, your IP address, which browser you use, from which device you visit our website, or the time you opened our website and when you left it again. If you have also agreed that we can determine your location, we can also store and process it.
Your IP address is stored in pseudonymized form (i.e. abbreviated). Unique data that directly identifies you as a person, such as name, address or email address, is also only stored in pseudonymized form within advertising and online marketing procedures. Therefore, we cannot identify you as a person, but only have the pseudonymized, stored information in the user profiles.
Cookies may, under certain circumstances, be used, analyzed and used for advertising purposes on other websites that use the same advertising tools. Data may then also be stored on the servers of the advertising tool providers.
In exceptional cases, unique data (names, email address, etc.) may also be stored in user profiles. Such storage occurs, for example, if you are a member of a social media channel that we use for our online marketing measures, and the network links already received data with the user profile.
With all advertising tools we use that store your data on their servers, we always receive only aggregated information, and never data that identifies you as an individual. The data only shows how well the applied advertising measures have worked. For example, we see which measures have prompted you or other users to come to our website and purchase a service or product there. Based on the analyses, we can improve our advertising offer in the future and adapt it even more precisely to the needs and wishes of interested parties.
Duration of data processing
We will inform you below about the duration of data processing, insofar as we have further information on the matter. In principle, we process personal data only as long as it is absolutely necessary for the provision of our services and products. Data stored in cookies is stored for different periods. Some cookies are deleted immediately after leaving the website, others can remain stored in your browser for several years. In the respective privacy policies of the individual providers, you will usually find precise information about the individual cookies used by the provider.
Right to object
You have the right and the possibility to withdraw your consent to the use of cookies, or third-party providers, at any time. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent the collection of data via cookies by managing, deactivating or deleting cookies in your browser. The legality of the processing until withdrawal remains unaffected.
Since cookies can generally be used with online marketing tools, we also recommend our general privacy policy on cookies. To understand exactly what data is stored and processed about you, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to the use of third-party providers, the legal basis for the corresponding data processing is this consent. This consent constitutes, in accordance with Art. 6 para. 1 lit. a GDPR (consent), the legal basis for the processing of personal data that may arise from collection through online marketing tools.
On our part, there is also a legitimate interest in measuring online marketing measures in anonymized form, so that we can optimize our offer and our measures with the help of the data obtained. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). However, we only use the tools to the extent that you have given your consent.
Information on specific online marketing tools can be found - if available - in the following sections.
Security and Anti-Spam
|
Summary of the Security and Anti-Spam Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: cybersecurity 📓 Processed data: data such as your IP address, name or technical data such as browser version More details can be found below and in the individual data protection texts. 📅 Storage period: generally, data is stored until it is no longer required for the provision of the service ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is security and anti-spam software?
With so-called security and anti-spam software, you, and we, can protect ourselves from various spam or phishing emails and possible other cyber attacks. Spam refers to unsolicited advertising emails sent in bulk. Such emails are also called junk mail and can also cause costs. Phishing emails, on the other hand, are messages that aim to build trust through fake messages or websites to gain access to personal data. Anti-spam software usually protects against unwanted spam messages or malicious emails that could, for example, introduce viruses into our system. We also use general firewalls and security systems that protect our computers from unwanted network attacks.
Why do we use security and anti-spam software?
We attach particular importance to the security of our website. After all, it's not just about our security, but above all about yours. Unfortunately, in the world of IT and the internet, cyber threats are now part of everyday life. Often, hackers try to steal personal data from an IT system through a cyberattack. Therefore, a good security system is absolutely necessary. A security system monitors all incoming and outgoing connections to our network, respectively computer. To achieve even greater security against cyberattacks, in addition to the standardized security systems on our computer, we also use additional external security services. This better prevents unauthorized data traffic and thus protects us from cybercrime.
What data is processed by security and spam protection software?
Exactly what data is collected and stored depends, of course, on the respective service. However, we always strive to use only programs that collect data very sparingly, or store only data necessary for the provision of the offered service. In principle, the service may store data such as name, address, IP address, email address, and technical data such as browser type or browser version. Possible performance data and logs may also be collected to identify potential incoming threats in a timely manner. This data is processed within the services and in compliance with applicable laws. This includes, even for American providers (through standard contractual clauses), the GDPR. These security services in some cases also work with third-party providers, who, at our instruction and in accordance with data protection regulations and additional security measures, may store and/or process data. Data storage is usually done through cookies.
Duration of data processing
We will inform you below about the duration of data processing, to the extent that we have additional information on the matter. For example, security programs store data until you or we withdraw the data storage. In principle, personal data is stored only as long as absolutely necessary for the provision of the services. In many cases, unfortunately, we lack precise information from providers regarding the duration of storage.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies, respectively third-party security software providers. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent the collection of data through cookies by managing, disabling, or deleting cookies in your browser.
