Data protection

Privacy Policy

Table of Contents

Introduction and overview

We have prepared this Privacy Policy (version 14 February 2024–322726102) in order to inform you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws which personal data (hereinafter referred to as “data”) we, as the controller, and the processors commissioned by us, such as hosting providers, process or will process in the future, as well as the lawful options available to you. The terms used are intended to be gender-neutral.
In brief: We provide you with comprehensive information about the data we process about you.

Privacy policies usually sound very technical and use legal terminology. This Privacy Policy, however, is intended to explain the most important points to you as simply and transparently as possible. Where this helps improve transparency, technical technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. In this way, we clearly and simply explain that, as part of our business activities, we process personal data only where there is an appropriate legal basis. This would certainly not be possible if we provided explanations that were as brief, unclear, and legally or technically complex as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative and perhaps discover one or two things you did not already know.
If you still have any questions, please contact the responsible party named below or in the legal notice, follow the available links, and consult additional information on third-party websites. Our contact details can, of course, also be found in the legal notice.

Scope of application

This Privacy Policy applies to all personal data processed by us within our company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and postal address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:

  • all online presences (websites and online shops) operated by us
  • Social media presences and email communication
  • mobile apps for smartphones and other devices

In brief: This Privacy Policy applies to all areas in which personal data is processed in a structured manner within the company through the channels mentioned above. Should we enter into a legal relationship with you outside these channels, we will provide you with separate information where necessary.

Legal basis

In the following Privacy Policy, we provide you with transparent information about the legal principles and provisions—in other words, the legal bases under the General Data Protection Regulation—that allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, access the EU General Data Protection Regulation online via EUR-Lex, the official gateway to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex32016R0679 read.

We process your data only if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. One example would be storing the information you enter into a contact form.
  2. Contract (Article 6(1)(b) GDPR): We process your data in order to perform a contract with you or to take steps at your request before entering into a contract. For example, if we conclude a purchase agreement with you, we require certain personal information in advance.
  3. Legal obligation (Article 6(1)(c) GDPR): We process your data where we are subject to a legal obligation. For example, we are legally required to retain invoices for accounting purposes. These generally contain personal data.
  4. Legitimate interests (Article 6(1)(f) GDPR): Where we have legitimate interests that do not override your fundamental rights and freedoms, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing therefore constitutes a legitimate interest.

Other conditions, such as performing tasks in the public interest, exercising official authority, or protecting vital interests, generally do not apply to us. If such a legal basis should nevertheless be relevant, it will be indicated at the appropriate point.

In addition to the EU Regulation, national laws also apply:

  • In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated as DSG.
  • In Germany applies Bundesdatenschutzgesetz, abbreviated as BDSG.

If any additional regional or national laws apply, we will inform you about them in the following sections.

Contact details of the data controller

If you have any questions about data protection or the processing of personal data, you will find the contact details of the responsible person or entity below:
Dominik Ullrich
Aschenhof 24A, 97525 Schwebheim, Deutschland

E-Mail: info@dnd-apartments.com
Telefon: +4915140771554
Impressum: https://stay-in-wuerzburg.com/impressum

Storage period

As a general rule, we store personal data only for as long as is absolutely necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally required to retain certain data even after the original purpose no longer applies, for example for accounting purposes.

Should you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided that there is no legal obligation to retain it.

We provide more detailed information about the specific duration of each type of data processing below, where such information is available.

Rights under the General Data Protection Regulation

In accordance with Articles 13 and 14 of the GDPR, we inform you of the following rights to which you are entitled in order to ensure fair and transparent data processing:

  • Under Article 15 of the GDPR, you have the right to obtain information as to whether we process any of your data. If this is the case, you have the right to receive a copy of the data and to obtain the following information:
    • for what purpose we carry out the processing;
    • the categories, meaning the types of data that are processed;
    • who receives this data and, if the data is transferred to third countries, how its security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure or restriction of processing, as well as the right to object to processing;
    • that you have the right to lodge a complaint with a supervisory authority (links to these authorities can be found below);
    • the source of the data if we did not collect it directly from you;
    • whether profiling is carried out, meaning whether data is automatically evaluated in order to create a personal profile of you.
  • Under Article 16 of the GDPR, you have the right to rectification of your data, which means that we must correct it if you identify any errors.
  • Under Article 17 of the GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
  • Under Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data and may no longer use it for other purposes.
  • Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we must provide your data to you in a commonly used format.
  • Under Article 21 of the GDPR, you have the right to object, which, if exercised, will result in a change to the processing.
    • If the processing of your data is based on Article 6(1)(e) (public interest or the exercise of official authority) or Article 6(1)(f) (legitimate interests), you may object to the processing. We will then examine as quickly as possible whether we are legally able to comply with your objection.
    • If data is used for direct marketing purposes, you may object to this type of data processing at any time. After that, we may no longer use your data for direct marketing.
    • If data is used for profiling, you may object to this type of data processing at any time. After that, we may no longer use your data for profiling.
  • Under Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing, such as profiling.
  • Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may contact a data protection supervisory authority at any time if you believe that the processing of personal data infringes the GDPR.

In brief: You have rights—please do not hesitate to contact the responsible person or entity listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/?tid=322726102 find. In Germany, each federal state has its own data protection authority. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) The following local data protection authority is responsible for our company:

Bavarian Data Protection Authority

State Commissioner for Data Protection: Prof. Dr. Thomas Petri
Address: Wagmüllerstr. 18, 80538 Munich
Phone number: 089/21 26 72-0
Email address: poststelle@datenschutz-bayern.de
Website: https://www.datenschutz-bayern.de/

Data processing security

To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as reasonably possible for third parties to draw conclusions about personal information from our data.

Article 25 of the GDPR refers to this as “data protection by design and by default.” This means that security must always be considered for both software, such as forms, and hardware, such as access to server rooms, and that appropriate measures must be implemented. Where necessary, we will explain specific measures in more detail below.

TLS encryption with HTTPS

TLS, encryption and HTTPS sound very technical—and they are. We use HTTPS (Hypertext Transfer Protocol Secure, meaning “secure hypertext transfer protocol”) to transmit data securely over the internet and protect it from interception.
This means that the entire transmission of all data from your browser to our web server is secured—no one can “listen in.”

In doing so, we have introduced an additional layer of security and comply with data protection by design (Artikel 25 Absatz 1 DSGVO). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the internet, we can ensure the protection of confidential data.
You can recognise the use of this secure data transmission by the small padlock symbol at the top left of your browser, to the left of the internet address (e.g. examplepage.com), and by the use of https instead of http as part of our internet address.
If you would like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links with further information.

Communication

Communication Summary
👥 Data subjects: Everyone who communicates with us by telephone, email or online form
📓 Data processed: e.g. telephone number, name, email address, entered form data. You can find more details about this under the respective type of contact used.
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Storage period: Duration of the business relationship and the statutory requirements.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)

If you contact us and communicate with us by telephone, email or online form, personal data may be processed.

The data is processed in order to handle and process your enquiry and the associated business transaction. The data will be stored for as long as necessary or for as long as required by law.

Data subjects

All persons who contact us through the communication channels we provide are affected by the processes mentioned above.

Telephone

When you call us, the call data is stored in pseudonymised form on the respective device and by the telecommunications provider used. In addition, data such as your name and telephone number may subsequently be sent by email and stored for the purpose of responding to your enquiry. The data will be deleted as soon as the business transaction has been completed and the legal requirements allow it.

Email

If you communicate with us by email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and data is also stored on the email server. The data will be deleted as soon as the business transaction has been completed and the legal requirements allow it.

Online forms

If you communicate with us using an online form, data will be stored on our web server and may be forwarded to one of our email addresses. The data will be deleted as soon as the business transaction has been completed and the legal requirements allow it.

Legal basis

The processing of the data is based on the following legal bases:

  • Art. 6(1)(a) GDPR (consent): You give us your consent to store your data and continue to use it for purposes relating to the business transaction;
  • Art. 6(1)(b) GDPR (contract): Processing is necessary for the performance of a contract with you or with a processor, such as a telephone provider, or we need to process the data for pre-contractual activities, such as preparing an offer;
  • Art. 6(1)(f) GDPR (legitimate interests): We aim to handle customer enquiries and business communication in a professional manner. Certain technical facilities, such as email programs, Exchange servers and mobile network operators, are necessary in order to conduct communication efficiently.

Data Processing Agreement

In this section, we would like to explain what a Data Processing Agreement is and why it is required. Because the term “Data Processing Agreement” is quite a mouthful, we will also frequently use the acronym DPA in this text. Like most companies, we do not work alone, but also make use of services provided by other companies or individuals. By involving various companies or service providers, we may pass on personal data for processing. These partners then act as processors with whom we conclude a contract, the so-called Data Processing Agreement (DPA). The most important thing for you to know is that your personal data is processed exclusively in accordance with our instructions and must be governed by the DPA.

Who are data processors?

As a company and website owner, we are responsible for all data that we process about you. In addition to controllers, there may also be so-called processors. This includes any company or person that processes personal data on our behalf. More precisely, and according to the definition in the GDPR, any natural or legal person, public authority, agency or other body that processes personal data on our behalf is considered a processor. Processors may therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

For a better understanding of the terminology, here is an overview of the three roles under the GDPR:

Data subject (you as a customer or interested party) → Controller (we as the company and contracting party) → Processor (service providers such as web hosts or cloud providers)

Content of a Data Processing Agreement

As mentioned above, we have concluded a DPA with our partners who act as processors. Above all, it stipulates that the processor processes the data to be handled exclusively in accordance with the GDPR. The contract must be concluded in writing; however, in this context, electronic conclusion of the contract is also considered “in writing.” Personal data is processed only on the basis of this contract. The contract must contain the following:

  • Binding to us as the controller
  • Obligations and rights of the controller
  • Categories of data subjects
  • Type of personal data
  • Nature and purpose of the data processing
  • Subject matter and duration of the data processing
  • Place of data processing

Furthermore, the agreement contains all obligations of the processor. The most important obligations are:

  • to ensure measures for data security
  • to implement appropriate technical and organisational measures to protect the rights of the data subject
  • to maintain a record of data processing activities
  • to cooperate with the data protection supervisory authority upon request
  • to carry out a risk analysis regarding the personal data received
  • Sub-processors may only be engaged with the written authorisation of the controller.

You can see what such a DPA looks like in practice, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html view. A sample contract is presented here.

Customer data

Customer Data Summary
👥 Data subjects: Customers or business and contractual partners
🤝 Purpose: Provision of the contractually or pre-contractually agreed services, including related communication
📓 Data processed: Name, address, contact details, email address, telephone number, payment information (such as invoices and bank details), contract data (such as the term and subject matter of the contract), IP address, order data
📅 Storage period: The data will be deleted as soon as it is no longer required for the fulfilment of our business purposes and there is no statutory retention obligation.
⚖️ Legal bases: Legitimate interests (Art. 6(1)(f) GDPR), contract (Art. 6(1)(b) GDPR)

What is customer data?

In order to provide our services or contractual services, we also process data relating to our customers and business partners. This data always includes personal data. Customer data refers to all information processed on the basis of a contractual or pre-contractual relationship in order to provide the services offered. Customer data therefore includes all information that we collect and process about our customers.

Why do we process customer data?

There are many reasons why we collect and process customer data. The most important is that we simply need various types of data in order to provide our services. Sometimes your email address alone is sufficient, but if you purchase a product or service, for example, we also need data such as your name, address, bank details or contract data. We also use the data for marketing and sales optimisation so that we can improve our overall service for our customers. Another important aspect is our customer service, which is always very important to us. We want you to be able to contact us at any time with questions about our offers, and for this we need at least your email address.

What data is processed?

The exact data stored can only be described in terms of categories at this point. This is because it always depends on which services you obtain from us. In some cases, you only provide us with your email address so that, for example, we can contact you or answer your questions. In other cases, you purchase a product or service from us, and for this we need significantly more information, such as your contact details, payment data and contract data.

Here is a list of possible data that we receive from you and process:

  • name
  • Contact address
  • Email address
  • Telephone number
  • Date of birth
  • Payment data (invoices, bank details, payment history, etc.)
  • Contract data (duration, content)
  • Usage data (visited websites, access data, etc.)
  • Metadata (IP address, device information)

How long will the data be stored?

As soon as we no longer need the customer data to fulfill our contractual obligations and purposes, and the data is also not required for potential warranty and liability obligations, we delete the corresponding customer data. This is the case, for example, when a business contract ends. After that, the limitation period is generally 3 years, although longer periods are possible in individual cases. We naturally also comply with statutory retention obligations. Your customer data will certainly not be passed on to third parties unless you have explicitly given your consent to do so.

Legal basis

The legal bases for the processing of your data are Article 6(1)(a) of the GDPR (consent), Article 6(1)(b) of the GDPR (contract or precontractual measures), Article 6(1)(f) of the GDPR (legitimate interests), and in specific cases (e.g., medical services), Article 9(2)(a) of the GDPR (processing of special categories of data).

