Privacy policy
Please note: The following is a translation provided for your convenience. Only the German version of this document is legally binding.
Preamble
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to in short as "data") we process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as, for example, our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: 17 January 2024
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Transmission of Personal Data
- International Data Transfers
- Deletion of Data
- Rights of Data Subjects
- Use of Cookies
- Business Services
- Use of Online Platforms for Offering and Sales Purposes
- Providers and Services Used in the Course of Business Operations
- Payment Procedures
- Provision of the Online Offering and Web Hosting
- Blogs and Publication Media
- Contact and Inquiry Management
- Communication via Messenger
- Chatbots and Chat Functions
- Newsletter and Electronic Notifications
- Advertising Communication via Email, Post, Fax or Telephone
- Sweepstakes and Competitions
- Surveys and Polls
- Web Analytics, Monitoring and Optimization
- Online Marketing
- Affiliate Programs and Affiliate Links
- Provision of an Affiliate Program
- Customer Reviews and Rating Procedures
- Presence on Social Networks (Social Media)
- Plugins and Embedded Functions and Content
- Management, Organization and Auxiliary Tools
- Amendment and Update of the Privacy Policy
- Definitions of Terms
Controller
Saad-Julian Wohlgenannt
Bergstraße 80
10115 Berlin
Email address: saad@dental-armor.com Legal notice (Impressum): https://dental-armor.com/policies/contact-information
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Categories of Data Processed
- Inventory data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Event data (Facebook).
Categories of Data Subjects
- Customers.
- Prospective customers.
- Communication partners.
- Users.
- Sweepstakes and competition participants.
- Business and contractual partners.
- Participants.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Contact requests and communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organizational procedures.
- Conversion measurement.
- Affiliate tracking.
- Management and response to inquiries.
- Conducting sweepstakes and competitions.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours of residence or registered office. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(1)(a) GDPR) - The data subject has given their consent to the processing of personal data relating to them for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes, in particular, the Act to Adapt Data Protection Law to Regulation (EU) 2016/679 and to Implement Directive (EU) 2016/680 (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Security Measures
In accordance with statutory requirements, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, transfer, ensuring the availability of and separation of the data. We have also established procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to any compromise of data. Furthermore, we take the protection of personal data into account as early as the development and selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and through data-protection-friendly default settings.
TLS/SSL encryption (https): In order to protect the data of users transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting the data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.
Transmission of Personal Data
In the course of our processing of personal data, it may occur that data is transmitted to, or disclosed to, other bodies, companies, legally independent organizational units or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude corresponding contracts or agreements serving to protect your data with the recipients of your data.
International Data Transfers
Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transmitting data to other persons, bodies or companies, this only takes place in accordance with statutory requirements. Where the level of data protection in the third country has been recognized by way of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise assured, in particular through standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or in the case of a contractually or legally required transfer (Art. 49(1) GDPR). In addition, we will inform you of the basis for third-country transfers with respect to the individual providers from the third country, whereby adequacy decisions take precedence as the basis. Information on third-country transfers and existing adequacy decisions can be found on the website of the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
EU-US Trans-Atlantic Data Privacy Framework: Within the framework of the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognized the level of data protection as adequate for certain companies from the USA, by way of the adequacy decision dated 10 July 2023. The list of certified companies as well as further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). We will inform you within the scope of the privacy notices which of the service providers we use are certified under the Data Privacy Framework.
Deletion of Data
The data processed by us will be deleted in accordance with statutory requirements as soon as the consents permitting their processing are revoked or other permissions cease to apply (e.g., if the purpose for processing this data no longer applies, or the data is not required for this purpose). If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to those purposes. That is, the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or the storage of which is necessary for the assertion, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person. Our privacy notices may also contain further information on the retention and deletion of data that takes precedence for the respective processing operations.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling, to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right of access: You have the right to request confirmation as to whether relevant data is being processed, and to information about this data as well as further information and a copy of the data, in accordance with statutory requirements.
- Right to rectification: In accordance with statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with statutory requirements, you have the right to demand that data concerning you be deleted without delay, or, alternatively, to demand a restriction of the processing of the data in accordance with statutory requirements.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with statutory requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you believe that the processing of personal data concerning you infringes the requirements of the GDPR.
Use of Cookies
Cookies are small text files, or other means of storing information, that store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping cart in an e-shop, the content accessed or the functions used in an online offering. Cookies may also be used for various purposes, e.g., for the purposes of the functionality, security and convenience of online offerings, as well as for creating analyses of visitor flows.
Notes on consent: We use cookies in accordance with statutory provisions. We therefore obtain prior consent from users, except where such consent is not required by law. Consent is not required in particular if the storage and reading of information, including cookies, is strictly necessary in order to provide users with a telemedia service they have explicitly requested (i.e., our online offering). Strictly necessary cookies generally include cookies with functions serving the display and functioning of the online offering, load balancing, security, the storage of user preferences and options, or similar purposes related to the provision of the main and secondary functions of the online offering requested by users. Revocable consent is clearly communicated to users and includes information on the respective use of cookies.
Notes on legal bases under data protection law: The legal basis under data protection law on which we process the personal data of users with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing your data is the consent given. Otherwise, data processed using cookies is processed on the basis of our legitimate interests (e.g., in the efficient business operation of our online offering and improvement of its usability), or, if this occurs in the course of fulfilling our contractual obligations, if the use of cookies is necessary to fulfill our contractual obligations. We explain the purposes for which we process cookies in the course of this privacy policy or in the course of our consent and processing procedures.