Since cookies may also be used in such security services, we recommend our general privacy policy regarding cookies. To understand exactly what data is stored and processed for you, you should read the privacy policies of the respective tools.
Legal basis
We use security services primarily based on our legitimate interests (Art. 6 para. 1 lit. f GDPR) for a good security system against various cyberattacks.
Certain types of processing, in particular the use of cookies, as well as the use of security features, require your consent. If you have consented to your data being processed and stored through embedded security services, this consent is considered the legal basis for data processing (Art. 6 para. 1 lit. a GDPR). Most of the services we use place cookies in your browser to store data. Therefore, we recommend that you carefully read our data protection text regarding cookies and review the privacy policy, or cookie policy, of the respective service provider.
Information on specific tools can be found – to the extent available – in the following sections.
Introduction to Payment Service Providers
|
Summary of the Privacy Policy on Payment Service Providers
👥 Affected persons: website visitors 🤝 Purpose: facilitating and optimizing the payment process on our website 📓 Processed data: data such as name, address, bank details (account number, credit card number, passwords, TAN codes, etc.), IP address, and contract data More details can be found with the respectively used payment service provider tool. 📅 Storage period: depends on the payment service provider used ⚖️ Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance) |
What is a payment service provider?
We use online payment systems on our website that allow us and you a secure and smooth payment method. In this process, personal data can, among other things, be sent, stored, and processed with the respective payment service provider. Payment service providers are online payment systems that allow you to place an order via online banking. The payment processing is then handled by the payment service provider you choose. We then receive information about the successful payment. This method can be used by any user who has an active online banking account with a PIN and TAN code. There are hardly any banks left that do not offer or accept such payment methods.
Why do we use payment service providers on our website?
Of course, with our website and our integrated online store, we want to offer the best possible service so that you feel comfortable on our page and use our offers. We know that your time is valuable, and especially payment processes should function quickly and smoothly. For these reasons, we offer you various payment service providers. You can choose your preferred payment service provider and thus pay in your usual way.
What data is processed?
Exactly what data is processed depends, of course, on the respective payment service provider. However, data such as name, address, bank details (account number, credit card number, passwords, TAN codes, etc.) are generally stored. These are necessary data for a transaction to be carried out at all. In addition, possible contract data and user data, such as when you visit our website, what content you are interested in, or which subpages you click, may also be stored. Your IP address and information about the computer you use are also stored by most payment service providers.
The data is usually stored and processed on the servers of the payment service providers. We, as the website operators, do not receive this data. We are only informed whether the payment worked or not. For identity and creditworthiness checks, it may happen that payment service providers transmit data to the relevant authority. For all payment transactions, the business and data protection terms of the respective provider always apply. Therefore, please always review the general terms and conditions and the privacy policy of the payment service provider. You also have the right at any time, for example, to request the deletion or correction of data. Please contact the respective service provider regarding your rights (right of withdrawal, right of access, and data subject rights).
Duration of data processing
We will inform you below about the duration of data processing, to the extent that we have additional information on the matter. In principle, we only process personal data for as long as is absolutely necessary for the provision of our services and products. If, as in the case of accounting, this is legally prescribed, the storage period may be longer. For example, we store contract-related accounting documents (invoices, contract documents, account statements, etc.) for 10 years (§ 147 of the German Tax Code) and other relevant business documents for 6 years (§ 247 of the German Commercial Code) after their creation.
Right to object
You always have the right to access, correct, and delete your personal data. If you have questions, you can also contact the responsible persons of the payment service provider used at any time. Contact details can be found either in our specific privacy policy or on the website of the respective payment service provider.
Cookies used by payment service providers for their functions can be deleted, deactivated, or managed in your browser. Depending on which browser you use, this works differently. Please note, however, that the payment process may then no longer function.
Legal basis
Therefore, to fulfill contractual and legal relationships (Art. 6 para. 1 lit. b GDPR), we offer, in addition to traditional banking/credit institutions, other payment service providers. The privacy policies of the individual payment service providers (such as Amazon Payments, Apple Pay, or Discover) provide you with an exact overview of the processing and storage of data. In addition, you can always contact the responsible persons with questions regarding data protection.
Information on specific payment service providers can be found – to the extent available – in the following sections.
Google Pay Privacy Policy
We use the online payment service provider Google Pay on our website. The service provider is the American company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.
Google processes your data, among other things, in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCCs) are sample templates provided by the European Commission and aim to ensure that your data complies with European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the corresponding standard contractual clauses can be found, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data processing terms for Google advertising products (Google Ads Controller-Controller Data Protection Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/adscontrollerterms/.