In the event of the protection of vital interests, data processing is carried out in accordance with Art. 9 Para. 2 lit. c GDPR. For the purposes of healthcare, occupational medicine, medical diagnostics, care or treatment in the health or social sector, or for the management of systems and services in the health or social sector, the processing of personal data is carried out in accordance with Art. 9 Para. 2 lit. h GDPR. If you voluntarily provide data of special categories, the processing is based on Art. 9 Para. 2 lit. a GDPR.

Introduction to web hosting

Web Hosting Summary
👥 Data subjects: Website visitors
🤝 Purpose: Professional website hosting and ensuring smooth operation
📓 Data Processed: IP address, time of website visit, browser used, and other data. For more details, please see below or contact the respective web hosting provider.
📅 Storage period: dependent on the respective provider, but usually 2 weeks
⚖️ Legal basis: Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is web hosting?

When you visit websites these days, certain information—including personal data—is automatically generated and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only for valid reasons. By the way, by “website” we mean the entirety of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By “domain” we mean, for example, example.de or sampleexample.com.

If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser for this. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We call them browsers or web browsers for short.

To display a website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why it’s usually handled by professional providers. They offer web hosting and thus ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!

When your browser establishes a connection on your computer (desktop, laptop, tablet, or smartphone) and during the transfer of data to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.

A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the internet, and the hosting provider.

Why do we process personal data?

The purposes of data processing are:

  1. Professional website hosting and operational security
  2. to maintain operational and IT security
  3. Anonymous analysis of access behavior to improve our services and, where applicable, for law enforcement or the pursuit of claims

What data is processed?

Even as you are visiting our website right now, our web server—that is, the computer on which this website is hosted—typically automatically stores data such as

  • the complete web address (URL) of the website visited
  • Browser and browser version (e.g., Chrome 87)
  • the operating system used (e.g., Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
  • the hostname and IP address of the device from which the access is made (e.g. COMPUTERNAME and 194.23.43.121)
  • Date and Time
  • in files known as web server log files

How long is data stored?

As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that government authorities may access this data in the event of unlawful conduct.

In brief: Your visit is logged by our provider (the company that hosts our website on special computers [servers]), but we will not share your information without your consent!

Legal basis

The lawfulness of processing personal data in the context of web hosting is based on Art. 6 (1) (f) GDPR (safeguarding of legitimate interests), because the use of professional hosting with a provider is necessary in order to present the company securely and user-friendly on the internet and, if necessary, to pursue attacks and claims arising therefrom.

Usually, there is a data processing agreement pursuant to Art. 28 et seq. GDPR in place between us and the hosting provider, which ensures compliance with data protection and guarantees data security.

1&1 IONOS Web Hosting Privacy Policy

1&1 IONOS Web Hosting Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Website storage and accessibility on the Internet
📓 Data processed: IP address, but primarily technical data
📅 Storage period: Visitor data is deleted after 8 weeks
⚖️ Legal bases: Art. 6 (1) (f) GDPR (Legitimate Interests)

What is 1&1 IONOS Web Hosting?

To host our website, we use the web hosting services of the company IONOS by 1&1. In Germany, 1&1 IONOS SE is located at Elgendorfer Str. 57, 56410 Montabaur. In Austria, you can find 1&1 IONOS SE at Gumpendorfer Straße 142/PF 266, 1060 Vienna.

IONOS offers the following web hosting services: domains, website & shop, hosting & WordPress, marketing, email & office, IONOS Cloud, and servers. With over 22 million domains, nearly 9 million customer contracts, and 100,000 servers, IONOS is one of the leading German top dogs in the web hosting sector.
We already mentioned this in our introductory remarks on the subject of web hosting: hosting also results in data from you or your end device being stored on the IONOS servers. Above all, your IP address, which is known to be personal data, is stored. In addition, technical data such as the URL of our website, the name of your internet browser, or the operating system you are using are also stored.

Why do we use 1&1 IONOS web hosting?

IONOS was founded in Germany back in 1988, which means it has over 30 years of experience under its belt. However, that doesn't mean the company hasn't constantly evolved in terms of technology. In our view, precisely this combination of experience and a spirit of innovation provides a great foundation for our website. After all, we want our website to run smoothly 24 hours a day while ensuring a high level of security. Since IONOS does not limit monthly traffic and provides plenty of storage space, our website remains high-performing even with a large number of visitors. We are very satisfied with the speed of the website, and the price-performance ratio currently fits our requirements.

What data is processed by 1&1 IONOS Webhosting?

1&1 IONOS web hosting may also process personal data from you. When you visit our website, the following data from you or your computer is stored by IONOS:

  • the previously visited website (also known as referrer)
  • the requested website (in this case, our website)
  • Browser type and browser version
  • Your operating system and device type
  • Time of page access
  • Your IP address in anonymized form

The collected data is used to increase the security of the website, detect potential errors, and also to perform anonymous statistical analyses. According to IONOS, the anonymized IP address is used only to determine the location of the access.

How long and where is the data stored?

The data is stored on IONOS's own servers. Generally, IONOS stores the data for as long as necessary to fulfill its obligations. Visitor data is stored for 8 weeks. However, it may also happen that data is stored for a longer period, for example, to have evidence for potential legal disputes. Visitor data is not passed on to third parties, nor is it transferred to a country outside the EU.

How can I delete my data or prevent data from being stored?

You have the right at any time to information, correction, or deletion and restriction of the processing of your personal data. You can also revoke your consent to the processing of data at any time.

If you generally wish to deactivate, delete, or manage cookies, you will find the corresponding links to the respective instructions for the most popular browsers under the „Cookies“ section.

Legal basis

We have a legitimate interest in using IONOS to be able to offer our online service. Professional hosting by a provider is necessary in order to present our company securely and user-friendly on the internet and to be able to track potential cyber attacks. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests).

You can find much more information about data protection at IONOS in the privacy policy at https://www.ionos.de/terms-gtc/datenschutzerklaerung/. If you have any further questions about data protection, you can also contact the IONOS data protection team by email at datenschutz@ionos.de contact.

Data Processing Agreement (DPA) IONOS

We have concluded a data processing agreement (DPA) with IONOS pursuant to Article 28 of the General Data Protection Regulation (GDPR). You can read about what a DPA is precisely and, above all, what must be included in a DPA in our general section „Data Processing Agreement (DPA)“.

This contract is legally required because IONOS processes personal data on our behalf. It clarifies that IONOS may only process data received from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) under https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/auftragsverarbeitung/.

Introduction to website builder systems

Website Builder Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Processed Data: Data such as technical usage information like browser activity, clickstream activity, session heatmaps, and contact details, IP address, or your geographic location. You can find more details about this further down in this privacy policy and in the providers' privacy policies.
📅 Retention period: depends on the provider
⚖️ Legal bases: Art. 6 para. 1 lit. f GDPR (Legitimate interests), Art. 6 para. 1 lit. a GDPR (Consent)

What are website builder systems?

We use a website builder system for our website. Website builder systems are special forms of a content management system (CMS). With a builder system, website operators can create a website very easily and without programming knowledge. In many cases, web hosts also offer builder systems. By using a builder system, personal data about you may also be collected, stored, and processed. In this privacy notice, we provide you with general information about data processing by website builder systems. More detailed information can be found in the provider's privacy policies.

Why do we use website builder systems for our website?

The biggest advantage of a modular system is its ease of use. We want to provide you with a clear, simple, and well-structured website that we can operate and maintain ourselves without external support. Modular systems now offer many helpful functions that we can use even without programming knowledge. This allows us to design our web presence according to our wishes and offer you an informative and pleasant time on our website.

What data is stored by a modular system?

Which data is stored exactly depends, of course, on the website builder system used. Every provider processes and collects different data from the website visitor. As a rule, however, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider, and the date of your website visit are collected. Furthermore, tracking data (e.g., browser activity, clickstream activities, session heatmaps, etc.) may also be processed. In addition, personal data can also be collected and stored. This usually involves contact details such as email address, telephone number (if you have provided them), IP address, and geographical location data. You can find out exactly what data is stored in the provider's privacy policy.

How long and where is the data stored?

We will inform you about the duration of data processing further down in connection with the website builder system used, provided we have further information on this. You can find detailed information on this in the provider's privacy policy. In general, we only process personal data for as long as is strictly necessary for the provision of our services and products. It is possible that the provider stores data from you according to its own criteria, over which we have no influence.

Right to object

You always have the right to access, rectification, and erasure of your personal data. If you have any questions, you can also contact the administrators of the website builder system used at any time. Contact details can be found either in our privacy policy or on the website of the respective provider.

You can delete, disable, or manage cookies used by providers for their functions in your browser. Depending on which browser you use, this works in different ways. However, please note that not all functions may then work as usual.

Legal basis

We have a legitimate interest in using a website builder system to optimize our online service and present it to you efficiently and in a user-friendly manner. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). Nevertheless, we only use the builder system to the extent that you have given your consent.

Insofar as the processing of data is not strictly necessary for the operation of the website, such data is processed only on the basis of your consent. This applies in particular to tracking activities. The legal basis in this regard is Art. 6 (1) (a) GDPR.

With this privacy policy, we have provided you with the most important general information regarding data processing. If you would like to find out more detailed information in this regard, you will find further information – if available – in the following section or in the provider's privacy policy.

WordPress.com Privacy Policy

WordPress.com Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Processed data: Data such as technical usage information like browser activity, clickstream activity, session heatmaps, as well as contact details, IP address, or your geographic location. You can find more details about this further down in this privacy policy.
📅 Retention period: It depends primarily on the type of data stored and the specific settings.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is WordPress?

We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

In 2003, the company was born and in a relatively short time developed into one of the best-known content management systems (CMS) worldwide. A CMS is software that helps us design our website and present content in a visually appealing and organized way. The content can consist of text, audio, and video.
By using WordPress, your personal data may also be collected, stored, and processed. As a rule, primarily technical data such as operating system, browser, screen resolution, or hosting provider are stored. However, personal data such as IP address, geographical data, or contact details may also be processed.

Why do we use WordPress on our website?

We have many strengths, but real programming just isn't one of our core competencies.

Nevertheless, we want a high-performing and attractive website that we can also manage and maintain ourselves. With a website builder or a content management system like WordPress, precisely that is possible. With WordPress, we do not need to be programming aces to be able to offer you a beautiful website. Thanks to WordPress, we can also operate our website quickly and easily without any prior technical knowledge. If technical problems ever arise or we have special requests for our website, there are still our professionals who feel at home in HTML, PHP, CSS, and the like.

Thanks to the simple usability and comprehensive features of WordPress, we can design our web presence according to our wishes and offer you a great user experience.

What data is processed by WordPress?

Non-personal data includes, for example, technical usage information such as browser activity, clickstream activity, session heatmaps, and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet service provider, and the date of the site visit.

Furthermore, personal data is also collected. This primarily includes contact data (e-mail address or telephone number, provided you supply them), IP address, or your geographic location.

WordPress can also use cookies to collect data. These frequently record data about your behavior on our website. For example, it can record which subpages you particularly like to view, how long you stay on individual pages, when you leave a page again (bounce rate), or which preferences (e.g., language selection) you have made. Based on this data, WordPress can also better adapt its own marketing measures to your interests and user behavior. The next time you visit our website, it will consequently be displayed to you as you previously configured it.

WordPress can also use technologies such as pixel tags (web beacons) to clearly identify you as a user, for example, and potentially be able to offer interest-based advertising.

How long and where is the data stored?

How long the data is stored depends on various factors. Above all, it depends on the type of data stored and the specific settings of the website. In principle, data is deleted in WordPress when it is no longer needed for its own purposes. There are exceptions, of course, especially when legal obligations require longer retention of the data. Web server logs containing your IP address and technical data are deleted by WordPress or Automattic after 30 days. Automattic uses the data for this long to analyze traffic on its own websites (for example, all WordPress sites) and to fix potential problems. Deleted content on WordPress sites is also kept in the trash for 30 days to allow for recovery, after which it may remain in backups and caches until they are deleted. The data is stored on Automattic's American servers.

How can I delete my data or prevent data storage?

You have the right and the ability to access your personal data at any time and to object to its use and processing. You may also file a complaint with a government regulatory authority at any time.

In your browser, you also have the option to manage, delete, or disable cookies individually. Please note, however, that disabling or deleting cookies may have a negative impact on the functionality of our WordPress site. Depending on which browser you use, the process for managing cookies varies slightly. Under the „Cookies“ section, you’ll find links to the relevant instructions for the most popular browsers.

Legal basis

If you have consented to the use of WordPress, this consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected by WordPress.

We also have a legitimate interest in using WordPress to optimize our online service and present it in an appealing way to you. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use WordPress to the extent that you have given your consent.

WordPress and Automattic also process your data in the USA, among other places. Automattic is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template documents provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the standard contractual clauses, Automattic commits to maintaining the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more details about the privacy policy and what data is processed by WordPress and how, please visit https://automattic.com/privacy/.

WordPress.com Data Processing Agreement (DPA)

In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded a data processing agreement (DPA) with WordPress.com. You can read more about what a DPA is and, above all, what a DPA must contain in our general section on the „Data Processing Agreement (DPA)“.