Storage period: With regard to storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their end device (e.g., browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved, or preferred content can be displayed directly when the user visits a website again. Likewise, data collected by means of cookies from users may be used for reach measurement. Unless we provide users with explicit information on the type and storage period of cookies (e.g., in the course of obtaining consent), users should assume that cookies are permanent and that the storage period may be up to two years.
General notes on withdrawal and objection (so-called "opt-out"): Users can withdraw any consent given at any time and object to processing in accordance with statutory requirements. To do so, users can, among other things, restrict the use of cookies in their browser settings (whereby this may also restrict the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a cookie consent management procedure, within the framework of which the consents of users to the use of cookies, or to the processing operations and providers named within the cookie consent management procedure, are obtained and can be managed and withdrawn by users. In this context, the consent declaration is stored so that it does not have to be requested again and so that consent can be proven in accordance with the legal obligation. Storage may take place server-side and/or in a cookie (so-called opt-in cookie, or by means of comparable technologies) in order to be able to associate the consent with a user or their device. Subject to individual information on the providers of cookie management services, the following information applies: The duration of storage of consent may be up to two years. In this context, a pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (e.g., which categories of cookies and/or service providers) as well as the browser, system and end device used; Legal bases: Consent (Art. 6(1)(1)(a) GDPR).
Business Services
We process the data of our contractual and business partners, e.g., customers and prospective customers (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships as well as associated measures and in the context of communication with contractual partners (or pre-contractually), e.g., in order to respond to inquiries.
We process this data in order to fulfill our contractual obligations. These include, in particular, the obligations to provide the agreed services, any update obligations, and remedies in the event of warranty and other performance disruptions. In addition, we process the data to safeguard our rights and for the purpose of administrative tasks associated with these obligations, as well as for corporate organization. Furthermore, we process the data on the basis of our legitimate interests in proper and efficient business management as well as in security measures to protect our contractual partners and our business operations against misuse, endangerment of their data, secrets, information and rights (e.g., for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the scope of applicable law, we only disclose the data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed of any further forms of processing, e.g., for marketing purposes, within the framework of this privacy policy.
We inform contractual partners which data is required for the aforementioned purposes prior to or in the course of data collection, e.g., in online forms, by way of special marking (e.g., colors) or symbols (e.g., asterisks or similar), or in person.
We delete the data upon expiry of statutory warranty and comparable obligations, i.e., in principle after expiry of 4 years, unless the data is stored in a customer account, e.g., for as long as it must be retained for legal archiving reasons. The statutory retention period for documents relevant under tax law as well as for commercial books, inventories, opening balance sheets, annual financial statements, the work instructions and other organizational documents required for understanding these documents, and accounting vouchers, is ten years, and for received commercial and business letters and copies of commercial and business letters sent, six years. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statement or the management report was prepared, the commercial or business letter was received or sent, or the accounting voucher arose, or the record was made or the other documents arose.
Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply as between users and the providers.
- Categories of data processed: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email, telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Customers; prospective customers. Business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; contact requests and communication; office and organizational procedures. Management and response to inquiries.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Online shop, order forms, e-commerce and delivery: We process the data of our customers in order to enable them to select, acquire, or order the chosen products, goods and associated services, as well as their payment and delivery, or performance. Insofar as necessary for the execution of an order, we use service providers, in particular postal, freight and shipping companies, in order to carry out delivery or performance vis-à-vis our customers. We use the services of banks and payment service providers to process payment transactions. The information required is marked as such in the course of the ordering process or comparable acquisition process, and includes the information required for delivery, or provision, and billing, as well as contact information in order to be able to make any necessary inquiries; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).
Use of Online Platforms for Offering and Sales Purposes
We offer our services on online platforms operated by other service providers. In this context, the privacy notices of the respective platforms apply in addition to our privacy notices. This applies in particular with regard to the execution of the payment process and the procedures used on the platforms for reach measurement and interest-based marketing.
- Categories of data processed: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email, telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Customers.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Marketing.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Shopify: Platform through which e-commerce services are offered and carried out. The services and the processes carried out in connection with them include in particular online shops, websites, their offers and content, community elements, purchasing and payment processes, customer communication as well as analysis and marketing; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website: https://www.shopify.com/de/. Privacy policy: https://www.shopify.com/de/legal/datenschutz.
Providers and services used in the course of business operations
In the course of our business activities, and in compliance with the statutory requirements, we use additional services, platforms, interfaces or plug-ins provided by third parties (in short, "services"). Their use is based on our interests in a proper, lawful and - -
- Categories of data processed: Basic data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history - - ); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category - - ).
- Data subjects: Customers; prospective customers; users (e.g. website visitors, users of - - ). Business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Office and organizational procedures.
- Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Payment procedures
In the context of contractual and other legal relationships, on the basis of statutory obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, use banks and credit institutions as well as other service providers (collectively, "payment service providers").
The data processed by the payment service providers include basic data, such as name and address, bank details, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract-, amount- and recipient-related information. This information is required in order to carry out the transactions. However, the data entered is processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or denying payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit reporting agencies. This transmission is intended for the purpose of identity and creditworthiness checks. In this regard, we refer to the terms and conditions and the privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers apply to the payment transactions, and these can be accessed within the respective websites or transaction applications. We also refer to these for the purpose of further information and the assertion of rights of withdrawal, information and other data subject rights.
- Categories of data processed: Basic data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms).
- Data subjects: Customers; prospective customers; users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; feedback (e.g. collecting feedback via online form).
- Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR).