You can learn more about the data processed through the use of Google Pay in the privacy policy at https://policies.google.com/privacy.
PayPal Privacy Policy
|
Summary of the PayPal Privacy Policy
👥 Affected persons: website visitors 🤝 Purpose: optimizing the payment process on our website 📓 Processed data: data such as name, address, bank details (account number, credit card number, passwords, TAN codes, etc.), IP address, and contract data may be processed. More details can be found below in this privacy policy. 📅 Storage period: data is generally stored until cooperation with PayPal is terminated ⚖️ Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance), Art. 6 para. 1 lit. a GDPR (consent) |
What is PayPal?
We use the online payment service PayPal on our website. The service provider is the American company PayPal Inc. For the European area, the company PayPal Europe (S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg) is responsible.
With PayPal, all users can send and receive money electronically. The company was founded in 1998 and is now one of the most well-known and largest providers of online payment services worldwide, with over 325 million active customers.
Why do we use PayPal for our website?
There are various reasons why we use and offer PayPal on our website. Since PayPal is one of the most well-known online payment providers, many of our website visitors also use and trust this service. PayPal also offers high security standards for digital money transfers. The service uses various encryption methods to protect your personal data as best as possible. We also appreciate the user-friendliness of PayPal and the possibility of international payments in various currencies. Transactions usually take place very quickly, which is an additional advantage for both us and you as customers.
What data is processed by PayPal?
PayPal distinguishes various categories of personal data in its privacy policy that can be processed through the use of the service. These include login and contact data, identification and signature data, payment information, information about imported contacts, data from your account profile, device data such as your IP address, location data, and so-called derived data. This refers to information that can be derived from transactions or other data. This could be, for example, purchasing habits, behavioral patterns, creditworthiness, or personal preferences.
In addition, there is also personal data collected by third parties (such as identity checkers, fraud detection service providers, or your bank). This data includes information from credit bureaus, transaction data, information regarding legal regulations, technical usage data, location data, and again, derived data.
PayPal, and its partners, also use tracking technologies such as cookies, pixel tags, web beacons, and widgets to recognize you as a user, customize content, and conduct analyses for interest-based advertising.
How long and where is the data stored?
In principle, PayPal stores data for as long as necessary to fulfill its obligations and within the scope of the purpose. Personal data necessary for the customer relationship is stored for up to 10 years after the termination of the relationship. If PayPal is subject to a legal obligation, the storage period for personal data corresponds to the applicable law (e.g., insolvency law). PayPal also stores personal data for as long as necessary if storage is advisable with regard to legal disputes.
Since PayPal is a globally operating company, the service also has data centers worldwide where your data can be stored. This means that your data may be stored on PayPal servers outside your country and outside the scope of the GDPR.
How can I delete my data, or prevent data storage?
You have the right to access, rectify, delete, and restrict the processing of your personal data at any time. You can also withdraw your consent to data processing at any time.
If you generally want to deactivate, delete, or manage cookies, you will find the corresponding links to the instructions for the most common browsers in the "Cookies" section.
Legal basis
We have a legitimate interest in integrating an external payment service with PayPal and thus making our offer more attractive and improving it technically and economically. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Please note that you can only use PayPal if you enter into a contractual relationship with PayPal. In this case, you may need to provide additional data protection and contractual declarations (e.g., consent).
PayPal processes your data, among other things, in the USA. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This can be associated with various risks for the lawfulness and security of data processing.
As a basis for data processing involving recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, and therefore particularly in the USA) or data transfers to those countries, PayPal uses so-called standard contractual clauses (= Article 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission, aiming to ensure that your data meets European data protection standards even when transferred to and stored in third countries (such as the USA). Through these clauses, PayPal commits to complying with European data protection levels when processing your data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find more information about standard contractual clauses and the data processed through PayPal in the privacy policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.
Introduction to Audio and Video
|
Summary of the Privacy Policy on Audio and Video
👥 Data subjects: website visitors 🤝 Purpose: optimization of our service 📓 Processed data: data such as contact details, user behavior data, information about your device, and your IP address may be stored. More details can be found below in the respective data protection texts. 📅 Storage period: data is generally retained as long as necessary for the purpose of the service ⚖️ Legal bases: Article 6(1)(a) GDPR (consent), Article 6(1)(f) GDPR (legitimate interests) |
What are audio and video elements?
We have embedded audio and video elements on our website so that you can watch videos or listen to music/podcasts directly through our website. The content is provided by service providers. All content is accordingly received from the respective servers of the providers.