This contract is legally required because WordPress.com processes personal data on our behalf. It clarifies that WordPress.com may only process data it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) under https://wordpress.com/support/data-processing-agreements/.

Introduction to web analytics

Web Analytics Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Evaluation of visitor information to optimize the website offerings.
📓 Data Processed: Access statistics, which include data such as access locations, device information, duration and time of access, navigation behavior, click behavior, and IP addresses. For more details, please refer to the respective web analytics tool used.
📅 Retention period: depending on the web analytics tool used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Web Analytics?

We use software on our website to analyze the behavior of website visitors, referred to as web analytics for short. This involves collecting data that the respective analytics tool provider (also called a tracking tool) stores, manages, and processes. This data is used to create analyses of user behavior on our website and make them available to us as website operators. In addition, most tools offer various testing options. For example, we can test which offers or content resonate best with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles may also be created and the data stored in cookies.

Why do we do web analytics?

With our website, we have a clear goal in mind: we want to provide the best online experience in our industry. To achieve this goal, we aim to offer the best and most engaging content while also ensuring that you feel completely at ease on our website. Using web analytics tools, we can take a closer look at the behavior of our website visitors and then improve our website for both you and us accordingly. For example, we can determine the average age of our visitors, where they’re from, when our website receives the most traffic, and which content or products are particularly popular. All of this information helps us optimize the website and tailor it as closely as possible to your needs, interests, and preferences.

What data is processed?

Exactly what data is stored depends, of course, on the analytics tools used. However, as a general rule, the data stored includes, for example, what content you view on our website, which buttons or links you click, when you visit a page, which browser you use, and what device (PC, tablet, smartphone, etc.) you use to visit the website, and what computer system you use. If you have consented to the collection of location data, this data may also be processed by the web analytics tool provider.

In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are considered personal data. However, your IP address is generally stored in a pseudonymized form (i.e., in an unrecognizable and truncated form). For the purposes of testing, web analytics, and web optimization, no direct data—such as your name, age, address, or email address—is stored. Any such data that is collected is stored in a pseudonymized form. This ensures that you cannot be identified as an individual.

The following example schematically illustrates how Google Analytics works as an example of client-side web tracking using JavaScript code.

How long the respective data is stored always depends on the provider. Some cookies only store data for a few minutes or until you leave the website again, while other cookies can store data for several years.

Duration of data processing

We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be extended.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.

Legal basis

The use of web analytics requires your consent, which we have obtained through our cookie pop-up. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by web analytics tools.

In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. Web analytics help us detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). Nevertheless, we only use these tools to the extent that you have given your consent.

Since web analytics tools use cookies, we also recommend that you read our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should review the privacy policies of the respective tools.

Information on specific web analytics tools—if available—can be found in the following sections.

Introduction to messenger services and communication

Messenger & Communication Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Contact inquiries and general communication between us and you
📓 Processed Data: Data such as name, address, email address, phone number, general content data, and, if applicable, IP address
You can find more details in the respective tools used.
📅 Retention period: depending on the messaging & communication features used
⚖️ Legal Basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests), Art. 6(1), first sentence, (b) GDPR (Contractual or Precontractual Obligations)

What are messenger and communication features?

We offer various ways to communicate with us on our website (such as messaging and chat features, online and contact forms, email, and phone). In doing so, we process and store your data to the extent necessary to respond to your inquiry and take subsequent action.

In addition to traditional communication methods such as email, contact forms, and the phone, we also use chat and messaging services. The most commonly used messaging service at present is WhatsApp, but there are, of course, many different providers that offer messaging features specifically for websites. If content is end-to-end encrypted, this is noted in the individual privacy notices or in the privacy policy of the respective provider. End-to-end encryption simply means that the content of a message is not visible even to the provider. However, information about your device, location settings, and other technical data may still be processed and stored.

Why do we use messenger and communication features?

Communication options with you are of great importance to us. After all, we want to talk to you and answer any possible questions about our service in the best possible way. Well-functioning communication is an important part of our service. With the practical messenger and communication features, you can choose the ones you prefer at any time. In exceptional cases, however, it may also happen that we do not answer certain questions via chat or messenger. This is the case, for example, when it comes to internal contractual matters. For these, we recommend other communication options such as e-mail or telephone.

We generally assume that we remain responsible under data protection law, even if we use services provided by a social media platform. However, the European Court of Justice has ruled that in certain cases, the operator of the social media platform, together with us, may be joint controllers within the meaning of Art. 26 GDPR. Where this is the case, we point this out separately and cooperate on the basis of a corresponding agreement. The essentials of the agreement are set out below under the affected platform.

Please note that when using our embedded elements, your data may also be processed outside the European Union, as many providers, such as Facebook Messenger or WhatsApp, are American companies. As a result, you may no longer be able to claim or enforce your rights regarding your personal data as easily.

What data is processed?

The exact data that is stored and processed depends on the respective provider of the messenger and communication functions. In general, this includes data such as name, address, telephone number, email address, and content data, such as all information you enter into a contact form. Information about your device and your IP address is also usually stored. Data collected through a messenger and communication function is also stored on the providers’ servers.

If you want to know precisely which data is stored and processed by the respective providers and how you can object to the data processing, you should read the company's respective privacy policy carefully.

How long is data stored?

How long the data is processed and stored primarily depends on the tools we use. Further below, you can find more information about the data processing carried out by the individual tools. The providers’ privacy policies usually state exactly which data is stored and processed and for how long. In principle, personal data is processed only for as long as is necessary to provide our services. If data is stored in cookies, the storage period varies greatly. The data may be deleted immediately after leaving a website, but it may also remain stored for several years. Therefore, you should examine each individual cookie in detail if you would like more precise information about data storage. In most cases, the privacy policies of the individual providers also contain useful information about the individual cookies.

Right to object

You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling or deleting cookies in your browser. For further information, please refer to the section on consent.

As cookies may be used for messenger and communication functions, we also recommend that you read our general Privacy Policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

Legal basis

If you have consented that data from you may be processed and stored through integrated messenger & communication functions, this consent is considered the legal basis for data processing (Art. 6(1)(a) GDPR). We process your enquiry and manage your data within the framework of contractual or pre-contractual relationships in order to fulfil our pre-contractual and contractual obligations or to answer enquiries. The basis for this is Art. 6(1) sentence 1 lit. b GDPR. In principle, if consent has been given, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners.

Introduction to social media

Social Media Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Presentation and optimisation of our services, contact with visitors, prospective customers and others, advertising
📓 Data processed: Data such as telephone numbers, email addresses, contact details, data on user behaviour, information about your device and your IP address.
More details can be found under the respective social media tool used.
📅 Storage period: depending on the social media platforms used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is social media?

In addition to our website, we are also active on various social media platforms. User data may be processed so that we can specifically address users who are interested in us via social networks. In addition, elements of a social media platform may also be embedded directly into our website. This is the case, for example, if you click on a so-called social button on our website and are redirected directly to our social media presence. So-called social networks or social media are websites and apps through which registered members can create content, exchange content publicly or within specific groups, and connect with other members.

Why do we use social media?

For years, social media platforms have been the place where people communicate and connect online. Through our social media presences, we can introduce our products and services to interested parties. The social media elements integrated into our website help you to quickly and easily access our social media content.

The data stored and processed through your use of a social media channel primarily serves the purpose of enabling web analytics. The aim of these analyses is to develop more precise and personalised marketing and advertising strategies. Depending on your behaviour on a social media platform, the evaluated data can be used to draw appropriate conclusions about your interests and to create so-called user profiles. This also enables the platforms to present you with tailored advertisements. In most cases, cookies are placed in your browser for this purpose, which store data about your usage behaviour.

As a rule, we assume that we remain responsible under data protection law even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Art. 26 GDPR. Where this is the case, we point this out separately and work on the basis of a corresponding agreement. The essential content of the agreement is then reproduced further below for the platform concerned.

Please note that when using social media platforms or elements embedded by us, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are American companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.

What data is processed?

The exact data that is stored and processed depends on the respective provider of the social media platform. However, this usually includes data such as telephone numbers, email addresses, data that you enter into a contact form, user data such as which buttons you click, whom you like or follow, when you visited which pages, information about your device and your IP address. Most of this data is stored in cookies. In particular, if you have a profile on the social media channel you are visiting and are logged in, data may be linked to your profile.

All data collected through a social media platform is also stored on the providers’ servers. Therefore, only the providers have access to the data and can provide you with the appropriate information or make changes.

If you want to know exactly what data is stored and processed by social media providers and how you can object to the data processing, you should carefully read the respective company’s privacy policy. If you have questions about data storage and data processing or wish to exercise corresponding rights, we recommend that you contact the provider directly.

Duration of data processing

We will provide information about the duration of data processing further below, insofar as we have additional information about it. For example, the social media platform Facebook stores data until it is no longer needed for its own purposes. However, customer data that is compared with the company’s own user data is deleted within two days. In general, we process personal data only for as long as is absolutely necessary to provide our services and products. If required by law, as is the case with accounting, for example, this storage period may also be exceeded.

Right to object

You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers such as embedded social media elements. This works either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling or deleting cookies in your browser.

As cookies may be used by social media tools, we also recommend reading our general Privacy Policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

Legal basis

If you have consented that data from you may be processed and stored through integrated social media elements, this consent is considered the legal basis for data processing. (Art. 6 Abs. 1 lit. a DSGVO). In principle, if consent has been given, your data is also processed on the basis of our legitimate interest (Art. 6 Abs. 1 lit. f DSGVO) in fast and good communication with you or other customers and business partners are stored and processed. However, we only use the tools if you have given your consent. Most social media platforms also place cookies in your browser to store data. Therefore, we recommend that you carefully read our privacy text about cookies and view the privacy policy or cookie policies of the respective service provider.

Information on specific social media platforms can be found—if available—in the following sections.

Facebook Privacy Policy

Facebook Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as customer data, data on user behaviour, information about your device and your IP address.
More details can be found further below in this Privacy Policy.
📅 Storage period: until the data is no longer useful for Facebook’s purposes
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are Facebook tools?

We use selected tools from Facebook on our website. Facebook is a social media network operated by Meta Platforms Inc., or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. With the help of these tools, we can offer you and people who are interested in our products and services the best possible service.

If data about you is collected and transmitted through our embedded Facebook elements or through our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for it. Facebook alone is responsible for the further processing of this data. Our joint obligations have also been set out in a publicly accessible agreement at https://www.facebook.com/legal/controller_addendum anchored. It states, for example, that we must clearly inform you about the use of Facebook tools on our website. Furthermore, we are also responsible for ensuring that the tools are integrated into our website in a manner that complies with data protection law. Facebook, on the other hand, is responsible, for example, for the data security of Facebook products. If you have any questions regarding the collection and processing of data by Facebook, you can contact the company directly. If you direct the question to us, we are obliged to forward it to Facebook.

Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.

In addition to many other products, Facebook also offers the so-called “Facebook Business Tools.” This is Facebook’s official term. However, because the term is hardly known, we have decided to refer to them simply as Facebook tools. These include, among others:

  • Facebook Pixel
  • social plug-ins (such as the “Like” or “Share” button)
  • Facebook Login
  • Account Kit
  • APIs (programming interfaces)
  • SDKs (collection of programming tools)
  • Platform integrations
  • Plugins
  • Codes
  • Specifications
  • Documentation
  • Technologies and services

Through these tools, Facebook expands its services and has the ability to obtain information about user activities outside of Facebook.

Why do we use Facebook tools on our website?

We only want to show our services and products to people who are genuinely interested in them. With the help of advertisements (Facebook Ads), we can reach exactly these people. However, in order to show users suitable advertising, Facebook needs information about people’s wishes and needs. For this purpose, information about user behaviour (and contact details) on our website is made available to the company. This allows Facebook to collect better user data and show interested people suitable advertising for our products or services. The tools therefore enable customised advertising campaigns on Facebook.

Facebook refers to data about your behaviour on our website as “event data.” This data is also used for measurement and analytics services. Facebook can therefore create “campaign reports” on our behalf regarding the effectiveness of our advertising campaigns. Furthermore, analyses give us a better understanding of how you use our services, website or products. This allows us to use some of these tools to optimise your user experience on our website. For example, social plug-ins allow you to share content from our website directly on Facebook.

What data is stored by Facebook tools?

Through the use of individual Facebook tools, personal data (customer data) may be sent to Facebook. Depending on the tools used, customer data such as name, address, telephone number and IP address may be transmitted.

Facebook uses this information to match the data with the data it already has about you (if you are a Facebook member). Before customer data is transmitted to Facebook, so-called “hashing” takes place. This means that a data set of any size is transformed into a string of characters. This also serves to encrypt data.

In addition to contact details, “event data” is also transmitted. “Event data” refers to the information we receive about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information it receives with third parties, such as advertisers, unless the company has explicit permission or is legally required to do so. “Event data” may also be linked to contact details. This enables Facebook to provide better personalised advertising. After the matching process mentioned above, Facebook deletes the contact details again.