Additional information on processing activities, procedures and services:
- Amazon Payments: Payment services (technical integration of online payment methods); Service provider: Amazon Payments Europe S.C.A. 38 avenue J.F. Kennedy, L-1855 Luxembourg; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://pay.amazon.de/. Privacy policy: https://pay.amazon.de/help/201212490.
- American Express: Payment services (technical integration of online payment methods); Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.americanexpress.com/de/. Privacy policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
- Apple Pay: Payment services (technical integration of online payment methods); Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
- Flattr: Flattr - online payment and donation service; Service provider: Flattr AB, Box 4111, 203 12 Malmö, Sweden; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://flattr.com/. Privacy policy: https://flattr.com/privacy.
- Giropay: Payment services (technical integration of online payment methods); Service provider: giropay GmbH, An der Welle 4, 60322 Frankfurt, Germany; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.giropay.de. Privacy policy: https://www.giropay.de/rechtliches/datenschutzerklaerung/.
- Google Pay: Payment services (technical integration of online payment methods); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://policies.google.com/privacy.
- Klarna: Payment services (technical integration of online payment methods); Service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.klarna.com/de. Privacy policy: https://www.klarna.com/de/datenschutz.
- Mastercard: Payment services (technical integration of online payment methods); Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.mastercard.de/de-de.html. Privacy policy: https://www.mastercard.de/de-de/datenschutz.html.
- PayPal: Payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
- Stripe: Payment services (technical integration of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://stripe.com; Privacy policy: https://stripe.com/de/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
- Visa: Payment services (technical integration of online payment methods); Service provider: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, GB; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR); Website: https://www.visa.de. Privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
Provision of the online offering and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or end device.
- Categories of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status); content data (e.g. entries in online forms).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Additional information on processing activities, procedures and services:
- Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from an appropriate server provider (also referred to as a "web hoster"); Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the event of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure the utilization of the servers and their stability; Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR). Deletion of data: Log file information is stored for a maximum period of 30 days and then deleted or anonymized. Data whose further storage is required for evidentiary purposes shall be excluded from deletion until the respective incident has been finally clarified.
- Email sending and hosting: The web hosting services we use also include the sending, receiving and storage of emails. For these purposes, the addresses of the recipients and senders, as well as other information relating to the sending of emails (e.g. the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent in encrypted form on the internet. As a rule, emails are encrypted during transmission, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We can therefore not accept any responsibility for the transmission path of the emails between the sender and receipt on our server; Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Content delivery network: We use a "content delivery network" (CDN). A CDN is a service that helps deliver the content of an online offering, in particular large media files such as graphics or program scripts, more quickly and securely with the help of regionally distributed servers connected via the internet; Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Blogs and publication media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). The readers' data is processed for the purposes of the publication medium only to the extent necessary for its presentation and the communication between authors and readers, or for security reasons. Otherwise, we refer to the information on the processing of the data of visitors to our publication medium contained within this privacy policy.
- Categories of data processed: Basic data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Contact and inquiry management
When contacting us (e.g. by mail, contact form, email, telephone or via social media) as well as in the context of existing user and business relationships, the information provided by the persons making inquiries is processed to the extent necessary to respond to the contact inquiries and any requested measures.
- Categories of data processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status).
- Data subjects: Communication partners.
- Purposes of processing: Contact inquiries and communication; management and response to inquiries; feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Legal basis: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR).
Additional information on processing activities, procedures and services:
- Contact form: If users contact us via our contact form, email or other means of communication, we process the data communicated to us in this context in order to process the matter communicated; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR), legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Communication via messenger
We use messenger services for communication purposes and therefore ask you to observe the following information regarding the functionality of the messenger services, encryption, the use of communication metadata, and your options for objection.
You may also contact us via alternative means, e.g. by telephone or email. Please use the contact options provided to you or the contact options specified within our online offering.
In the case of end-to-end encryption of content (i.e. the content of your message and attachments), we point out that the communication content (i.e. the content of the message and attached images) is end-to-end encrypted. This means that the content of the messages is not visible, not even to the messenger providers themselves. You should always use an up-to-date version of the messenger services with encryption enabled in order to ensure that the message content is encrypted.
However, we would like to additionally point out to our communication partners that although the messenger providers do not view the content, they may find out that and when communication partners are communicating with us, as well as technical information about the device used by the communication partners and, depending on their device settings, location information (so-called metadata) may be processed.
Notes on legal basis: If we ask communication partners for permission before communicating with them via a messenger service, the legal basis for our processing of their data is their consent. Otherwise, if we do not ask for consent and, for example, they contact us on their own initiative, we use messenger services in relation to our contractual partners and in the context of contract initiation as a contractual measure, and in the case of other prospective customers and communication partners on the basis of our legitimate interests in fast and efficient communication and fulfilling the needs of our communication partners for communication via messenger services. We further point out that we will not transmit the contact data communicated to us to the messenger services for the first time without your consent.
Withdrawal, objection and deletion: You can withdraw a given consent at any time and - -
- Categories of data processed: Contact data (e.g. email, telephone numbers); usage data (e.g. websites visited, interest in content, - - ); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, - - ).
- Data subjects: Communication partners.
- Purposes of processing: Contact inquiries and communication; direct marketing (e.g. by email or post).
- Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Chatbots and chat functions
We offer online chats and chatbot functions as a means of communication (together referred to as "chat services"). A chat is an online conversation conducted in a certain temporal proximity. A chatbot is software that answers user questions or informs them via messages. If you use our chat functions, we may process your personal data.