These are embedded functional elements from platforms such as YouTube, Vimeo, or Spotify. The use of these portals is usually free, but paid content can also be published. With the help of these embedded elements, you can listen to or watch the respective content through our website.
When you use audio or video elements on our website, your personal data may also be transmitted, processed, and stored by the service providers.
Why do we use audio and video elements on our website?
Of course, we want to offer you the best possible service on our website. And we are aware that content is no longer conveyed only through text and static images. Instead of just providing you with a link to a video, we offer you audio and video formats directly on our website that are entertaining or informative, and ideally both. This expands our service and makes it easier for you to access interesting content. Thus, in addition to our texts and images, we also offer video and/or audio content.
What data is stored by audio and video elements?
When you open a page on our website that contains, for example, an embedded video, your server connects to the service provider's server. In doing so, your data is transmitted to the third-party provider and stored there. Some data is collected and stored completely independently of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system, and other general information about your end device. In addition, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which button you clicked on, or through which website you use the service. All this information is usually stored through cookies or pixel tags (also called web beacons). Pseudonymized data is usually stored in cookies in your browser. Which specific data is stored and processed, you will always find in the privacy policy of the respective provider.
Duration of data processing
How long exactly data is stored on the servers of third-party providers, you will find either below in the data protection text of the respective tool or in the privacy policy of the provider. In principle, personal data is processed only as long as it is absolutely necessary for the provision of our services or products. This also generally applies to third-party providers. You can usually assume that certain data is stored on the servers of third-party providers for several years. Data may be stored for different periods, especially in cookies. Some cookies are deleted immediately after leaving the website, others may remain stored in your browser for several years.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies, or third-party providers, respectively. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating, or deleting cookies in your browser. The lawfulness of processing until withdrawal remains unaffected.
Since embedded audio and video functions on our page typically also use cookies, you should also read our general privacy policy on cookies. In the privacy policies of the respective third-party providers, you will learn more about how your data is processed and stored.
Legal basis
If you have consented to your data being processed and stored through embedded audio and video elements, this consent is considered the legal basis for data processing (Article 6(1)(a) GDPR). In principle, your data is also stored and processed based on our legitimate interest (Article 6(1)(f) GDPR) in fast and good communication with you or with other clients and business partners. However, we use embedded audio and video elements only to the extent that you have given your consent.
YouTube Privacy Policy
|
Summary of the YouTube Privacy Policy
👥 Data subjects: website visitors 🤝 Purpose: optimization of our service 📓 Processed data: data such as contact details, user behavior data, information about your device, and your IP address may be stored. More details can be found below in this privacy policy. 📅 Storage period: data is generally retained as long as necessary for the purpose of the service ⚖️ Legal bases: Article 6(1)(a) GDPR (consent), Article 6(1)(f) GDPR (legitimate interests) |
What is YouTube?
We have embedded videos from YouTube on our website. This allows us to present interesting videos directly on our page. YouTube is a video portal, a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you open a page on our website with an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. Various data is transmitted in this process (depending on your settings). Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all data processing in the European area.
Below, we want to explain in more detail what data is processed, why we have embedded YouTube videos, and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on, and upload videos for free. In recent years, YouTube has become one of the most important social media channels worldwide. To display videos on our website, YouTube provides a code snippet that we have embedded on our page.
Why do we use YouTube videos on our website?
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our page. And of course, interesting videos cannot be missing from this. With the help of our embedded videos, we provide you, in addition to our texts and images, with additional useful content. In addition, our page is more easily found in Google's search engine thanks to embedded videos. Even when we place ads through Google Ads, Google - thanks to the collected data - can display these ads only to people who are genuinely interested in our offers.
What data does YouTube store?
As soon as you visit one of our pages with an embedded YouTube video, YouTube places at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually link your interactions on our page to your profile with the help of cookies. This includes data such as session duration, bounce rate, approximate location, technical information such as browser type, screen resolution, or your internet provider. Other data may include contact data, possible ratings, sharing content through social media, or adding to your favorites on YouTube.
If you are not logged into a Google account or a YouTube account, Google stores data with a unique identifier associated with your device, browser, or application. For example, your preferred language setting is saved. However, many interaction data cannot be stored because fewer cookies are placed.
In the following list, we show you cookies placed in a browser test. On the one hand, we show you cookies placed without logging into a YouTube account. On the other hand, we show you cookies placed with an account login. The list does not claim to be exhaustive, as user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y113236968-1
Purpose of use: This cookie registers a unique identifier to store statistics about watched videos.
Expiration date: After the end of the session
Name: PREF
Value: f1=50000000
Purpose of use: This cookie also registers your unique identifier. Through PREF, Google receives statistics on how you use YouTube videos on our page.