In order to deliver advertisements in an optimised manner, Facebook only uses the event data if it has been combined with other data (which was collected by Facebook in another way). Facebook also uses this event data for security, protection, development and research purposes. Much of this data is transferred to Facebook via cookies. Cookies are small text files that are used to store data or information in browsers. Depending on the tools used and on whether you are a Facebook member, different numbers of cookies are created in your browser. In the descriptions of the individual Facebook tools, we go into more detail about individual Facebook cookies. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.

How long and where is the data stored?

In principle, Facebook stores data until it is no longer needed for its own services and Facebook products. Facebook has servers distributed around the world where its data is stored. However, customer data is deleted within 48 hours after it has been matched with Facebook’s own user data.

How can I delete my data or prevent data from being stored?

In accordance with the General Data Protection Regulation, you have the right to access, rectification, data portability and erasure of your data.

A complete deletion of the data only takes place if you completely delete your Facebook account. And this is how deleting your Facebook account works:

1. Click on **Settings** on the right-hand side of Facebook.

2. Then click on “Your Facebook Information” in the left-hand column.

3. Now click on “Deactivation and deletion”.

4. Now select “Delete account” and then click “Continue to account deletion”.

5. Now enter your password, click “Continue” and then “Delete account”.

The data that Facebook receives through our website is stored, among other things, via cookies (e.g. with social plugins). In your browser, you can disable, delete or manage individual or all cookies. How this works depends on which browser you use. Under the section “Cookies”, you will find the corresponding links to the respective instructions for the most popular browsers.

If you generally do not want cookies, you can configure your browser so that it always informs you when a cookie is about to be set. This allows you to decide for each individual cookie whether you want to allow it or not.

Legal basis

If you have consented that data from you may be processed and stored through integrated Facebook tools, this consent is considered the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners. However, we only use the tools if you have given your consent. Most social media platforms also place cookies in your browser in order to store data. Therefore, we recommend that you read our privacy text about cookies carefully and view Facebook’s privacy policy or cookie policies.

Facebook also processes your data in the USA, among other places. Facebook and Meta Platforms are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Facebook uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Facebook undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/legal/terms/dataprocessing.

We hope we have provided you with the most important information about the use of and data processing by Facebook tools. If you would like to learn more about how Facebook uses your data, we recommend the data policies at https://www.facebook.com/privacy/policy/.

Facebook Login Privacy Policy

We have integrated the practical Facebook Login into our website. This allows you to log in easily using your Facebook account without having to create another user account. If you decide to register using Facebook Login, you will be redirected to the social media network Facebook. There, you log in using your Facebook user data. Through this login process, data about you and your user behaviour is stored and transmitted to Facebook.

To store the data, Facebook uses various cookies. Below, we show you the most important cookies that are set in your browser or already exist when you log in to our website using Facebook Login:

Name: fr
Value: 0jieyh4c2GnlufEJ9..Bde09j…1.0.Bde09j
Purpose: This cookie is used so that the social plugin on our website functions as well as possible.
Expiry date: after 3 months

Name: datr
Value: 4Jh7XUA2322726102SEmPsSfzCOO4JFFl
Purpose: Facebook sets the “datr” cookie when a web browser accesses facebook.com, and the cookie helps identify login activity and protect users.
Expiry date: after 2 years

Name: _js_datr
Value: deleted
Purpose: Facebook sets this session cookie for tracking purposes, even if you do not have a Facebook account or are logged out.
Expiry date: at the end of the session

Note: The cookies listed are only a small selection of the cookies available to Facebook. Other cookies include, for example, _fbp, sb or wd. A complete list is not possible because Facebook has a large number of cookies and uses them variably.

On the one hand, Facebook Login offers you a quick and easy registration process; on the other hand, it gives us the opportunity to share data with Facebook. This allows us to better tailor our services and advertising campaigns to your interests and needs. Data that we receive from Facebook in this way includes public data such as

  • Your Facebook name
  • Your profile picture
  • a stored email address
  • Friends lists
  • Button information (e.g. “Like” button)
  • Date of birth
  • Language
  • Place of residence

In return, we provide Facebook with information about your activities on our website. This includes information about the device you use, which subpages of our website you visit or which products you have purchased from us.

By using Facebook Login, you consent to data processing. You can withdraw this consent at any time. If you would like more information about data processing by Facebook, we recommend Facebook’s Privacy Policy at https://www.facebook.com/privacy/policy/.

If you are logged in to Facebook, you can change your ad settings yourself at https://www.facebook.com/adpreferences/advertisers/?entry_product=ad_settings_screen.

Facebook Social Plugins Privacy Policy

Our website includes so-called social plugins from Meta Platforms Inc. You can recognise these buttons by the classic Facebook logo, such as the “Like” button (the hand with a raised thumb), or by a clear “Facebook Plugin” label. A social plugin is a small part of Facebook that is integrated into our website. Each plugin has its own function. The most commonly used functions are the well-known “Like” and “Share” buttons.

The following social plugins are offered by Facebook:

  • “Save” button
  • “Like” button, Share, Send and Quote
  • Page Plugin
  • Comments
  • Messenger Plugin
  • Embedded posts and video players
  • Group Plugin

At https://developers.facebook.com/docs/plugins, you can find more detailed information about how the individual plugins are used. We use social plugins on the one hand to provide you with a better user experience on our website and on the other hand because Facebook can use them to optimise our advertisements._

If you have a Facebook account or have previously visited https://www.facebook.com/, Facebook has already set at least one cookie in your browser. In this case, your browser sends information to Facebook via this cookie as soon as you visit our website or interact with social plugins (e.g. the “Like” button).

The information received is deleted or anonymised within 90 days. According to Facebook, this data includes your IP address, the website you visited, the date, the time and other information relating to your browser.

To prevent Facebook from collecting large amounts of data during your visit to our website and linking it to your Facebook data, you must log out of Facebook while visiting the website.

If you are not logged in to Facebook or do not have a Facebook account, your browser sends less information to Facebook because you have fewer Facebook cookies. Nevertheless, data such as your IP address or which website you visit may be transmitted to Facebook. We would also like to expressly point out that we do not know the exact content of the data. However, based on our current knowledge, we try to inform you about data processing as well as possible. You can also read how Facebook uses the data in the company’s Data Policy at https://www.facebook.com/about/privacy/update.

At least the following cookies are set in your browser when you visit a website with Facebook social plugins:

Name: dpr
Value: not specified
Purpose: This cookie is used to ensure that the social plugins on our website function properly.
Expiry date: at the end of the session

Name: fr
Value: 0jieyh4322726102c2GnlufEJ9..Bde09j…1.0.Bde09j
Purpose: This cookie is also required for the plugins to function properly.
Expiry date: after 3 months

Note: These cookies were set during a test, even if you are not a Facebook member.

If you are logged in to Facebook, you can change your ad settings yourself at https://www.facebook.com/adpreferences/advertisers/. If you are not a Facebook user, you can generally manage your usage-based online advertising at https://www.youronlinechoices.com/de/praferenzmanagement/?tid=322726102. There, you have the option to deactivate or activate providers.

If you would like to learn more about Facebook’s data protection practices, we recommend the company’s own Data Policy at https://www.facebook.com/privacy/policy/.

Instagram Privacy Policy

Instagram Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Processed data: Data such as user behavior data, information about your device, and your IP address.
More details can be found further below in this Privacy Policy.
📅 Retention period: until Instagram no longer needs the data for its purposes
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Instagram?

We have integrated Instagram features into our website. Instagram is a social media platform operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and is one of Facebook’s products. The inclusion of Instagram content on our website is known as embedding. This allows us to display content such as buttons, photos, or videos from Instagram directly on our website. When you visit pages on our website that have an Instagram feature integrated, data is transmitted to, stored by, and processed by Instagram. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed across all Facebook companies.

In the following, we want to give you a more detailed insight into why Instagram collects data, what kind of data it is, and how you can largely control the data processing. Since Instagram belongs to Meta Platforms Inc., we base our information partly on the Instagram policies and partly on the Meta privacy policy itself.

Instagram is one of the most famous social media networks worldwide. Instagram combines the advantages of a blog with the advantages of audiovisual platforms like YouTube or Vimeo. You can upload photos and short videos to Insta (as many users casually call the platform), edit them with various filters, and also share them on other social networks. And if you don't want to be active yourself, you can simply follow other interesting users.

Why do we use Instagram on our website?

Instagram is the social media platform that has really taken off in recent years. And, of course, we’ve responded to this boom as well. We want you to feel as comfortable as possible on our website. That’s why presenting our content in a variety of ways is a given for us. Thanks to the embedded Instagram features, we can enrich our content with helpful, funny, or exciting posts from the world of Instagram. Since Instagram is a subsidiary of Facebook, the data collected can also be used for personalized advertising on Facebook. This ensures that our ads reach only people who are genuinely interested in our products or services.

Instagram also uses the data it collects for measurement and analysis purposes. We receive aggregated statistics, which give us more insight into your preferences and interests. It is important to note that these reports do not identify you personally.

What data does Instagram store?

When you visit one of our pages that incorporates Instagram features (such as Instagram images or plug-ins), your browser automatically connects to Instagram’s servers. In the process, data is sent to Instagram, where it is stored and processed—regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases you’ve made, the ads you see, and how you use our service. Additionally, the date and time of your interaction with Instagram are stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.

Facebook distinguishes between customer data and event data. We assume this is also the case with Instagram. Customer data includes, for example, name, address, phone number, and IP address. This customer data will only be transmitted to Instagram after it has been „hashed.“ Hashing means that a data record is converted into a string of characters. This allows contact information to be encrypted. In addition, the „event data“ mentioned above is also transmitted. By „event data,“ Facebook—and consequently Instagram—means data about your user behavior. It may also happen that contact data is combined with event data. The collected contact data is matched against the data Instagram already has about you.

The collected data is transmitted to Facebook via small text files (cookies) that are usually placed in your browser. Depending on the Instagram features used and whether you have an Instagram account yourself, varying amounts of data are stored.

We assume that data processing on Instagram works the same way as it does on Facebook. This means that if you have an Instagram account or www.instagram.com visited, Instagram has at least set a cookie. If that is the case, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram feature. After 90 days at the latest (after matching), this data is deleted or anonymized again. Although we have dealt intensively with Instagram's data processing, we cannot say precisely what data Instagram actually collects and stores.

Below, we show you cookies that are set in your browser at a minimum when you click on an Instagram feature (such as a button or an Instagram picture). In our test, we assume that you do not have an Instagram account. If you are logged into Instagram, significantly more cookies will, of course, be set in your browser.

These cookies were used in our test:

name: csrftoken
Value: “”
Purpose: This cookie is most likely set for security reasons to prevent fraudulent requests. However, we were unable to determine the exact reason.
Expiration Date: after one year

name: mid
Value: “”
Purpose: Instagram sets this cookie to optimize its services and offerings both on and off Instagram. The cookie assigns a unique user ID.
Expiration Date: after the meeting

name: fbsr_322726102124024
Value: No information
Purpose: This cookie stores the login request for users of the Instagram app.
Expiration Date:
after the meeting

name: rur
Value: ATN
Purpose: This is an Instagram cookie that ensures functionality on Instagram.
Expiration Date: after the meeting

name: urlgen
Value: “{”194.96.75.33”: 1901}:1iEtYv:Y833k2_UjKvXgYe322726102”
Purpose: This cookie is used for Instagram's marketing purposes.
Expiration Date: after the meeting

Note: We cannot claim completeness here. Which cookies are set in an individual case depends on the embedded features and your use of Instagram.

How long and where is the data stored?

Instagram shares the information it receives among Facebook companies, with external partners, and with people you connect with worldwide. Data processing is carried out in compliance with its own data policy. Your data is distributed across Facebook servers around the world, partly for security reasons, among others. Most of these servers are located in the USA.

How can I delete my data or prevent data from being stored?

Under the General Data Protection Regulation, you have the right to access, transfer, correct, and delete your data. You can manage your data in your Instagram settings. If you want to completely delete your data from Instagram, you must permanently delete your Instagram account.

Here's how to delete your Instagram account:

First, open the Instagram app. Go down to your profile page and click on „Help“. Now you will be taken to the company's website. On the website, click on „Manage Your Account“ and then on „Delete Your Account“.

If you permanently delete your account, Instagram will delete posts such as your photos and status updates. Information that other people have shared about you is not part of your account and therefore will not be deleted.

As mentioned above, Instagram primarily stores your data using cookies. You can manage, disable, or delete these cookies in your browser. Depending on your browser, the management process works a bit differently. Under the „Cookies“ section, you will find the relevant links to the respective guides for the most popular browsers.

You can also generally configure your browser so that you are always informed when a cookie is to be set. Then you can always decide individually whether you want to allow the cookie or not.