If you use our chat services within an online platform, your identification number within the respective platform is also stored. We may also collect information about which users interact with our chat services and when. We also store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove them in accordance with statutory requirements.
We point out to users that the respective platform provider can find out that and when users communicate with our chat services, as well as collect technical information about the device used by the users and, depending on their device settings, also location information (so-called metadata), for the purposes of optimizing the respective services and for security purposes. The metadata of communication via chat services (i.e. e.g. the information about who communicated with whom) could also be used by the respective platform providers, in accordance with their provisions, to which we refer for further information, for marketing purposes or to display advertising tailored to users.
If users declare their willingness to a chatbot to activate information via regular messages, they have the option at any time to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. When unsubscribing from the chatbot messages, users' data is deleted from the list of message recipients.
We use the aforementioned information to operate our chat services, e.g. to address users personally, to answer their inquiries, to transmit any requested content, and also to improve our chat services (e.g. to "teach" chatbots answers to frequently asked questions - -
- Categories of data processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, - - ); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, - - ).
- Data subjects: Communication partners.
- Purposes of processing: Contact inquiries and communication; direct marketing (e.g. by email or post).
- Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); contract performance and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications (hereinafter "newsletter") only with the consent of the recipients or a statutory permission. Insofar as the content of the newsletter is specifically described within the scope of a registration for the newsletter, it shall be decisive for the users' consent. Otherwise, our newsletters contain information about our services and about us.
In order to register for our newsletters, it is generally sufficient for you to provide your email address. However, we may ask you to provide a name, for the purpose of personal address in the newsletter, or other information, insofar as this is necessary for the purposes of the newsletter.
Double opt-in procedure: Registration for our newsletter is generally carried out using a so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary so that no one can register using third-party email addresses. Newsletter registrations are logged in order to be able to prove the registration process in accordance with legal requirements. This includes the storage of the registration and confirmation time, as well as the IP address. Changes to your data stored with the shipping service provider are also logged.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove consent previously given. The processing of this data is limited to the purpose of a possible defense against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time. In the event of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist.
The logging of the registration procedure is carried out on the basis of our legitimate interests for the purpose of proving its proper execution. Insofar as we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.
Content:
Information about us, our services, promotions and offers.
- Categories of data processed: Basic data (e.g. names, addresses); contact data (e.g. email, telephone numbers); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by email or post).
- Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR).
- Option to object (opt-out): You can cancel the receipt of our newsletter at any time, i.e. withdraw your consent, or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter, or you can otherwise use one of the contact options listed above, preferably email.
Promotional communication via email, post, fax or telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post or fax, in accordance with statutory requirements.
Recipients have the right to withdraw consent given at any time, or to object to promotional communication at any time.
After withdrawal or objection, we store the data required to prove prior authorization for contacting or sending, for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing users' withdrawal or objection, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).
- Categories of data processed: Basic data (e.g. names, addresses); contact data (e.g. email, telephone numbers).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by email or post).
- Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Prize draws and competitions
We process the personal data of participants in prize draws and competitions only in compliance with the relevant data protection provisions, insofar as the processing is contractually necessary for the provision, conduct and handling of the prize draw, the participants have consented to the processing, or the processing serves our legitimate interests (e.g. in the security of the prize draw or the protection of our interests against misuse through the possible collection of IP addresses when submitting prize draw entries).
If entries by participants are published as part of the prize draws (e.g. as part of a vote or presentation of the prize draw entries or the winners, or reporting on the prize draw), we point out that the names of the participants may also be published in this context. Participants may object to this at any time.
If the prize draw takes place within an online platform or a social network (e.g. Facebook or Instagram, hereinafter referred to as "online platform"), the terms of use and privacy policies of the respective platforms shall additionally apply. In these cases, we would like to point out that we are responsible for the information provided by participants in connection with the prize draw and that inquiries regarding the prize draw should be directed to us.
The data of participants is deleted as soon as the prize draw or competition has ended and the data is no longer required to inform the winners or because no further inquiries regarding the prize draw are to be expected. As a general rule, the data of participants is deleted at the latest 6 months after the end of the prize draw. Data of winners may be retained for longer, e.g. in order to answer queries regarding the prizes or to fulfil the prize benefits; in this case, the retention period depends on the nature of the prize and, for example, is up to three years for goods or services, in order to be able to process warranty claims. Furthermore, the data of participants may be stored for longer, e.g. in the form of reporting on the prize draw in online and offline media.
If data was also collected for other purposes within the framework of the prize draw, its processing and the retention period are governed by the privacy notices relating to that use (e.g. in the case of a newsletter subscription in connection with a prize draw).
- Categories of data processed: Master data (e.g. names, addresses); Content data (e.g. entries in online forms); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Prize draw and competition participants.
- Purposes of processing: Conducting prize draws and competitions.
- Legal basis: Performance of contract and pre-contractual inquiries (Art. 6 (1) p. 1 lit. b) GDPR).
Surveys and questionnaires
We conduct surveys and questionnaires in order to gather information for the respective communicated survey or questionnaire purpose. The surveys and questionnaires we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is only processed to the extent necessary for the provision and technical implementation of the surveys (e.g. processing of the IP address in order to display the survey in the user's browser or to enable the survey to be resumed using a cookie).
- Categories of data processed: Contact data (e.g. email, telephone numbers); Content data (e.g. entries in online forms); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Communication partners. Participants.
- Purposes of processing: Feedback (e.g. collecting feedback via an online form).