Expiration date: After 8 months
Name: GPS
Value: 1
Purpose of use: This cookie registers your unique identifier on mobile devices to track the GPS location.
Expiration date: After 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose of use: This cookie attempts to estimate the bandwidth of the user on our websites (with embedded YouTube video).
Expiration date: After 8 months
Other cookies placed if you are logged into your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7113236968-
Purpose of use: This cookie is used to create a profile of your interests. The data is used for personalized advertisements.
Expiration date: After 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose of use: The cookie stores the status of a user's consent to use various Google services. CONSENT also serves for security to verify users and protect user data from unauthorized attacks.
Expiration date: After 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose of use: This cookie is used to create a profile of your interests. This data helps to display personalized advertising.
Expiration date: After 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose of use: This cookie stores information about your login data.
Expiration date: After 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose of use: This cookie functions by uniquely identifying your browser and your device. It is used to create a profile of your interests.
Expiration date: After 2 years
Name: SID
Value: oQfNKjAsI113236968-
Purpose of use: This cookie stores your Google account ID and the last login time in a digitally signed and encrypted form.
Expiration date: After 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose of use: This cookie stores information on how you use the website and what advertising you may have seen before visiting our page.
Expiration date: After 3 months
How long and where is the data stored?
The data that YouTube receives and processes from you is stored on Google's servers. Most of these servers are located in America. You can see exactly where Google's data centers are located at https://datacenters.google/. Your data is distributed across the servers. This makes the data more quickly accessible and better protected from manipulation.
Google stores the collected data for various periods. Some data you can delete at any time, others are deleted automatically after a limited period, and still others are stored by Google for a longer period. Some data (such as items from "My Activity," photos or documents, products) stored in your Google account remains stored until you delete it. Even if you are not logged into a Google account, you can delete some data related to your device, browser, or application.
How can I delete my data or prevent data storage?
In principle, you can manually delete data in your Google account. With the automatic data deletion function for location and activity data introduced in 2019, information is stored - depending on your decision - for either 3 or 18 months, after which it is deleted.
Regardless of whether you have a Google account or not, you can configure your browser so that Google cookies are deleted or deactivated. Depending on which browser you use, this works differently. In the "Cookies" section, you will find the relevant links to instructions for the most well-known browsers.
If you generally do not want cookies, you can set your browser to always inform you when a cookie should be placed. This way, you can decide for each individual cookie whether to allow it or not.
Legal basis
If you have agreed for your data to be processed and stored through embedded YouTube elements, this consent is considered the legal basis for data processing (Art. 6, para. 1, letter "a" GDPR). In principle, your data is also stored and processed based on our legitimate interest (Art. 6, para. 1, letter "f" GDPR) in fast and good communication with you or other customers and business partners. However, we only use embedded YouTube elements if you have given your consent. YouTube also places cookies in your browser to store data. Therefore, we recommend that you carefully read our data protection text regarding cookies and review the privacy policy or cookie policy of the respective service provider.
YouTube processes your data, among other things, in the USA. YouTube, or Google, is an active participant in the EU-US Data Privacy Framework, which governs the proper and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46, para. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. You can find the decision and the relevant standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data processing terms for Google's advertising products (Google Ads Data Processing Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
Since YouTube is a subsidiary of Google, there is a common privacy policy. If you want to learn more about how your data is handled, we recommend Google's privacy policy at https://policies.google.com/privacy?hl=de.
Introduction to Web Design
|
Web Design Privacy Policy Summary
👥 Data Subjects: website visitors 🤝 Purpose: improving user experience 📓 Data Processed: which data is processed depends heavily on the services used. Typically, this includes IP address, technical data, language settings, browser version, screen resolution, and browser name. More details can be found under the respective web design tools used. 📅 Storage Period: depends on the tools used ⚖️ Legal Bases: Art. 6, para. 1, letter "a" GDPR (consent), Art. 6, para. 1, letter "f" GDPR (legitimate interests) |
What is web design?
We use various tools on our website for our web design. Web design, contrary to common assumption, is not just about making our website look beautiful, but also about functionality and performance. But of course, an appropriate appearance of a website is also one of the major goals of professional web design. Web design is a sub-area of media design and deals with both the visual and the structural and functional layout of a website. The goal is to improve your experience on our website with the help of web design. In web design jargon, this is referred to as user experience (UX) and usability. User experience refers to all impressions and experiences that a website visitor has on a given page. A sub-point of user experience is usability. This refers to the user-friendliness of the website. Here, special attention is paid to ensuring that content, subpages or products are clearly structured and that you can easily and quickly find what you are looking for. To offer you the best possible experience on our website, we also use so-called third-party web design tools. The category "web design" in this privacy policy therefore includes all services that improve the design of our website. These can be, for example, fonts, various plugins, or other embedded web design functions.