Legal basis

If you have consented that data from you may be processed and stored through integrated social media elements, this consent is considered the legal basis for data processing. (Art. 6 Abs. 1 lit. a DSGVO). In principle, your data is also processed based on our legitimate interest (Art. 6 Abs. 1 lit. f DSGVO) stored and processed for fast and effective communication with you or other customers and business partners. We also only use the integrated social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser in order to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and review the privacy policy or cookie guidelines of the respective service provider.

Instagram also processes your data in the USA, among other places. Instagram or Meta Platforms is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

Furthermore, Instagram uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Instagram commits to maintaining the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

We have tried to bring you closer to the most important information about data processing by Instagram. On https://privacycenter.instagram.com/policy/ can you take a closer look at Instagram's data policies.

Introduction to affiliate programs

Affiliate programs privacy policy summary
👥 Data subjects: Website visitors
🤝 Purpose: economic success and the optimization of our service.
📓 Processed data: Access statistics containing data such as access locations, device data, access duration and time, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
📅 Storage period: personal data is usually stored by affiliate programs until it is no longer needed
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are affiliate programs?

We use partner programs from various providers on our website. By using a partner program, your data may be transferred to, stored by, and processed by the respective partner program provider. In this privacy policy, we provide you with a general overview of data processing by partner programs and show you how you can prevent or revoke data transmission. Every partner program (also known as an affiliate program) is based on the principle of referral commission. A link or an advertisement including a link is placed on our website, and if you are interested, click on it, and purchase a product or service in this way, we receive a commission (advertising cost reimbursement) for it.

Why do we use affiliate programs on our website?

Our goal is to provide you with a pleasant time and plenty of helpful content. To achieve this, we put a great deal of work and time into developing our website. Through affiliate programs, we have the opportunity to be slightly compensated for our work. Every affiliate link is, of course, always related to our topic and showcases offers that might interest you.

What data is processed?

To track whether you have clicked on a link provided by us, the affiliate program provider must know that it was you who followed the link via our website. Therefore, the affiliate program links used must be correctly attributed to the subsequent actions (transaction, purchase, conversion, impression, etc.). Only then can the calculation and settlement of commissions function properly.

For this assignment to work, a value can be appended to a link (in the URL) or information can be stored in cookies. This stores, for example, which page you are coming from (referrer), when you clicked on the link, an identifier of our website, which offer it is, and a user identifier.

This means that as soon as you interact with products and services of an affiliate program, this provider also collects data from you. Exactly what data is stored depends on the individual providers. For example, the Amazon Affiliate Program distinguishes between active and automatic information. Active information includes name, email address, telephone number, age, payment information, or location information. Automatically stored information in this case includes user behavior, IP address, device information, and the URL.

Duration of data processing

We will inform you about the duration of the data processing further down, provided we have further information on this. In general, personal data is only processed for as long as is necessary for the provision of the services and products. Data stored in cookies is stored for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others can be stored in your browser for several years unless actively deleted. The exact duration of data processing depends on the provider used; in most cases, you should expect a storage period of several years. You will generally find exact information on the duration of data processing in the respective privacy policies of the individual providers.

Right to object

You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the data controller of the affiliate program provider you are using at any time. You can find contact information either in our specific privacy policy or on the website of the respective provider.

You can delete, disable, or manage the cookies that websites use for their functions in your browser. The process varies depending on which browser you use.

Legal basis

If you have consented to the use of affiliate programs, the legal basis for the corresponding data processing is this consent. According to this consent represents Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as can occur when collecting data through an affiliate program, sets out.

Furthermore, we have a legitimate interest in using an affiliate program to optimize our online service and our marketing measures. The corresponding legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). Nevertheless, we only use the partner program insofar as you have given your consent.

Information on special affiliate programs, if available, can be found in the following sections.

Booking.com Partner Program Privacy Statement

We use the Booking.com affiliate program for our website. The service provider is the Dutch company Booking.com B.V., Herengracht 597, 1017 CE Amsterdam, Netherlands. You can learn more about the data processed through the use of Booking.com in the privacy policy at https://www.booking.com/content/privacy.de.html.

eBay Partner Network Privacy Policy

We use the eBay partner program for our website. The service provider is the American company eBay Partner Network, Inc., 2145 Hamilton Ave., San Jose, CA 95125, USA.

eBay also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This can be associated with various risks for the lawfulness and security of data processing.

As the legal basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, specifically in the USA) or for transferring data there, eBay uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template forms provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through these clauses, eBay undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

Learn more about the data and standard contractual clauses processed through the use of eBay Partner Network in the privacy policy at https://partnernetwork.ebay.de/page/network-agreement#privacy-policy.

Cloud services

Cloud Services Privacy Policy Summary
👥 Affected parties: We as website operators and you as website visitors
🤝 Purpose: Security and Data Storage
📓 Data Processed: Data such as your IP address, name, or technical information such as your browser version
You can find more details below and in the individual privacy policies or the providers' privacy statements.
📅 Storage period: most data is stored until it is no longer required to provide the service.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are cloud services?

Cloud services provide us, as website operators, with storage space and computing power via the internet. Data can be transmitted, processed, and stored on an external system via the internet. The management of this data is handled by the respective cloud provider. Depending on requirements, an individual or a company can choose the storage size or computing power. Cloud storage is accessed via an API or storage protocols. API stands for Application Programming Interface, which refers to a programming interface that connects software and hardware components.

Why do we use cloud services?

We use cloud services for several reasons. A cloud service offers us the ability to store our data securely. In addition, we have access to the data from different locations and devices, giving us greater flexibility and making our work processes easier. Cloud storage also saves us costs because we do not have to build and manage our own infrastructure for data storage and data security. By centrally storing our data in the cloud, we can also expand our fields of application and manage our information significantly better.

As website operators and companies, we primarily use cloud services for our own purposes. For example, we use the services to manage our calendar and to store documents or other important information in the cloud. However, this may also involve the storage of your personal data. This is the case, for example, when you provide us with your contact details (such as your name and email address) and we store our customer data with a cloud provider. Consequently, data that we process from you may also be stored and processed on external servers. If we offer certain forms or content from cloud services on our website, cookies may also be set for web analytics and advertising purposes. Furthermore, such cookies remember your settings (such as the language used) so that you will find your familiar web environment the next time you visit our website.

What data is processed by cloud services?

Much of the data we store in the cloud is not personal, but some data, according to the GDPR definition, counts as personal data. This frequently involves customer data such as names, addresses, IP addresses, or telephone numbers, or technical device information. Furthermore, videos, images, and audio files can also be stored in the cloud. Exactly how the data is collected and stored depends on the respective service. We try to use only services that handle data in a highly trustworthy and professional manner. Basically, the services, such as Amazon Drive, have access to the stored files in order to be able to offer their own service accordingly. For this, however, the services require permissions such as the right to copy files for security reasons. This data is processed and managed within the scope of the services and in compliance with applicable laws. This includes the GDPR, even for US-based providers (via standard contractual clauses). In some cases, these cloud services also work with third-party providers who can process data under instruction and in accordance with privacy policies and other security measures. At this point, we would like to emphasize once again that all well-known cloud services (such as Amazon Drive, Google Drive, or Microsoft OneDrive) reserve the right to access stored content in order to be able to offer and optimize their own service accordingly.

Duration of data processing

We will inform you about the duration of the data processing further down, provided we have further information on this. In general, cloud services store data until you or we revoke data storage or delete the data again. Generally, personal data is only stored for as long as is strictly necessary for the provision of the services. However, final data deletion from the cloud can take a few months. This is because the data is usually not stored on just one server, but is distributed across various servers.

Right to object

You also have the right and the option to withdraw your consent to data storage in a cloud at any time. If cookies are used, you also have a right of withdrawal here. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. We also recommend our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective cloud providers.

Legal basis

We use cloud services primarily based on our legitimate interests (Art. 6 Abs. 1 lit. f GDPR) in a secure and reliable storage system.

Certain processing activities, in particular the use of cookies and storage functions, require your consent. If you have consented to your data being processed and stored by cloud services, this consent serves as the legal basis for the data processing (Art. 6 (1) (a) GDPR). Most of the services we use place cookies in your browser to store data. Therefore, we recommend that you read our privacy policy regarding cookies carefully and review the privacy policy or cookie guidelines of the respective service provider.

Information about specific tools—if available—can be found in the following sections.

Google Cloud Privacy Notice

We use Google Cloud for our website, an online storage service for files, photos, and videos. The service provider is the American company Google Inc. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google also processes data from you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Google undertakes to maintain the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

Google provides a data processing agreement pursuant to Art. 28 GDPR, which serves as the data protection basis for our customer relationship with Google. This agreement refers to the EU Standard Contractual Clauses in terms of its content. You can find the data processing terms here: https://business.safety.google/intl/de/adsprocessorterms/

You can learn more about the data processed through the use of Google Cloud in the Privacy Policy at https://policies.google.com/privacy?hl=de.

Introduction to payment providers

Payment provider privacy policy summary
👥 Data subjects: Website visitors
🤝 Purpose: Enabling and optimizing the payment process on our website
📓 Processed data: Data such as name, address, bank details (account number, credit card number, passwords, TANs, etc.), IP address and contract data
You can find more details in the respective payment provider tool used.
📅 Retention period: depending on the payment provider used
⚖️ Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract)

What is a payment provider?

We use online payment systems on our website that enable a secure and smooth payment process for both us and you. In the process, personal data may also be sent to the respective payment provider, stored there, and processed there. Payment providers are online payment systems that allow you to place an order via online banking. The payment transaction is processed by the payment provider you have chosen. We then receive information about the payment made. This method can be used by any user who has an active online banking account with PIN and TAN. There are hardly any banks left that do not offer or accept such payment methods.

Why do we use payment providers on our website?

Of course, we want to provide the best possible service through our website and our integrated online store so that you feel comfortable on our site and take advantage of our offers. We know that your time is valuable and that payment processing, in particular, needs to be fast and seamless. For these reasons, we offer a variety of payment providers. You can choose your preferred payment provider and pay in the way you’re used to.

What data is processed?

Which exact data is processed depends, of course, on the respective payment service provider. However, fundamentally, data such as name, address, bank details (account number, credit card number, passwords, TANs, etc.) are stored. This is necessary data in order to be able to carry out a transaction at all. In addition, any contract data and user data, such as when you visit our website, which content you are interested in, or which subpages you click on, may also be stored. Your IP address and information about the computer you are using are also stored by most payment service providers.

The data is generally stored and processed on the servers of the payment service providers. We, as the website operator, do not receive this data. We are only informed whether the payment was successful or not. For identity and credit checks, it may happen that payment service providers forward data to the relevant agency. The terms and conditions and privacy policies of the respective provider always apply to all payment transactions. Therefore, please also always review the general terms and conditions and the privacy policy of the payment service provider. You also have the right at any time, for example, to have data deleted or corrected. Please contact the respective service provider regarding your rights (right of withdrawal, right to information, and data subject rights).

Duration of data processing

We will inform you about the duration of data processing further below, provided we have further information on this. In general, we only process personal data for as long as is strictly necessary for the provision of our services and products. If required by law, such as in the case of accounting, this retention period may be exceeded. For example, we retain accounting records associated with a contract (invoices, contract documents, bank statements, etc.) for 10 years (Section 147 of the German Fiscal Code - AO) and other relevant business documents for 6 years (Section 247 of the German Commercial Code - HGB) after they are generated.

Right to object

You always have the right to access, correction, and deletion of your personal data. If you have any questions, you can also contact the responsible parties of the payment provider used at any time. You can find contact information either in our specific privacy policy or on the website of the respective payment provider.

You can delete, disable, or manage cookies used by payment providers for their functions in your browser. Depending on the browser you use, this works in different ways. However, please note that the payment process may then no longer work.

Legal basis

So we offer for the processing of contractual or legal relationships (Art. 6 para. 1 lit. b GDPR) In addition to traditional banks and credit institutions, other payment service providers are also available. The privacy policies of the individual payment providers (such as Amazon Payments, Apple Pay, or Discover) provide you with a detailed overview of data processing and data storage. In addition, if you have any questions regarding data protection, you can always contact the responsible parties.

Information on the specific payment service providers can be found – if available – in the following sections.

American Express Privacy Statement

We use American Express on our website, a globally operating financial service provider. The service provider is the American company American Express Company. For the European region, the responsible company is American Express Europe S.A. (Avenida Partenón 12-14, 28042, Madrid, Spain).

American Express also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This can be associated with various risks for the lawfulness and security of data processing.

As the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, and thus particularly in the USA) or for data transfers thereto, American Express uses so-called Standard Contractual Clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through these clauses, American Express commits to maintaining the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

You can learn more about the data processed through the use of American Express in the Privacy Policy at https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.

giropay Privacy Policy

We use the online payment provider giropay on our website. The service provider is the German company paydirekt GmbH, located at Stephanstraße 14-16, 60313 Frankfurt am Main, Germany.

For more information about the data processed when using giropay, please see the privacy policy at https://www.giropay.de/agb/index.html.

Google Pay Privacy Policy

We use the online payment provider Google Pay on our website. The service provider is the American company Google Inc. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google also processes data from you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Google undertakes to maintain the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The data processing terms for Google advertising products (Google Ads Controller-Controller Data Protection Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/adscontrollerterms/.