- Legal basis: Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Google Forms: Creation and evaluation of online forms, surveys, feedback forms, etc.; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR); Website: https://www.google.de/intl/de/forms; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause).
Web analytics, monitoring and optimization
Web analytics (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and may include behavioral, interest-related or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, determine at which times our online offering or its functions or content are most frequently used or invite reuse. We can likewise identify which areas require optimization.
In addition to web analytics, we may also use testing procedures, e.g. to test and optimize different versions of our online offering or its components.
Unless stated otherwise below, profiles, i.e. data compiled in relation to a usage process, may be created for these purposes and information may be stored in and retrieved from a browser or a terminal device. The data collected includes, in particular, the websites visited and the elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data vis-à-vis us or vis-à-vis the providers of the services we use, location data may also be processed.
The IP addresses of users are likewise stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. In general, no plain-text user data (such as email addresses or names) is stored within the framework of web analytics, A/B testing and optimization; instead, pseudonyms are stored. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
- Categories of data processed: Usage data (e.g. websites visited, interest in content, access times); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); Profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
- Security measures: IP masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR).
Further information on processing operations, procedures and services:
- Google Analytics 4: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to associate analytics information with a terminal device in order to identify which content users have accessed within one or several usage processes, which search terms they have used, whether they have accessed the content again or interacted with our online offering. The time of use and its duration are likewise stored, as well as the sources of users referring to our online offering and technical aspects of their terminal devices and browsers. In doing so, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics does provide coarse geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, sub-continent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible and is not used for any further purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed).
-
Google Tag Manager: Google Tag Manager is a solution that allows us to manage so-called website tags via a single interface and thereby integrate other services into our online offering (for details, please refer to the further information provided elsewhere in this privacy policy). The Tag Manager itself (which implements the tags) therefore does not, for example, create user profiles or store cookies. Google only learns the user's IP address, which is necessary in order to run Google Tag Manager; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement:
https://business.safety.google/adsprocessorterms. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms).
Online marketing
We process personal data for online marketing purposes, which may in particular include the marketing of advertising space or the display of promotional and other content (collectively referred to as "content") based on the potential interests of users, as well as the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called "cookie"), or similar procedures are used by means of which information about the user relevant to the display of the aforementioned content is stored. Such information may include, in particular, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used, and information on usage times and functions used. If users have consented to the collection of their location data, this data may also be processed.
The IP addresses of users are likewise stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect users. In general, no plain-text user data (such as email addresses or names) is stored within the framework of the online marketing procedures; instead, pseudonyms are stored. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is generally stored in the cookies or by means of similar procedures. Such cookies may later generally also be read on other websites that use the same online marketing procedure and analyzed for the purpose of displaying content, as well as supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases, plain-text data can be assigned to the profiles. This is the case, for example, if users are members of a social network whose online marketing procedure we use and the network links the users' profiles with the aforementioned information. We ask that you note that users may enter into additional agreements with the providers, e.g. by giving consent during registration.
As a general rule, we only have access to aggregated information about the success of our advertisements. However, within the framework of so-called conversion measurement, we can determine which of our online marketing procedures have led to a so-called conversion, i.e., for example, to the conclusion of a contract with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless stated otherwise, please assume that cookies used are stored for a period of two years.
- Categories of data processed: Usage data (e.g. websites visited, interest in content, access times); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); Tracking (e.g. interest/behavior-based profiling, use of cookies); Marketing; Profiles with user-related information (creation of user profiles). Conversion measurement (measurement of the effectiveness of marketing measures).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR).
-
Opt-out option: We refer to the privacy notices of the respective providers and the opt-out options indicated for the providers (so-called "opt-out"). If no explicit opt-out option has been provided, you have the option of disabling cookies in your browser settings. However, this may restrict the functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for the respective regions:
a) Europe: https://www.youronlinechoices.eu.
b) Canada: https://www.youradchoices.ca/choices.
c) USA: https://www.aboutads.info/choices.
d) Cross-region: https://optout.aboutads.info.
Further information on processing operations, procedures and services:
- Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who are presumed to have an interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether users took the advertisements as an occasion to interact with them and make use of the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR), Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and Standard Contractual Clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
- Google AdSense with personalized ads: We use the Google AdSense service with personalized ads, with the help of which advertisements are displayed within our online offering and for the display or other use of which we receive remuneration; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: Information on the services, Controller-Controller Data Protection Terms and Standard Contractual Clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
- Google AdSense with non-personalized ads: We use the Google AdSense service with non-personalized ads, with the help of which advertisements are displayed within our online offering and for the display or other use of which we receive remuneration; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Google Ads Controller-Controller Data Protection Terms and standard contractual clauses for data transfers to third countries: https://business.safety.google/adscontrollerterms.
- LinkedIn Insight Tag: Code that is loaded when a user visits our online offering and tracks the user's behavior and conversions and stores them in a profile (possible purposes of use: measurement of campaign performance, optimization of ad delivery, building custom and similar audiences); Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy, Cookie policy: https://www.linkedin.com/legal/cookie_policy; Data processing agreement: https://www.linkedin.com/legal/l/dpa; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa). Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Affiliate programs and affiliate links
We integrate so-called affiliate links or other references (which may include, for example, search masks, widgets or discount codes) into our online offering, relating to the offers and services of third-party providers (collectively referred to as "affiliate links"). If users follow the affiliate links, or subsequently make use of the offers, we may receive a commission or other benefits from these third-party providers (collectively referred to as "commission").