Why do we use web design tools?
How you perceive information on a website depends very heavily on the structure, functionality, and visual perception of the website. Therefore, good and professional web design has always been increasingly important to us. We are constantly working to improve our website and consider this an extended service for you as a website visitor. In addition, a beautiful and functional website also brings economic benefits for us. Ultimately, you will only visit us and use our offers if you feel completely comfortable.
What data is stored by web design tools?
When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data this entails, of course, depends heavily on the tools used. Below you will see exactly which tools we use for our website. For more information on data processing, we recommend that you also read the respective privacy policy of the tools used. There you will usually find out what data is processed, whether cookies are used, and how long the data is stored. Through fonts such as Google Fonts, information such as language settings, IP address, browser version, browser screen resolution, and browser name are automatically transmitted to Google's servers.
Duration of data processing
How long data is processed is very individual and depends on the web design elements used. If, for example, cookies are used, the storage period can be as short as one minute or as long as several years. Please inform yourself about this. For this purpose, we recommend our general text section on cookies, and also the privacy policies of the tools used. There you will usually find out exactly which cookies are used and what information is stored in them. Google font files, for example, are stored for one year. This is intended to improve the website's loading time. In principle, data is only stored for as long as necessary to provide the service. In the case of legal requirements, data may also be stored longer.
Right to object
You have the right and the possibility at any time to withdraw your consent to the use of cookies or third-party providers. This can be done either via our cookie management tool or via other opt-out functions. You can also prevent data collection via cookies by managing, deactivating, or deleting cookies in your browser. However, for web design elements (usually for fonts), there is also data that cannot be deleted so easily. This is the case when data is automatically collected directly when a page is opened and transmitted to a third-party provider (such as Google). In such a case, please contact the support of the respective provider. In the case of Google, you can contact support at https://support.google.com/?hl=de.
Legal basis
If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. This consent, in accordance with Art. 6, para. 1, letter "a" GDPR (consent), constitutes the legal basis for the processing of personal data that may arise from collection through web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can offer you a beautiful and professional online presence. The corresponding legal basis for this is Art. 6, para. 1, letter "f" GDPR (legitimate interests). However, we only use web design tools if you have given your consent. We definitely want to emphasize this again here.
Information on specific web design tools can be found – where available – in the following sections.
Introduction to Online Map Services
|
Summary of the Online Map Services Privacy Policy
👥 Data Subjects: website visitors 🤝 Purpose: improving user experience 📓 Data Processed: which data is processed depends heavily on the services used. Typically, this includes IP address, location data, search queries, and/or technical data. More details can be found under the respective tools used. 📅 Storage Period: depends on the tools used ⚖️ Legal Bases: Art. 6, para. 1, letter "a" GDPR (consent), Art. 6, para. 1, letter "f" GDPR (legitimate interests) |
What are online map services?
We also use online map services on our website as an extended service. Google Maps is probably the service most familiar to you, but there are also other providers specializing in the creation of digital maps. Such services allow the display of locations, route plans, or other geographical information directly through our website. Through an embedded map service, you no longer have to leave our website to view, for example, the route to a location. For the online map to function on our website, map excerpts are embedded via HTML code. The services can then display road maps, the earth's surface, or aerial/satellite images. When you use the embedded map offer, data is also transmitted to the tool used and stored there. This data may also include personal data.
Why do we use online map services on our website?
Generally speaking, our desire is to offer you a pleasant time on our website. And your time is, of course, only pleasant if you can easily navigate our website and quickly and easily find all the information you need. That's why we decided that an online map system could be a significant improvement to our website service. Without leaving our website, you can seamlessly view route directions, locations, or even sights using the map system. It is also very practical, of course, that this way you can see at a glance where our headquarters are located, so you can find us quickly and safely. As you can see, there are simply many advantages, and we clearly see online map services on our website as part of our customer service.
What data is stored by online map services?
When you open a page on our website with an embedded online map function, personal data may be transmitted to the respective service and stored there. This usually involves your IP address, through which your approximate location can also be determined. In addition to the IP address, data such as entered search terms, as well as longitude and latitude coordinates, are also stored. If, for example, you enter an address for route planning, this data is also stored. The data is not stored with us, but on the servers of the embedded tools. You can imagine it roughly like this: you are on our website, but when you interact with a map service, this interaction actually takes place on their website. For the service to function flawlessly, at least one cookie is usually also placed in your browser. Google Maps, for example, uses cookies to record user behavior and thus optimize its own service and display personalized advertising. You can learn more about cookies in our "Cookies" section.