You can find out more about the data processed through the use of Google Pay in the Privacy Policy at https://policies.google.com/privacy.

Klarna Checkout Privacy Policy

Klarna Checkout Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimization of the payment process on our website
📓 Processed data: Data such as name, address, bank details (account number, credit card number, passwords, TANs, etc.), IP address and contract data
You can find more details about this further down in this privacy policy.
📅 Retention period: Data will be stored as long as Klarna needs it for the processing purpose.
⚖️ Legal basis: Art. 6(1)(c) of the GDPR (Legal obligation), Art. 6(1)(f) of the GDPR (Legitimate interests)

What is Klarna Checkout?

We use the Klarna Checkout online payment system from the Swedish company Klarna Bank AB on our website. Klarna Bank is headquartered at Sveavägen 46, 111 34 Stockholm, Sweden. If you choose this service, personal data, among other things, will be sent to, stored by, and processed by Klarna. In this privacy policy, we would like to provide you with an overview of Klarna’s data processing practices.

Klarna Checkout is a payment system for orders placed in an online store. The user selects the payment method, and Klarna Checkout handles the entire payment process. Once a user has made a payment through the Checkout system and provided the necessary information, future online purchases can be completed even faster and more easily. The Klarna system recognizes returning customers as soon as they enter their email address and ZIP code.

Why do we use Klarna Checkout for our website?

Our goal with our website and integrated online store is to provide you with the best possible service. In addition to the overall experience on the website and our product offerings, this also includes smooth, fast, and secure payment processing for your orders. To ensure this, we use the Klarna Checkout payment system.

What data is stored by Klarna Checkout?

As soon as you choose the Klarna payment service and pay using the Klarna Checkout payment method, you also provide personal data to the company. On the Klarna Checkout page, technical data such as your browser type, operating system, our website address, date and time, language settings, time zone settings, and IP address are collected from you, transmitted to Klarna’s servers, and stored there. This data is stored even if you have not yet completed an order.

When you order a product or service via our shop, you must enter your personal data in the provided fields. This data is processed by Klarna for payment processing. Specifically, the following personal data (as well as general product information) may be stored and processed by Klarna for creditworthiness and identity checks:

  • Contact information: names, date of birth, national ID number, title, billing and shipping address, email address, phone number, nationality, or salary.
  • Payment information such as credit card details or your account number
  • Product information such as tracking number, type of item, and price of the product

In addition, there is also data that can be collected optionally, provided you consciously choose to do so. This includes political, religious, or philosophical beliefs, or various health data.

In addition to the data mentioned above, Klarna may also collect data about the goods or services you buy or order, either directly or through third parties (such as through us or via public databases). This can include, for example, the tracking number or the type of item ordered, as well as information about your creditworthiness, your income, or the granting of credit. Klarna may also share your personal data with service providers such as software providers, data storage providers, or us as the merchant.

When data is entered automatically into a form, cookies are always involved. If you do not want to use this function, you can disable these cookies at any time. Further down in the text, you will find instructions on how to generally delete, disable, or manage cookies in your browser. Our tests have shown that no cookies are set directly by Klarna. If you choose the payment method “Klarna Sofort” and click “Place Order”, you will be redirected to the Sofort website. After successful payment, you will be taken to our thank-you page. The following cookie is set there by sofort.com:

name: SOFUEB
Value: e8cipp378mdscn9e17kajlfhv7322726102-4
Purpose: This cookie stores your session ID.
Expiration Date: after ending the browser session

How long and where is the data stored?

Klarna strives to store your data only within the EU or the European Economic Area (EEA). However, there may be instances where data is transferred outside the EU/EEA. If this happens, Klarna ensures that data protection complies with the GDPR and that the third country is covered by an adequacy decision issued by the European Union. Data is always stored for as long as Klarna needs it for the purpose of processing.

How can I delete my data or prevent data from being stored?

You can revoke your consent for Klarna to process personal data at any time. You also always have the right to information, correction, and deletion of your personal data. To do this, you simply need to contact the company or the company's data protection team by email at datenschutz@klarna.de Contact us via the Klarna website „"My Data Protection Request"“ You can also contact Klarna directly.

You can delete, disable, or manage cookies that Klarna may use for its features in your browser. Depending on the browser you use, this works in different ways. You will find the relevant links to the instructions for the most popular browsers under the „Cookies“ section.

Legal basis

So we offer for the processing of contractual or legal relationships (Art. 6 para. 1 lit. b GDPR) In addition to traditional banks and credit institutions, we also offer the payment service provider Klarna Checkout.

We hope we have provided you with a clear overview of how Klarna processes your data. If you would like to learn more about how your data is handled, we recommend that you read the Klarna Privacy Policy at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy.

PayPal Privacy Policy

PayPal Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimization of the payment process on our website
📓 Data Processed: Data such as name, address, banking information (account number, credit card number, passwords, TANs, etc.), IP address, and contract information may be processed.
You can find more details on this further down in this Privacy Policy.
📅 Retention period: Data is generally stored until the relationship with PayPal is terminated
⚖️ Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract), Art. 6(1)(a) of the GDPR (consent)

What is PayPal?

We use the online payment service PayPal on our website. The service provider is the U.S. company PayPal Inc. PayPal Europe (S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg) is responsible for the European region.

With PayPal, all users can send and receive money electronically. The company was founded in 1998 and has now become one of the best-known and largest online payment service providers worldwide, with over 325 million active customers.

Why do we use PayPal for our website?

There are several reasons why we use PayPal and offer it on our website. Since PayPal is one of the best-known online payment providers, many of our website visitors also use and trust this service. PayPal also offers high security standards for digital money transfers. The service uses various encryption methods to protect your personal data as effectively as possible. We also appreciate PayPal’s ease of use and the ability to make international payments in different currencies. Transactions are typically processed very quickly, which is another benefit for both us and you as a customer.

What data is processed by PayPal?

In its Privacy Policy, PayPal distinguishes between various categories of personal data that may be processed through the use of the service. These include registration and contact information, identification and signature data, payment information, information about imported contacts, data from your account profile, device data such as your IP address, location data, and so-called derived data. This refers to information that can be derived from transactions or other data. This may include, for example, purchasing habits, behavioral patterns, creditworthiness, or personal preferences.

There is also personal data collected by third parties (such as identity verification providers, fraud detection providers, or your bank). This data includes information from credit bureaus, transaction data, information regarding legal requirements, technical usage data, location data, and, once again, derived data.

PayPal and its partners also use tracking technologies such as cookies, pixel tags, web beacons, and widgets to recognize you as a user, customize content, and perform analytics for interest-based advertising.

How long and where is the data stored?

In general, PayPal retains data for as long as necessary to fulfill its obligations and within the scope of the intended purpose. Personal data necessary for the customer relationship is retained for up to 10 years after the relationship ends. If PayPal is subject to a legal obligation, the retention period for personal data is determined by the applicable law (e.g., insolvency law). PayPal also retains personal data for as long as necessary if retention is advisable in light of potential legal disputes.

Since PayPal is a global company, it operates data centers around the world where your data may be stored. This means that your data may be stored on PayPal servers outside your country and outside the scope of the GDPR.

How can I delete my data or prevent data from being stored?

You have the right at any time to information, correction, or deletion and restriction of the processing of your personal data. You can also revoke your consent to the processing of data at any time.

If you generally wish to deactivate, delete, or manage cookies, you will find the corresponding links to the respective instructions for the most popular browsers under the „Cookies“ section.

Legal basis

We have a legitimate interest in integrating PayPal as an external payment service to make our offerings more attractive and to improve them technically and economically. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). Please note that you can only use PayPal if you enter into a contractual relationship with PayPal. In such cases, it may be necessary to provide additional data protection and contractual declarations (e.g., consent).

PayPal also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This can be associated with various risks for the legality and security of data processing.

As the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, and specifically in the USA) or for data transfers there, PayPal uses so-called Standard Contractual Clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through these clauses, PayPal commits to maintaining the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more information about the standard contractual clauses and the data processed when using PayPal, please see the Privacy Policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.

UniCredit Privacy Policy

We use the payment provider UniCredit on our website. The service provider is the Italian company UniCredit S.p.A., Piazza Gae Aulenti 3, Tower A, 20154 Milan, Italy.

For more information about the data processed when using UniCredit, please see the Privacy Policy at https://www.unicredit.it/it/info/privacy.html

Visa Privacy Notice

We use Visa, a global payment provider, on our website. The service provider is the U.S. company Visa Inc. Visa Europe Services Inc. (1 Sheldon Square, London W2 6TT, United Kingdom) is responsible for the European region.

Visa processes your data in the United States, among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.

As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, the United States) or for data transfers to those countries, Visa uses so-called standard contractual clauses (= Art. 46. (2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, Visa commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more information on Visa's standard contractual clauses, please visit https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.

For more information about the data processed when using Visa, please see the Privacy Policy at https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Introduction to external online platforms

External Online Platforms: Privacy Policy Summary
👥 Affected parties: Website visitors and visitors to the external online platforms
🤝 Purpose: Presentation and optimization of our service, contact with visitors and prospective customers
📓 Data processed: Data such as telephone numbers, email addresses, contact details, data on user behaviour, information about your device and your IP address.
You can find more details on this from the respective platform being used.
📅 Retention period: depending on the platforms used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are external online platforms?

In order to be able to offer our services or products outside of our website as well, we also use external platforms. These are mostly online marketplaces such as Amazon or eBay. In addition to our data protection responsibility, the privacy policies of the external platforms we use also apply. This is especially the case when our products are purchased via the platform, i.e., when a payment transaction takes place. Furthermore, most platforms also use your data to optimize their own marketing activities. For example, the platform can use collected data to tailor advertisements precisely to the interests of customers and website visitors.

Why do we use external online platforms?

In addition to our website, we also want to offer our products and services on other platforms in order to introduce them to more customers. External online marketplaces such as Amazon, eBay, or Digistore24 offer large sales websites that present our products to people who may not be familiar with our website. It can also happen that embedded elements on our site lead to an external online platform. Data processed and stored by the online platform used serves the company, on the one hand, to log the payment transaction and, on the other hand, to be able to perform web analytics.

The purpose of these analyses is to be able to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a platform, the evaluated data can be used to draw appropriate conclusions about your interests and create so-called user profiles. This also enables platforms to present you with tailored advertisements or products. Cookies are usually placed in your browser for this purpose, which store data on your usage behavior.

Please note that when using the platforms or our embedded elements, your data may also be processed outside the European Union, as online platforms such as Amazon or eBay are American companies. As a result, you may no longer be able to claim or enforce your rights regarding your personal data as easily.

What data is processed?

Exactly which data is stored and processed depends on the specific external platform. However, it usually includes data such as phone numbers, email addresses, information you enter into a contact form, user data (such as which buttons you click and when you visited which pages), information about your device, and your IP address. Very often, most of this data is stored in cookies. If you have your own profile on an external platform and are logged in there, data may be linked to that profile. The collected data is stored on the servers of the platforms used and processed there. You can find out exactly how an external platform stores, manages, and processes data in its respective privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the platform directly.

Duration of data processing

We will inform you about the duration of the data processing below, provided we have further information on this. For example, Amazon stores data until it is no longer required for its own purposes. In general, we only process personal data for as long as is strictly necessary to provide our services and products.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies at any time. This works either via our cookie management tool or via opt-out functions on the respective external platform. Furthermore, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.

Since cookies may be used, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective external platforms.

Legal basis

If you have consented to the processing and storage of your data by external platforms, this applies Consent as the legal basis for data processing (Art. 6 Abs. 1 lit. a DSGVO). In general, if consent has been given, your data will also be processed on the basis of a legitimate interest (Art. 6(1)(f) of the GDPR) for the purpose of ensuring prompt and effective communication with you or other customers and business partners. If we have embedded elements from external platforms on our website, we use them only to the extent that you have given your consent.

Information on special external platforms can be found – if available – in the following sections.

eBay Privacy Notice

We use the online trading platform eBay. The service provider is the American company eBay Inc., 2025 Hamilton Avenue, San Jose, CA 95125, USA.

eBay also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This can be associated with various risks for the lawfulness and security of data processing.

As the legal basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, specifically in the USA) or for transferring data there, eBay uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template forms provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through these clauses, eBay undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

Learn more about the data and standard contractual clauses processed through the use of eBay in the privacy policy at https://www.ebay.com/help/policies/member-behaviour-policies/user-privacy-notice-privacy-policy?id=4260.

Introduction to review platforms

Review platforms summary
👥 Data subjects: Visitors to the website or a review platform
🤝 Purpose: Feedback on our products and/or services
📓 Data Processed: IP address, email address, name, and more. You can find more details below or on the respective review platforms.
📅 Retention period: depending on the respective platform
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. f GDPR (Legitimate interests),

What are review platforms?