In order to be able to track whether users have made use of the offers via an affiliate link we use, it is necessary for the respective third-party providers to learn that users have followed an affiliate link used within our online offering. The association of the affiliate links with the respective transactions or other actions (e.g. purchases) serves solely the purpose of commission accounting and is deleted as soon as it is no longer required for that purpose.
For the purposes of the aforementioned association of the affiliate links, the affiliate links may be supplemented with certain values that are part of the link or may otherwise be stored, e.g. in a cookie. Such values may include, in particular, the originating website (referrer), the time, an online identifier of the operators of the website on which the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer, and an online identifier of the user.
Notes on legal basis: If we ask users for their consent to the use of the third-party providers, the legal basis for the processing of data is consent. Otherwise, the data of users is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
- Categories of data processed: Contract data (e.g. subject matter of contract, term, customer category); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Affiliate tracking.
- Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR).
Offering of an affiliate program
We offer an affiliate program, i.e. commissions or other benefits (collectively referred to as "commission") for users (referred to as "affiliates") who refer to our offers and services. The referral is made by means of a link assigned to the respective affiliate or other methods (e.g. discount codes), which allow us to recognize that the use of our services was based on the referral (collectively referred to as "affiliate links").
In order to be able to track whether users have made use of our services on the basis of the affiliate links used by the affiliates, it is necessary for us to learn that users have followed an affiliate link. The association of the affiliate links with the respective transactions or other use of our services serves solely the purpose of commission accounting and is deleted as soon as it is no longer required for that purpose.
For the purposes of the aforementioned association of the affiliate links, the affiliate links may be supplemented with certain values that are part of the link or may otherwise be stored, e.g. in a cookie. Such values may include, in particular, the originating website (referrer), the time, an online identifier of the - -
- Categories of data processed: Contract data (e.g. subject matter of contract, term, customer category - - ); Usage data (e.g. websites visited, interest in content, - - ).
- Data subjects: Users (e.g. website visitors, users of - - ). Business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Affiliate tracking.
- Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR). Performance of contract and pre-contractual inquiries (Art. 6 (1) p. 1 lit. b) GDPR).
Customer reviews and rating procedures
We participate in review and rating procedures in order to evaluate, optimize and promote our services. If users rate us or otherwise provide feedback via the participating rating platforms or procedures, the general terms and conditions of use and the privacy notices of the providers shall additionally apply. As a general rule, the rating also requires registration with the respective providers.
In order to ensure that the persons providing ratings have actually made use of our services, we transmit, with the customers' consent, the data required for this purpose relating to the customer and the service used to the respective rating platform (including name, email address and order number or item number). This data is used solely to verify the authenticity of the user.
- Categories of data processed: Contract data (e.g. subject matter of contract, term, customer category); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and procedural data (e.g. IP addresses, timing data, identification numbers, consent status).
- Data subjects: Customers; Users (e.g. website visitors, users of online services).
- Purposes of processing: Feedback (e.g. collecting feedback via an online form). Marketing.
- Legal basis: Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Rating widget: We integrate so-called "rating widgets" into our online offering. A widget is a functional and content element integrated into our online offering that displays changeable information. It may, for example, be displayed in the form of a seal or comparable element, sometimes also referred to as a "badge." The corresponding content of the widget is displayed within our online offering, but at that moment it is retrieved from the servers of the respective widget provider. Only in this way can the current content always be shown, in particular the current rating. For this purpose, a data connection must be established from the website accessed within our online offering to the server of the widget provider, and the widget provider receives certain technical data (access data, including the IP address) that is necessary in order for the content of the widget to be delivered to the user's browser. Furthermore, the widget provider receives information that users have visited our online offering. This information may be stored in a cookie and used by the widget provider to determine which online offerings participating in the rating procedure have been visited by the user. The information may be stored in a user profile and used for advertising or market research purposes; Legal basis: Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR).
Presence on social networks (social media)
We maintain online presences within social networks and, within this framework, process user data in order to communicate with the users active there or to provide information about ourselves.
We would like to point out that user data may be processed outside the European Union in this context. This may entail risks for users because, for example, it could make it more difficult to enforce users' rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behaviour and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are generally stored on the users' computers, in which the usage behaviour and interests of the users are stored. Furthermore, data may also be stored in the usage profiles independently of the devices used by the users (in particular if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we would like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data in each case and can take appropriate measures and provide information directly. Should you nevertheless need assistance, you may contact us.
- Categories of data processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status); master data (e.g. names, addresses).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Contact requests and communication; feedback (e.g. collecting feedback via online form); marketing; provision of our online offering and user-friendliness. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.instagram.com. Privacy policy: https://instagram.com/about/legal/privacy.
- Facebook pages: Profiles within the Facebook social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further information: We are jointly responsible together with Meta Platforms Ireland Limited for the collection (but not the further processing) of data from visitors to our Facebook page (so-called "fan page"). This data includes information on the types of content that users view or with which they interact, or the actions taken by them (see under "Things Others Do and Provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device Information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, so-called "Page Insights", to page operators so that they can gain insights into how people interact with their pages and with the content associated with them. We have entered into a special agreement with Facebook ("Page Insights Information", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfil the rights of data subjects (i.e. users can, for example, address requests for information or deletion directly to Facebook). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Information about Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint responsibility is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transmission of the data to the parent company Meta Platforms, Inc. in the USA.
-
LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa); Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out; Further information: We are jointly responsible together with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of visitor data for the purposes of creating the "Page Insights" (statistics) of our LinkedIn profiles.