How long and where is the data stored?
Each online map service processes different user data. To the extent that we have additional information, we will inform you about the duration of data processing below in the respective sections for individual tools. In principle, personal data is only stored for as long as necessary to provide the service. Google Maps, for example, stores certain data for a specific period, while other data you must delete yourself. For Mapbox, for example, the IP address is stored for 30 days and then deleted. As you can see, each tool stores data for a different period. Therefore, we recommend that you carefully review the privacy policies of the tools used.
Providers also use cookies to store data about your usage behavior on the map service. More general information about cookies can be found in our "Cookies" section, but you will also learn which cookies can be used in the data protection texts of the individual providers. However, this is usually only an exemplary list, which is not exhaustive.
Right to object
You always have the option and the right to access your personal data, and also to object to its use and processing. You can also withdraw any consent you have given us at any time. This usually works most easily through the cookie consent tool. However, there are also additional opt-out tools that you can use. You can also manage, delete, or deactivate possible cookies placed by the providers used with a few clicks of the mouse. However, it may then happen that some functions of the service no longer work as usual. How you manage cookies in your browser also depends on the browser you use. In the "Cookies" section, you will also find links to the instructions for the most important browsers.
Legal basis
If you have consented to the use of an online map service, the legal basis for the corresponding data processing is this consent. This consent, in accordance with Art. 6, para. 1, letter "a" GDPR (consent), constitutes the legal basis for the processing of personal data that may arise from collection through an online map service.
Furthermore, we have a legitimate interest in using an online map service to optimize our service on our website. The corresponding legal basis for this is Art. 6, para. 1, letter "f" GDPR (legitimate interests). However, we always use an online map service only if you have given your consent. We want to emphasize this again at this point.
Information on specific online map services can be found – where available – in the following sections.
Google Maps Privacy Policy
|
Google Maps Privacy Policy Summary
👥 Data Subjects: website visitors 🤝 Purpose: optimizing our service 📓 Data Processed: data such as entered search terms, your IP address, and also latitude and longitude coordinates. More details can be found below in this privacy policy. 📅 Storage Period: depends on the stored data ⚖️ Legal Bases: Art. 6, para. 1, letter "a" GDPR (consent), Art. 6, para. 1, letter "f" GDPR (legitimate interests) |
What is Google Maps?
We use Google Maps from Google Inc. on our website. For the European area, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Maps, we can better show you locations and thus adapt our service to your needs. Through the use of Google Maps, data is transmitted to Google and stored on Google's servers. Here we want to go into more detail about what Google Maps is, why we use this Google service, what data is stored, and how you can prevent this.
Google Maps is an internet map service from Google. With Google Maps, you can search for exact locations of cities, sights, accommodations, or businesses online via computer, tablet, or app. If businesses are listed in Google My Business, additional information about the company is displayed in addition to the location. To show the possibility of navigation, map excerpts of a location can be embedded on a website via HTML code. Google Maps displays the earth's surface as a road map or as an aerial or satellite image. Thanks to Street View images and high-quality satellite images, very precise images are possible.
Why do we use Google Maps on our website?
All our efforts on this page are aimed at offering you a useful and meaningful experience on our site. By embedding Google Maps, we can provide you with the most important information about various locations. At a glance, you can see where our headquarters is located. The route planner always shows you the best and fastest way to reach us. You can get directions for driving, public transport, walking, or cycling. For us, providing Google Maps is part of our customer service.
What data does Google Maps store?
For Google Maps to provide its service fully, the company must collect and store your data. This includes, among other things, entered search terms, your IP address, and also latitude and longitude coordinates. If you use the route planning function, the entered starting address is also stored. However, this data storage occurs on Google Maps' websites. We can only inform you about this but cannot influence it. Since we have embedded Google Maps on our website, Google places at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google primarily uses this data to optimize its own services and to provide you with individual, personalized advertising.
The following cookie is placed in your browser due to the integration of Google Maps:
Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ113236968-5
Purpose: NID is used by Google to tailor ads to your Google search. With the help of the cookie, Google "remembers" your most frequently entered search queries or your previous interaction with ads. This way, you always receive individually tailored ads. The cookie contains a unique identifier that Google uses to collect your personal settings for advertising purposes.
Expiration date: after 6 months
Note: We cannot guarantee the completeness of the data stored. Especially with the use of cookies, changes can never be ruled out. To identify the NID cookie, a separate test page was created where only Google Maps is embedded.
How long and where is the data stored?