You can rate our products or services on various review platforms. We participate in some of these platforms so that we can receive feedback from you and thereby optimize our offerings. If you rate us via a review platform, the privacy policy and terms and conditions of the respective review service apply. In many cases, you’ll also need to register to submit a review. Review technologies (widgets) may also be integrated into our website. When you use one of these integrated tools, data is also transmitted to, processed by, and stored by the respective provider.

Many of these integrated programs work on a similar principle. After you have ordered a product or used a service from us, you will be asked to leave a review via email or on the website. For this purpose, you are usually redirected to a review page via a link, where you can easily and quickly create a review. Some review systems also offer an interface to various social media channels to make the feedback accessible to more people.

Why do we use review platforms?

Review platforms collect feedback and ratings about our offerings. Through your reviews, we quickly receive relevant feedback and can improve our products and/or services much more efficiently. Consequently, the reviews serve us on the one hand to optimize our offerings, and on the other hand, they give you and all our future customers a good overview of the quality of our products and services.

What data is processed?

With your consent, we share information about you and the services you have used with the relevant review platform. We do this to ensure that you have actually used one of our services. Only then can you provide genuine feedback. The data transmitted is used solely for user identification. Exactly which data is stored and processed depends, of course, on the providers used. In most cases, personal data such as your IP address, email address, or name is also provided to the review platforms. Even after you submit your review, order information—such as the order number for a purchased item—is forwarded to the respective platform. If your email address is transmitted, it is so that the review platform can send you an email after you’ve purchased a product. So that we can also display your review on our website, we inform the providers that you have visited our site. The review platform used is responsible for the personal data collected.

How long and where is the data stored?

You can find more details about the duration of data processing below in the provider’s privacy policy, provided we have further information on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Personal data mentioned in a review is typically anonymized by employees of the platform in question and is therefore visible only to the company’s administrators. The collected data is stored on the providers’ servers and, with most providers, deleted upon completion of the contract.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.

Legal basis

If you have consented to the use of a review platform, the legal basis for the corresponding data processing is this consent. Pursuant to Art. 6(1)(a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, such as may occur during collection by a review portal.

We also have a legitimate interest in using a review platform to optimize our online service. The applicable legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we will only use a review platform if you have given your consent.

We hope we have been able to provide you with a clearer understanding of the most important general information regarding data processing by review platforms. You can find more detailed information below in the privacy notices or in the linked privacy policies of the respective companies.

Google Customer Reviews Privacy Policy

We also use the review platform Google Customer Reviews for our website. The service provider is the American company Google Inc. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google also processes data from you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Google undertakes to maintain the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The data processing terms for Google advertising products (Google Ads Controller-Controller Data Protection Terms), which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/

You can find out more about the data processed through the use of Google in the privacy policy at https://policies.google.com/privacy?hl=de.

Introduction to online mapping services

Online Map Services Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Improving the user experience
📓 Data Processed: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, location data, search terms, and/or technical data. You can find more details in the documentation for each tool used.
📅 Storage period: depends on the tools used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are online map services?

We also use online map services as an enhanced feature on our website. Google Maps is probably the service you’re most familiar with, but there are also other providers that specialize in creating digital maps. These services allow us to display locations, route maps, or other geographic information directly on our website. With an integrated map service, you no longer need to leave our website to view, for example, directions to a location. To ensure the online map works on our website, map sections are embedded using HTML code. These services can display road maps, the Earth’s surface, or aerial or satellite images. When you use the embedded map feature, data is also transmitted to and stored by the tool being used. This data may include personal information.

Why do we use online map services on our website?

Generally speaking, our goal is to provide you with a pleasant time on our website. And your time is, of course, only pleasant if you can easily find your way around our website and quickly and easily find all the information you need. Therefore, we thought that an online map system could significantly optimize our service on the website. Without leaving our website, you can easily view directions, locations, or even points of interest using the map system. Of course, it is also super practical that you can see at a glance where our company headquarters is located, so you can find us quickly and safely. As you can see, there are simply many advantages, and we clearly view online mapping services on our website as part of our customer service.

What data is stored by online mapping services?

When you open a page on our website that includes an integrated online map function, personal data may be transmitted to the respective service and stored there. This usually involves your IP address, which can also be used to determine your approximate location. In addition to the IP address, data such as entered search terms as well as latitude and longitude coordinates are also stored. If you enter an address for route planning, for example, this data is also stored. The data is not stored by us, but rather on the servers of the integrated tools. You can imagine it roughly like this: Although you are on our website, when you interact with a map service, this interaction actually takes place on their website. For the service to function properly, at least one cookie is usually also placed in your browser. Google Maps, for example, also uses cookies to record user behavior and thereby optimize its own service and be able to display personalized advertising. You can learn more about cookies in our „Cookies“ section.

How long and where is the data stored?

Every online map service processes different user data. Where we have further information, we inform you about the duration of data processing further down in the corresponding sections for the individual tools. In principle, personal data is generally only stored for as long as necessary to provide the service. Google Maps, for example, stores certain data for a specified period, while other data must be deleted by you. With Mapbox, for instance, the IP address is stored for 30 days and then deleted. As you can see, each tool stores data for varying lengths of time. Therefore, we recommend that you carefully review the privacy policies of the tools used.

The providers also use cookies to store data on your user behavior regarding the map service. You can find more general information about cookies in our „Cookies“ section, but the privacy notices of the individual providers will also tell you which cookies may be used. However, this is usually just a non-exhaustive, representative list.

Right to object

You always have the possibility and also the right to access your personal data and to object to its use and processing. You can also revoke your consent at any time. As a rule, the easiest way to do this is via the cookie consent tool. However, there are also other opt-out tools that you can use. You can also manage, delete, or deactivate possible cookies set by the providers used with just a few clicks. However, it may then happen that some functions of the service no longer work as usual. How you manage cookies in your browser also depends on the browser you are using. In the „Cookies“ section you will also find links to the instructions for the most important browsers.

Legal basis

If you have consented to the use of an online mapping service, the legal basis for the corresponding data processing is this consent. Pursuant to Art. 6 (1) lit. a GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by an online mapping service.

We also have a legitimate interest in using an online mapping service to optimize our service on our website. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). However, we only ever use an online mapping service if you have given your consent. We want to emphasize this point once again.

Information on special online map services, if available, can be found in the following sections.

Google Maps Privacy Policy

Google Maps Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Processed data: Data such as entered search terms, your IP address, and also latitude and longitude coordinates.
You can find more details about this further down in this privacy policy.
📅 Retention period: depends on the data stored
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Google Maps?

We use Google Maps by Google Inc. on our website. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google Maps allows us to better display locations to you and thereby adapt our service to your needs. Through the use of Google Maps, data is transmitted to Google and stored on Google servers. Here, we want to go into more detail about what Google Maps is, why we use this Google service, what data is stored, and how you can prevent this.

Google Maps is an online mapping service provided by Google. With Google Maps, you can use a PC, tablet, or app to search online for precise locations of cities, landmarks, accommodations, or businesses. If businesses are present on Google My Business, additional information about the company is displayed alongside its location. To show how to get there, map sections of a location can be embedded into a website using HTML code. Google Maps displays the Earth's surface as a road map or as an aerial or satellite image. Thanks to Street View images and high-resolution satellite imagery, very detailed representations are possible.

Why do we use Google Maps on our website?

All of our efforts on this page are aimed at ensuring you have a useful and enjoyable experience on our website. By integrating Google Maps, we can provide you with key information about various locations. You can see at a glance where our headquarters are located. The directions always show you the best or fastest way to get here. You can view directions for traveling by car, public transportation, on foot, or by bike. For us, providing Google Maps is part of our customer service.

What data does Google Maps store?

In order for Google Maps to provide its full range of services, the company must collect and store data from you. This includes, among other things, the search terms you enter, your IP address, and your latitude and longitude coordinates. If you use the route planner feature, the starting address you enter is also stored. However, this data is stored on Google Maps’ websites. We can only inform you of this; we have no control over it. Since we have integrated Google Maps into our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google uses this data primarily to optimize its own services and to provide you with individualized, personalized advertising.

The following cookie is set in your browser due to the integration of Google Maps:

name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ322726102-5
Purpose: NID is used by Google to tailor ads to your Google searches. Using the cookie, Google „remembers“ your most frequently entered search queries or your previous interaction with ads. This ensures you always receive customized ads. The cookie contains a unique ID that Google uses to collect your personal settings for advertising purposes.
Expiration Date: after 6 months

Note: We cannot guarantee that the information regarding the stored data is complete. Changes can never be ruled out, particularly when using cookies. To identify the NID cookie, a separate test page was created that embedded only Google Maps.

How long and where is the data stored?

Google servers are located in data centers all over the world. However, most of the servers are in America. For this reason, your data is also increasingly stored in the USA. Here you can read in detail where the Google data centers are located: https://www.google.com/about/datacenters/locations/?hl=de

Google distributes the data across various storage media. As a result, the data can be retrieved faster and is better protected against any attempted tampering. Every data center also has special emergency procedures. For example, if there are problems with Google's hardware or a natural disaster paralyzes the servers, the data remains pretty securely protected anyway.

Google stores some data for a specified period of time. For other data, Google only offers the option to delete it manually. Furthermore, the company also anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months, respectively.

How can I delete my data or prevent data from being stored?

With the automatic deletion feature for location and activity data introduced in 2019, information on location tracking and web/app activity is stored for either 3 or 18 months—depending on your choice—and then deleted. In addition, this data can be manually deleted from the history at any time via your Google Account. If you want to completely prevent your location from being tracked, you must pause the „Web & App Activity“ section in your Google Account. Click „Data and personalization“ and then on the „Activity controls“ option. Here you can turn activities on or off.

You can also disable, delete, or manage individual cookies in your browser. The process varies slightly depending on which browser you use. Under the "Cookies" section, you’ll find links to the instructions for the most popular browsers.

If you generally do not want cookies, you can configure your browser so that it always informs you when a cookie is about to be set. This allows you to decide for each individual cookie whether you want to allow it or not.

Legal basis

If you have consented to the use of Google Maps, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as can occur with the use of Google Maps,.

Furthermore, we have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). Nevertheless, we only use Google Maps if you have given your consent.

Google also processes data from you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template models provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Google undertakes to maintain the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

If you would like to learn more about Google's data processing practices, we recommend reviewing the company's privacy policy at https://policies.google.com/privacy?hl=de.

Introduction to online booking systems

Privacy Policy Summary for Online Booking Systems
👥 Data subjects: Website visitors
🤝 Purpose: To improve the user experience and organization
📓 Processed Data: Which data is processed depends heavily on the services used. Usually, this involves IP addresses, contact and payment data, and/or technical data. You can find more details on this in the respective tools used.
📅 Storage period: depends on the tools used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is an online booking system?

We use one or more booking systems so that you can make reservations through our website. This makes it very easy to schedule appointments online. A booking system is a software application integrated into our website that displays available resources (such as open appointments) and allows you to book directly online and, in most cases, pay as well. You’re probably already familiar with such booking systems from the restaurant or hotel industries. However, such systems are now used in a wide variety of industries. Depending on the tool and settings, booking systems can be used both internally by us and by customers like you. In the process, personal data about you is generally collected and stored.

In most cases, the booking process works as follows: On our website, you’ll find the booking system where you can book an appointment for a service directly with a click of the mouse and by entering your information—and in most cases, you can pay right away. You may be able to enter various personal details using a form. Please be aware that all data you enter may be stored and managed in a database.

Why do we use an online booking system?

In a way, we also see our website as a complimentary service for you. You should receive helpful information and feel completely at ease on our site. This also includes an online service that makes booking appointments or services as easy as possible for you. Gone are the days when you had to wait for days for a booking confirmation via tedious phone calls or emails. With an online booking system, everything is done in just a few clicks and you can move on to other things. The system also makes managing all bookings and appointments easier for us. Therefore, we consider such a booking system to be completely sensible for both you and us.

What data is processed?

Of course, we cannot specify exactly which data is processed in this general information text about booking systems. This always depends on the tool used and the functions and capabilities it offers. In addition to the standard booking function, many booking systems also offer a range of other features. For example, many systems have an external online payment system (e.g., Stripe, Klarna, or PayPal) and a calendar synchronization feature integrated. Accordingly, depending on the features, different types and varying amounts of data may be processed. Typically, data such as your IP address, name, and contact information, as well as technical details about your device and the time of a booking, are processed. If you also make a payment through the system, banking information such as account numbers, credit card numbers, passwords, TANs, etc., is stored and shared with the respective payment provider. We recommend that you carefully read the privacy policy of the tool you are using so that you know exactly what data of yours is being processed.

Duration of data processing

Every booking system stores data for different periods of time. Therefore, we cannot yet provide specific details here about the duration of data processing. In principle, however, personal data is always stored only for as long as is strictly necessary to provide the services. Booking systems also generally use cookies that store information for varying lengths of time. Some cookies are deleted immediately after leaving the page, while others can be stored for several years. You can learn more about this in our „Cookies“ section. Please also review the respective privacy policies of the providers. These should explain how long your data will be stored in your specific case.