This data includes information on the types of content that users view or with which they interact, or the actions taken by them, as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data) and details from the users' profile, such as job function, country, industry, hierarchy level, company size and employment status. Data protection information on the processing of user data by LinkedIn can be found in LinkedIn's privacy notices: https://www.linkedin.com/legal/privacy-policy
We have entered into a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum (the 'Addendum')", https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfil the rights of data subjects (i.e. users can, for example, address requests for information or deletion directly to LinkedIn). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection of data by and transmission to Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of Ireland Unlimited Company, which in particular concerns the transmission of the data to the parent company LinkedIn Corporation in the USA. - Pinterest: Social network; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.pinterest.com. Privacy policy: https://policy.pinterest.com/de/privacy-policy.
- Snapchat: Social network; Service provider: Snap Inc., 3000 31st Street, Santa Monica, California 90405 USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.snapchat.com/; Privacy policy: https://www.snap.com/de-DE/privacy/privacy-policy. Basis for third-country transfer: Standard Contractual Clauses (https://www.snap.com/en-US/terms/standard-contractual-clauses).
- Threads: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.threads.net/. Privacy policy: https://help.instagram.com/515230437301944.
- TikTok: Social network / video platform; Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Website: https://www.tiktok.com. Privacy policy: https://www.tiktok.com/de/privacy-policy.
- X: Social network; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR). Privacy policy: https://twitter.com/privacy, (settings: https://twitter.com/personalization).
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR); Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Option to object (opt-out): https://myadcenter.google.com/personalizationoff.
Plugins and embedded functions and content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may, for example, be graphics, videos or city maps (hereinafter uniformly referred to as "content").
The integration always requires that the third-party providers of this content process the users' IP address, as they could not send the content to their browsers without the IP address. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other details on the use of our online offering, as well as being combined with such information from other sources.
- Categories of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status); master data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); location data (information on the geographic position of a device or a person); event data (Facebook) ("event data" is data that may be transmitted by us to Facebook, e.g. via Facebook pixel (via apps or in other ways), and relates to persons or their actions; this data includes, for example, information about visits to websites, interactions with content, functions, app installations, product purchases, etc.; the event data is processed for the purpose of forming target groups for content and advertising information (custom audiences); event data does not include the actual content (such as comments written), no login information and no contact information (i.e. no names, email addresses and telephone numbers). Event data is deleted by Facebook after a maximum of two years, the target groups formed from it upon deletion of our Facebook account).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online offering and user-friendliness; marketing. Profiles with user-related information (creation of user profiles).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 (a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 (f) GDPR).
Further information on processing operations, procedures and services:
- Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate software into our online offering that we retrieve from servers of other providers (e.g. function libraries that we use for the purpose of displaying or improving the usability of our online offering). In doing so, the respective providers collect the IP address of the users and may process it for the purpose of transmitting the software to the users' browsers, as well as for security purposes and for the evaluation and optimisation of their offering. - We integrate software into our online offering that we retrieve from servers of other providers (e.g. function libraries that we use for the purpose of displaying or improving the usability of our online offering). In doing so, the respective providers collect the IP address of the users and may process it for the purpose of transmitting the software to the users' browsers, as well as for security purposes and for the evaluation and optimisation of their offering; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Facebook plugins and content: Facebook Social Plugins and content - This may include, for example, content such as images, videos or text and buttons that allow users to share content from this online offering within Facebook. The list and appearance of the Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/ - We are jointly responsible with Meta Platforms Ireland Limited for the collection of, or receipt in the course of a transfer of (but not the further processing of), "event data" that Facebook collects by means of the Facebook Social Plugins (and content embedding functions) executed on our online offering, or receives in the course of a transfer, for the following purposes: a) displaying content and advertising information that corresponds to the presumed interests of the users; b) delivery of commercial and transaction-related messages (e.g. addressing users via Facebook Messenger); c) improving ad delivery and personalising functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to the interests of the users). We have concluded a special agreement with Facebook ("Controller Addendum", https://www.facebook.com/legal/controller_addendum), which in particular regulates which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfil the rights of data subjects (i.e. users can, for example, submit requests for information or deletion directly to Facebook). Note: If Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information on individual users and are anonymous to us), this processing does not take place within the framework of joint controllership, but rather on the basis of a data processing agreement ("Data Processing Terms", https://www.facebook.com/legal/terms/dataprocessing), the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms) as well as, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
- Google Fonts (hosted on our own server): Provision of font files for the purpose of a user-friendly presentation of our online offering; Service provider: The Google Fonts are hosted on our own server, no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Google Fonts (retrieval from the Google server): Retrieval of fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to timeliness and loading times, their uniform presentation and consideration of possible licensing restrictions. The IP address of the user is communicated to the provider of the fonts so that the fonts can be made available in the user's browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the USA - When visiting our online offering, the users' browsers send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving the fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of the website visitors, as well as the referrer URL (i.e. the web page on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analysed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent has to adapt the font that is generated for the respective browser type. The user agent is primarily logged for debugging purposes and used to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the "Analytics" page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for production maintenance and an aggregated report on the top integrations can be generated based on the number of font requests. According to its own statements, Google does not use any of the information collected by Google Fonts to create profiles of end users or to serve targeted advertising; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website: https://fonts.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
- Google Maps: We integrate the maps of the "Google Maps" service provided by Google. The data processed may in particular include IP addresses and location data of the users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
- Instagram plugins and content: Instagram plugins and content - This may include, for example, content such as images, videos or text and buttons that allow users to share content from this online offering within Instagram. - We are jointly responsible with Meta Platforms Ireland Limited for the collection of, or receipt in the course of a transfer of (but not the further processing of), "event data" that Facebook collects by means of Instagram functions (e.g. content embedding functions) executed on our online offering, or receives in the course of a transfer, for the following purposes: a) displaying content and advertising information that corresponds to the presumed interests of the users; b) delivery of commercial and transaction-related messages (e.g. addressing users via Facebook Messenger); c) improving ad delivery and personalising functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to the interests of the users). We have concluded a special agreement with Facebook ("Controller Addendum", https://www.facebook.com/legal/controller_addendum), which in particular regulates which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfil the rights of data subjects (i.e. users can, for example, submit requests for information or deletion directly to Facebook). Note: If Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information on individual users and are anonymous to us), this processing does not take place within the framework of joint controllership, but rather on the basis of a data processing agreement ("Data Processing Terms", https://www.facebook.com/legal/terms/dataprocessing), the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms) as well as, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website: https://www.instagram.com. Privacy policy: https://instagram.com/about/legal/privacy/.