Google's servers are located in data centers around the world. However, most servers are located in America. For this reason, your data is primarily stored in the USA. Here you can read exactly where Google's data centers are located: https://datacenters.google/
Google distributes data across various data carriers. This makes the data more quickly accessible and better protected from potential manipulation attempts. Each data center also has special emergency programs. If, for example, problems arise with Google's hardware or a natural disaster takes out servers, the data remains relatively securely protected.
Some data Google stores for a certain period. For other data, Google only offers the option of manual deletion. In addition, the company also anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months, respectively.
How can I delete my data or prevent data storage?
With the automatic deletion function for location and activity data introduced in 2019, location data and web/app activity are stored – depending on your decision – for either 3 or 18 months, after which they are deleted. In addition, this data can be manually deleted from history at any time via your Google account. If you want to completely prevent location tracking, you must pause the "Web & App Activity" section in your Google account. Click on "Data & personalization" and then on the "Activity controls" option. Here you can enable or disable activities.
In your browser, you can also disable, delete, or manage individual cookies. Depending on which browser you use, this always works a little differently. In the "Cookies" section, you will find the relevant links to instructions for the most popular browsers.
If you generally do not want cookies, you can set your browser to always inform you when a cookie is to be placed. This way, you can decide for each individual cookie whether to allow it or not.
Legal basis
If you have consented to the use of Google Maps, the legal basis for the corresponding data processing is this consent. This consent constitutes, in accordance with Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data that may arise from collection by Google Maps.
We also have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Google Maps insofar as you have given your consent.
Google also processes your data in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard Contractual Clauses (SCCs) are sample templates provided by the European Commission and aim to ensure that your data meets European data protection standards even when transferred and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even when the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. You can find the decision and the relevant standard contractual clauses, among others, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data processing terms for Google's advertising products (Google Ads Data Processing Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
If you want to learn more about Google's data processing, we recommend the company's own privacy policy at https://policies.google.com/privacy?hl=de.
Explanation of terms used
We always strive to make our privacy policy as clear and understandable as possible. However, especially with technical and legal topics, this is not always entirely easy. It often makes sense to use legal terms (such as personal data) or specific technical expressions (such as cookies, IP address). However, we would not want to use them without explanation. Below you will find an alphabetical list of important terms used that we may not have paid enough attention to in the previous privacy policy. If these terms are derived from the GDPR and refer to definitions, we will also indicate the GDPR texts here and, if necessary, add our own explanations.
Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process about you. In addition to controllers, there can also be so-called processors. This includes any company or person who processes personal data on our behalf. Processors can therefore be, in addition to service providers such as tax consultants, for example, hosting or cloud service providers, payment service providers or newsletter services, or large companies such as Google or Microsoft.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
Explanation: Typically, on websites, such consent is obtained through a cookie consent tool. You are probably familiar with it. Every time you visit a website for the first time, you are usually asked via a banner whether you agree or consent to data processing. You can usually also configure it individually and thus decide for yourself which data processing you allow and which you do not. If you do not give your consent, your personal data cannot be processed either. In principle, consent can, of course, also be given in writing, i.e., not through a tool.
Personal Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data are therefore all data that can identify you as a person. These are usually data such as:
According to the European Court of Justice (ECJ), your IP address also counts as personal data. IT experts can determine at least the approximate location of your device and subsequently you as the connection holder based on your IP address. Therefore, storing an IP address also requires a legal basis in the sense of the GDPR. There are also so-called “special categories” of personal data that are particularly sensitive and deserve special protection. These include:
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“profiling” means any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
Explanation: Profiling involves collecting various information about a person to learn more about that person. In the web area, profiling is often used for advertising purposes or for credit checks. Web or advertising analysis programs, for example, collect data about your behavior and your interests on a website. This results in a special user profile, with the help of which advertising can be specifically displayed to a certain target group.
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and are therefore the "controller." When we transmit collected data for processing to other service providers, they are "processors." For this purpose, a "data processing agreement (DPA)" must be signed.
Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Note: When we talk about processing in our privacy policy, we mean any kind of data processing. This includes, as mentioned above in the original GDPR definition, not only the collection but also the storage and processing of data.
Concluding remarks
Congratulations! If you are reading these lines, you have really "fought" your way through our entire privacy policy, or at least scrolled this far. As you can see from the volume of our privacy policy, we do not take the protection of your personal data lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we want not only to tell you which data is processed but also to explain the reasons for using various software programs. Privacy policies usually sound very technical and legal. Since most of you are not web developers or lawyers, we wanted to take a different linguistic approach and explain the situation in simple and clear language. Of course, this is not always possible due to the subject matter itself. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible authority. We wish you a pleasant stay and hope to welcome you back to our website soon.
All texts are copyrighted.
Source: Privacy Policy created with the AdSimple Data Protection Generator for Austria (translated into Bulgarian)