Privacy Policy
Information on how your data is handled
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Applicable Legal Bases
- Security Measures
- Disclosure of Personal Data
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Contact and Inquiry Management
- Newsletter and Electronic Notifications
- Promotional Communication via Email, Mail, Fax or Telephone
- Web Analytics, Monitoring and Optimization
- Online Marketing
- Social Media Presence
- Plugins and Embedded Functions and Content
- Changes and Updates
- Definitions
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our website, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: September 11, 2026
Controller
DJ Da Trooth
St. Rochus-Weg 2
56651 Galenberg, Germany
Email address: [email protected]
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Categories of data processed
- Registration data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
Categories of data subjects
- Communication partners.
- Users.
Purposes of processing
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Audience formation.
- Organizational and administrative procedures.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- IT infrastructure.
- Public relations.
- Sales promotion.
Applicable Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations in your or our country of residence may apply. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for a specific purpose or purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject.
National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG), which contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual German federal states may apply.
Reference to the applicability of the GDPR and the Swiss FADP: These privacy notices serve to provide information under both the Swiss Federal Act on Data Protection (FADP) and the GDPR. For this reason, please note that due to the broader territorial application and comprehensibility, the terminology of the GDPR is used. In particular, instead of the terms used in the Swiss FADP, "processing" of "personal data", "overriding interest" and "sensitive personal data", the terms used in the GDPR, "processing" of "personal data" as well as "legitimate interest" and "special categories of data" are used. The legal meaning of the terms will, however, continue to be determined under the Swiss FADP where it applies.
Applicability of data protection provisions in the country of establishment: In the country where the controller is established, national data protection regulations apply in addition to the GDPR.
Security Measures
In accordance with legal requirements, taking into account the state of the art, the cost of implementation, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, and availability of the data, and its segregation. We have also established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Furthermore, we take the protection of personal data into account as early as the development and selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and data protection-friendly default settings.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect user data transmitted through our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt information transmitted between the website or app and the user's browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured with an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL, signaling to users that their data is being transmitted securely and encrypted.
Disclosure of Personal Data
In the course of our processing of personal data, it may be disclosed or transmitted to other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in our website. In such cases, we comply with legal requirements and in particular enter into appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transmitting data to other persons, bodies or companies (which is apparent from the postal address of the respective provider, or where the privacy policy explicitly refers to a transfer of data to third countries), this is always done in accordance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated July 10, 2023. In addition, we have concluded standard contractual clauses with the respective providers, in accordance with the requirements of the EU Commission, establishing contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, while the standard contractual clauses serve as additional security. Should changes occur within the DPF framework, the standard contractual clauses act as a reliable fallback option, ensuring your data remains adequately protected even in the event of political or legal changes.
For each individual service provider, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, appropriate safeguards apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found on the EU Commission's website.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal requirements as soon as the underlying consent is revoked or there is no further legal basis for processing. This applies where the original processing purpose no longer applies or the data is no longer needed. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data specific to particular processing activities.
Where multiple retention or deletion periods are specified for a given piece of data, the longest period applies. Data retained beyond its original purpose due to legal requirements or other reasons is processed exclusively for the reasons justifying its retention.
Retention and deletion of data: The following general periods apply for retention and archiving under German law:
- 10 years – retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the working instructions and other organizational documents required to understand them (§ 147(1) No. 1 in conjunction with (3) of the German Fiscal Code (AO), § 257(1) No. 1 in conjunction with (4) of the German Commercial Code (HGB)).
- 8 years – accounting documents such as invoices and cost receipts (§ 147(1) No. 4 and 4a in conjunction with (3) sentence 1 AO, § 14b(1) of the German VAT Act (UStG), and § 257(1) No. 4 in conjunction with (4) HGB).
- 6 years – other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents relevant for taxation purposes, e.g. hourly wage slips, operating cost statements, calculation documents, price labeling, as well as payroll documents insofar as they are not already accounting documents, and cash register tapes (§ 147(1) No. 2, 3, 5 in conjunction with (3) AO, § 257(1) No. 2 and 3 in conjunction with (4) HGB).
- 3 years – data required to take into account potential warranty and compensation claims or similar contractual claims and rights, and to process related inquiries, based on past business experience and common industry practice, is stored for the duration of the standard statutory limitation period of three years (§§ 195, 199 of the German Civil Code (BGB)).
Commencement of the period at the end of the year: Where a period does not expressly begin on a specific date and is at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the point at which the termination or other ending of the legal relationship takes effect.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to such processing, including related profiling.
- Right to withdraw consent: You have the right to withdraw any consent given to us at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to request access to that data and further information, as well as a copy of the data, in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be deleted without delay, or alternatively to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of personal data concerning you infringes the GDPR. A complaint may be lodged in particular with a supervisory authority in the member state of your habitual residence, place of work, or the place of the alleged infringement.
Provision of the Online Offering and Web Hosting
We process user data in order to provide our online services. For this purpose, we process the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or end device.
- Categories of data processed: Usage data (e.g. page views and length of visit, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. logfiles relating to logins or data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Additional information on processing activities, procedures and services:
- Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a "web host"); legal bases: legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), and typically IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to avoid overloading our servers (particularly in the case of abusive attacks, so-called DDoS attacks), and to ensure server utilization and stability; legal bases: legitimate interests (Art. 6(1)(f) GDPR). Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is exempt from deletion until final clarification of the respective incident.