Right to object

If you have agreed to data processing by a booking system, you naturally always have the opportunity and the right to revoke this consent. Please always be aware that you have rights regarding your personal data and that you can also assert these rights at any time. If you do not want personal data to be processed, then no personal data may be processed either. It is as simple as that. The easiest way to revoke data processing is via a cookie consent tool or other offered opt-out functions. You can also manage data storage via cookies directly in your browser, for example. The legality of the data management remains unaffected until your revocation.

Legal basis

If you have consented to the use of booking systems, that consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur through booking systems.

Furthermore, we also have a legitimate interest in using booking systems, because on the one hand this allows us to expand our customer service and on the other hand to optimize our internal booking organization. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). Nevertheless, we only use these tools to the extent that you have given your consent. We definitely want to emphasize this again at this point.

Information on specific booking systems—if available—can be found in the following sections.

Introduction to other services

Other Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Improving the user experience
📓 Processed Data: Which data is processed depends heavily on the services used. In most cases, this involves IP addresses and/or technical data. You can find more details in the respective tools used.
📅 Storage period: depends on the tools used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What falls under „Miscellaneous“?

The „Other“ category includes those services that do not fit into any of the categories mentioned above. These are generally various plugins and embedded elements that improve our website. As a rule, these functions are obtained from third-party providers and integrated into our website. Examples include web search services such as Algolia Place, Giphy, Programmable Search Engine, or online weather data services such as OpenWeather.

Why are we using other third-party providers?

With our website, we aim to offer you the best online presence in our industry. For a long time now, a website has been much more than just a digital business card for companies. Rather, it is a place designed to help you find what you are looking for. To ensure we continually make our website even more engaging and helpful for you, we use various third-party services.

What data is processed?

Whenever elements are integrated into our website, your IP address is transmitted to the respective provider, stored, and processed there. This is necessary because otherwise the content cannot be sent to your browser and consequently cannot be displayed accordingly. It can also happen that service providers use pixel tags or web beacons. These are small graphics on websites that can record a log file and also create analyses of this file. With the information obtained, providers can improve their own marketing activities. In addition to pixel tags, such information (such as which button you click or when you visit which page) can also be stored in cookies. In addition to analysis data on your web behavior, technical information such as your browser type or your operating system can also be stored in them. Some providers can also link the data obtained with other internal services or with third-party providers. Each provider handles your data differently. Therefore, we recommend that you carefully read the privacy policies of the respective services. We generally strive to use only services that handle the topic of data privacy very carefully.

Duration of data processing

We will inform you about the duration of the data processing below, provided we have further information on the matter. Generally, we only process personal data for as long as it is strictly necessary for the provision of our services and products.

Legal basis

If we ask for your consent and you also consent to our use of the service, this serves as the legal basis for processing your data (Art. 6 (1) lit. a GDPR). In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our offering from both a technical and economic perspective. The legal basis for this is Art. 6 (1) lit. f GDPR (Legitimate Interests). However, we only use these tools to the extent that you have given your consent.

Information on the special tools can be found – if available – in the following sections.

DATEV Privacy Policy

We use the accounting software DATEV for our website. The service provider is the German company DATEV eG, Paumgartnerstr. 6 – 14, 90429 Nuremberg, Germany.

For more information about the data processed when using DATEV, please see the privacy policy at https://www.datev.de/web/de/m/ueber-datev/datenschutz/.

GetMyInvoices Privacy Policy

We use the invoice management software GetMyInvoices for our website. The service provider is the German company fino data services GmbH, Universitätsplatz 12, 34127 Kassel, Germany.

You can learn more about the data processed through the use of GetMyInvoices in the privacy policy at https://www.getmyinvoices.com/de/datenschutz.

Explanation of the terms used

We always strive to make our privacy policy as clear and understandable as possible. However, this isn’t always easy, especially when it comes to technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or certain technical terms (such as “cookies” or “IP address”). However, we do not want to use these terms without explanation. Below you will find an alphabetical list of important terms we use that we may not have addressed sufficiently in the privacy policy so far. If these terms are taken from the GDPR and are definitions, we will also cite the relevant GDPR text here and, where appropriate, add our own explanations.

Regulatory Authority

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Regulatory Authority“ an independent public body established by a Member State pursuant to Article 51;

Explanation: “Supervisory authorities” are always independent government agencies that, in certain cases, also have the authority to issue directives. They are responsible for carrying out what is known as “state supervision” and are housed within ministries, special departments, or other government agencies. In Austria, there is an Austrian Data Protection Authority, In Germany, each federal state has its own data protection authority.

Data Processor

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"Data Processor"“ a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;

Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. Consequently, data processors can include not only service providers such as tax advisors, but also hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

Relevant Regulatory Authority

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„concerned supervisory authority“ a supervisory authority that is affected by the processing of personal data because

a)

the controller or the processor is established within the territory of the Member State of that supervisory authority,

b)

this processing has or may have a significant impact on data subjects residing in the Member State of this supervisory authority, or

c)

a complaint has been lodged with this supervisory authority;

Explanation: In Germany, each federal state has its own data protection supervisory authority. So if your company’s headquarters (main office) is located in Germany, the supervisory authority for that federal state is generally your point of contact. In Austria, there is only one supervisory authority for the entire country Data Protection Supervisory Authority.

File System

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"File System"“ any structured collection of personal data that is accessible according to specific criteria, regardless of whether that collection is managed centrally, decentrally, or organized according to functional or geographic criteria;

Explanation: Any organized storage of data on a computer’s storage medium is referred to as a “file system.” For example, when we store your name and email address on a server for our newsletter, that data is located in what is known as a “file system.” Among the most important functions of a “file system” are the ability to quickly search for and locate specific data and, of course, the secure storage of that data.

Information Society Service

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"Information Society Service"“ a service within the meaning of Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council (19);

Explanation: Generally speaking, the term “information society” refers to a society that relies on information and communication technologies. As a website visitor in particular, you are familiar with a wide variety of online services, and most online services fall under the category of “information society services.” A classic example of this is an online transaction, such as purchasing goods over the Internet.

Third

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Third“ a natural or legal person, public authority, agency or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data;

Explanation: The GDPR essentially only explains here what a „third party” is not. In practice, anyone who is also interested in the personal data, but does not belong to the aforementioned persons, authorities, or bodies, is a „third party.” For example, a parent company can act as a „third party.” In this case, the subsidiary is the controller and the parent company is the „third party.” However, this does not mean that the parent company is automatically permitted to view, collect, or store the personal data of the subsidiary.

Restriction of processing

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Restriction of processing“ the marking of stored personal data with the aim of limiting their future processing;

Explanation: It is your right to request from processors at any time that your personal data be restricted for further processing operations. For this purpose, special personal data such as your name, your date of birth, or your address are marked in such a way that complete further processing is no longer possible. For example, you could restrict processing so that your data may no longer be used for personalized advertising.

Consent

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Consent“ any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her;

Explanation: Typically, such consent on websites is obtained via a cookie consent tool. You are certainly familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data of yours may be processed either. In principle, consent can of course also be given in writing, i.e., not via a tool.

Recipient

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"Recipient"“ a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

Explanation: Any individual or company that receives personal data is considered a recipient. Therefore, we and our processors are also considered recipients. Only government agencies conducting an investigation are not considered recipients.

Headquarters

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"Headquarters"“

a)

in the case of a controller with establishments in more than one Member State, the location of its central administration within the Union, unless decisions regarding the purposes and means of processing personal data are made at another establishment of the controller within the Union and that establishment is authorized to have those decisions implemented; in that case, the establishment that makes such decisions shall be considered the principal establishment;

b)

in the case of a data processor with establishments in more than one Member State, the location of its principal place of business in the Union or, if the data processor does not have a principal place of business in the Union, the establishment of the processor in the Union where the processing activities in the context of the operations of an establishment of the processor are mainly carried out, to the extent that the processor is subject to specific obligations under this Regulation;

Explanation: Google, for example, is an American company that also processes data in the United States, but its European headquarters is located in Ireland (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Thus, from a legal standpoint, Google Ireland Limited is an independent entity and is responsible for all Google products offered in the European Economic Area. In contrast to a head office, there are also branch offices; however, these do not function as legally independent entities and must therefore be distinguished from subsidiaries. A head office is thus, in principle, always the location where a company (business entity) has its center of operations.

International organization

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"international organization"“An international organization and its subordinate bodies, or any other entity established by or pursuant to an agreement concluded between two or more countries.”.

Explanation: The best-known examples of international organizations are probably the European Union or the United Nations. In the GDPR, a distinction is made in connection with data transfer between third countries and international organizations. Within the EU, the transfer of personal data does not pose a problem because all EU countries are bound by the regulations of the GDPR. In contrast, data transfer with third countries or international organizations is subject to certain conditions.

A valid and well-founded objection

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„substantive and well-founded objection“ an objection to a draft decision regarding whether there has been a violation of this Regulation or whether proposed measures against the controller or the processor are in accordance with this Regulation, provided that such an objection clearly sets out the scope of the risks posed by the draft decision to the fundamental rights and freedoms of the data subjects and, where applicable, to the free flow of personal data within the Union;

Explanation: If certain measures taken by us as the data controller or by our data processors are not in compliance with the GDPR, you may file what is known as a „substantial and justified objection.“ In doing so, you must explain the scope of the risks with regard to your fundamental rights and freedoms and, where applicable, the free movement of your personal data within the EU.

Personal data

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„personal data“ any information relating to an identified or identifiable natural person (hereinafter referred to as the „data subject“); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;

Explanation: Personal data, therefore, refers to any data that can be used to identify you as an individual. This typically includes data such as:

  • name
  • Address
  • Email address
  • Mailing Address
  • Telephone number
  • Date of birth
  • Identification numbers such as Social Security number, tax identification number, ID card number, or student ID number
  • Banking information such as account numbers, credit information, account balances, and much more.

According to the European Court of Justice (ECJ), your IP Address and Personal Data. IT experts can use your IP address to determine at least the approximate location of your device and, by extension, identify you as the account holder. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called „"special categories"“ personal data that is also considered to require special protection. This includes:

  • Racial and Ethnic Origin
  • political views
  • religious or ideological beliefs
  • union membership
  • genetic data, such as data obtained from blood or saliva samples
  • biometric data (information about psychological, physical, or behavioral characteristics that can identify a person).
    Health Data
  • Data on sexual orientation or sex life

Company

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„"Company"“ a natural and legal person engaging in an economic activity, regardless of its legal form, including partnerships or associations regularly engaged in an economic activity;

Explanation: For example, we are a company and also carry out an economic activity via our website by offering and selling services and/or products. For every company, a formal characteristic is its legal entity status, such as a GmbH (LLC) or an AG (corporation).

Corporate group

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Corporate group“ a group consisting of a controlling company and the companies dependent on it;

Explanation: One therefore speaks of a “corporate group” when several companies unite, are in a legal and financial relationship with one another, but there is still a central, overarching company. For example, Instagram, WhatsApp, Oculus VR, or Facebook are largely independent companies, but are all subject to the parent company Meta Platforms, Inc.

Controller

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Controller“ the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

Explanation: In our case, we are responsible for the processing of your personal data and, consequently, the “controller”. If we pass on collected data to other service providers for processing, they are “processors”. For this purpose, a “data processing agreement (DPA)” must be signed.

Processing

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Processing“ any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

Note: When we refer to processing in our privacy policy, we mean any kind of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.

Binding corporate rules

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„binding internal data protection rules“ Measures to protect personal data by which a controller or processor established in the territory of a Member State undertakes, with regard to transfers or a category of transfers of personal data to a controller or processor in one or more third countries, within the same corporate group or group of undertakings engaged in a joint economic activity, to comply;

Explanation: Perhaps you have heard or read the term “Binding Corporate Rules” quite often. Because that is the term that usually appears when it comes to binding internal data protection regulations. Especially for companies (such as Google) that process data in third countries, such an internal regulation is recommended, through which a company, so to speak, commits itself to complying with data protection regulations. This regulation governs the handling of personal data that is transferred to third countries and also processed there.

Personal data breach

Definition pursuant to Article 4 of the GDPR

For the purposes of this regulation, the term means:

„Personal data breach“ a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;

Explanation: For example, a „personal data breach” can occur in the event of a data leak, i.e., a technical problem or a cyber attack. If the breach results in a risk to the rights and freedoms of natural persons, the controller must report the incident to the competent supervisory authority without undue delay. In addition, the data subjects must also be informed if the breach poses a high risk to the rights and freedoms of natural persons.

Closing remarks

Congratulations! If you are reading these lines, you have truly „fought“ your way through our entire privacy policy, or at least scrolled down to this point. As you can see from the scope of our privacy policy, we take the protection of your personal data anything but lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we not only want to tell you which data is processed, but also give you a closer look at the motives for using various software programs. As a rule, privacy policies sound very technical and legal. However, since most of you are neither web developers nor lawyers, we wanted to take a different linguistic approach and explain the facts in simple and clear language. Of course, this is not always possible due to the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the responsible party. We hope you enjoy the rest of your day and look forward to welcoming you back to our website soon.

All texts are protected by copyright.

Source: Created with Privacy Policy Generator Germany from AdSimple