- LinkedIn plugins and content: LinkedIn plugins and content - This may include, for example, content such as images, videos or text and buttons that allow users to share content from this online offering within LinkedIn; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Data processing agreement: https://legal.linkedin.com/dpa; Basis for third-country transfer: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.linkedin.com/legal/l/dpa). Opt-out possibility: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- X plugins and content: Plugins and buttons of the "X" platform - This may include, for example, content such as images, videos or text and buttons that allow users to share content from this online offering within X; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website: https://twitter.com/de; Privacy policy: https://twitter.com/de/privacy, (Settings: https://twitter.com/personalization); Data processing agreement: https://privacy.twitter.com/en/for-our-partners/global-dpa. Basis for third-country transfer: Standard contractual clauses (https://privacy.twitter.com/en/for-our-partners/global-dpa).
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Opt-out possibility: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://myadcenter.google.com/personalizationoff.
- YouTube videos: Video content; YouTube videos are integrated via a special domain (identifiable by the component "youtube-nocookie") in the so-called "advanced privacy mode", whereby no cookies are collected on user activities in order to personalise video playback. Nevertheless, information on users' interaction with the video (e.g. remembering the last playback position) may be stored; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
Management, organisation and auxiliary tools
We use services, platforms and software of other providers (hereinafter referred to as "third-party providers") for the purposes of organisation, administration, planning and provision of our services. When selecting third-party providers and their services, we comply with the legal requirements.
In this context, personal data may be processed and stored on the servers of third-party providers. This may affect various data that we process in accordance with this privacy policy. This data may in particular include master data and contact data of users, data on transactions, contracts, other processes and their content.
If, in the course of communication or business or other relationships with us, users are referred to the third-party providers or their software or platforms, the third-party providers may process usage data and metadata for security purposes, for service optimisation or for marketing purposes. We therefore ask that you observe the privacy notices of the respective third-party providers.
- Categories of data processed: Content data (e.g. entries in online forms); usage data (e.g. web pages visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, consent status).
- Data subjects: Communication partners; users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Office and organisational procedures.
Changes and updates to the privacy policy
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or other individual notification.
If we provide addresses and contact information of companies and organisations in this privacy policy, please note that these addresses may change over time and please check the information before making contact.
Definitions of terms
In this section, you will receive an overview of the terminology used in this privacy policy. Insofar as the terms are legally defined, their legal definitions apply. The following explanations, on the other hand, are primarily intended to aid understanding.
- Affiliate tracking: In the context of affiliate tracking, links are logged that allow the linking websites to refer users to websites with product or other offers. The operators of the respective linking websites may receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g. purchase goods or make use of services). For this purpose, it is necessary for the providers to be able to track whether users who are interested in certain offers subsequently take advantage of them as a result of the affiliate links. It is therefore necessary for the functionality of affiliate links that they are supplemented by certain values that become part of the link or are otherwise stored, e.g. in a cookie. These values include in particular the originating website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user as well as tracking-specific values such as advertising material ID, partner ID and categorisations.
- Conversion measurement: Conversion measurement (also referred to as "visit action evaluation") is a procedure used to determine the effectiveness of marketing measures. For this purpose, a cookie is usually stored on the users' devices within the websites on which the marketing measures take place and is then retrieved again on the target website. For example, this allows us to determine whether the advertisements we placed on other websites were successful.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of "profiles with user-related information", or "profiles" for short, comprises any type of automated processing of personal data consisting of the use of this personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may involve various information regarding demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behaviour on a website or location). Cookies and web beacons are often used for profiling purposes.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate the visitor flows of an online offering and can include the behaviour or interests of visitors in certain information, such as the content of websites. With the help of reach analysis, operators of online offerings can, for example, recognise the time at which users visit their websites and what content they are interested in. This allows them, for example, to better adapt the content of the websites to the needs of their visitors. Pseudonymous cookies and web beacons are often used for the purposes of reach analysis in order to recognise recurring visitors and thus obtain more accurate analyses of the use of an online offering.
- Location data: Location data is generated when a mobile device (or another device with the technical prerequisites for location determination) connects to a radio cell, a WLAN or similar technical means and functions of location determination. Location data is used to indicate the geographically determinable position of the respective device on Earth. Location data can be used, for example, to display map functions or other location-dependent information.
- Tracking: "Tracking" refers to the ability to track the behaviour of users across multiple online offerings. As a rule, behavioural and interest information regarding the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information can then be used, for example, to show users advertisements that are likely to correspond to their interests.
- Controller: "Controller" refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" is any operation or set of operations carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether it be collecting, evaluating, storing, transmitting or deleting.