Use of Cookies
"Cookies" are functions that store and read information on users' end devices. Cookies may be used for various purposes, such as ensuring the functionality, security and convenience of online offerings, as well as analyzing visitor flows. We use cookies in accordance with legal requirements. Where necessary, we obtain prior consent from users. Where consent is not required, we rely on our legitimate interests. This applies where the storage and reading of information is essential to provide expressly requested content and functions, such as storing settings and ensuring the functionality and security of our online offering. Consent may be withdrawn at any time. We clearly inform you about the scope of consent and which cookies are used.
Legal bases: Whether we process personal data using cookies depends on your consent. Where consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests as explained in this section and in the context of the respective services and procedures.
Storage period: With regard to storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest once a user leaves an online offering and closes their end device (e.g. browser or mobile app).
- Persistent cookies: Persistent cookies remain stored even after the end device is closed. For example, login status may be saved, or preferred content displayed directly when the user revisits a website. User data collected via cookies may also be used for reach measurement. Unless we provide explicit information on the type and storage duration of cookies (e.g. when obtaining consent), users should assume that cookies are persistent and that the storage period may be up to two years.
General notes on withdrawal and objection (opt-out): Users may withdraw consent given at any time and may also object to processing in accordance with legal requirements, including via their browser's privacy settings.
- Categories of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR).
Additional information on processing activities, procedures and services:
- Processing of cookie data based on consent: We use a consent management solution to obtain users' consent to the use of cookies, or to the procedures and providers named within the consent management solution. This procedure serves to obtain, log, manage and withdraw consent, particularly regarding the use of cookies and comparable technologies used to store, read and process information on users' end devices. Users also have the option of managing and withdrawing their consent. Consent declarations are stored to avoid repeated requests and to provide proof of consent as legally required. Storage takes place server-side and/or in a cookie (a so-called "opt-in cookie") or via comparable technologies, so that consent can be attributed to a specific user or their device. Unless otherwise specified, the following general information applies: consent is stored for up to two years. A pseudonymous user identifier is created, stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers), and information about the browser, system and end device used; legal basis: consent (Art. 6(1)(a) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by mail, contact form, email, telephone or via social media) as well as within the context of existing user and business relationships, the details of the inquiring persons are processed to the extent necessary to respond to the contact requests and any requested measures.
- Categories of data processed: Contact data (e.g. postal and email addresses or phone numbers); content data (e.g. text or image messages and posts, as well as related information such as authorship or time of creation); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; feedback (e.g. collecting feedback via an online form); provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Additional information on processing activities, procedures and services:
- Contact form: When you contact us via our contact form, by email or other means of communication, we process the personal data transmitted to us in order to respond to and process your request. This generally includes details such as name, contact information and any other information you provide that is necessary for us to handle your request appropriately. We use this data exclusively for the stated purpose of contact and communication; legal bases: performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Newsletter and Electronic Notifications
We send newsletters, emails and other electronic notifications (hereinafter "newsletter") only with the recipients' consent or on a legal basis. Where the contents of the newsletter are described as part of the sign-up process, they are decisive for users' consent. Signing up for our newsletter generally only requires your email address. However, in order to offer you a personalized service, we may ask for your name for personal address in the newsletter, or for further information if necessary for the purpose of the newsletter.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years, based on our legitimate interests, before deleting them, in order to provide evidence of previously given consent. Processing of this data is limited to the purpose of a possible defense against claims. An individual request for deletion is possible at any time, provided the former existence of consent is confirmed. Where we are obliged to permanently observe objections, we reserve the right to store the email address solely for this purpose in a block list.
Logging of the registration process is carried out on the basis of our legitimate interests in being able to prove that it was carried out properly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interest in an efficient and secure delivery system.
Content: Information about us, our services, promotions and offers.
- Categories of data processed: Registration data (e.g. full name, home address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or phone numbers); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); usage data (e.g. page views and length of visit, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post).
- Legal bases: Consent (Art. 6(1)(a) GDPR).
- Right to object (opt-out): You may cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to unsubscribe from the newsletter either at the end of each newsletter, or you may use one of the contact options listed above, preferably email.
Additional information on processing activities, procedures and services:
- Measuring open and click rates: Newsletters contain a so-called "web beacon", i.e. a pixel-sized file retrieved from our server (or that of our sending service provider, if applicable) when the newsletter is opened. This retrieval initially collects technical information such as details about your browser and system, as well as your IP address and the time of retrieval. This information is used to technically improve our newsletter based on technical data or the target groups and their reading behavior; legal basis: consent (Art. 6(1)(a) GDPR).
Promotional Communication via Email, Mail, Fax or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels such as email, telephone, mail or fax, in accordance with legal requirements.
Recipients have the right to withdraw consent given at any time or to object to promotional communication at any time, free of charge, via the contact options listed above.
After withdrawal or objection, we store the data necessary to prove prior authorization for contact or dispatch for up to three years after the end of the year in which the withdrawal or objection occurred, based on our legitimate interests. Processing of this data is limited to the purpose of a possible defense against claims. On the basis of our legitimate interest in permanently observing users' withdrawal or objection, we further store the data required to avoid renewed contact (e.g., depending on the communication channel, the email address, phone number, name).
- Categories of data processed: Registration data; contact data; content data.
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing; marketing; sales promotion.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Web Analytics, Monitoring and Optimization
Web analytics (also referred to as "reach measurement") is used to evaluate visitor flows on our online offering and may include pseudonymized behavioral, interest, or demographic information about visitors, such as age or gender. Reach analysis allows us to identify, for example, when our online offering or its functions or content are used most frequently, or invite repeat use. It also allows us to identify areas that need optimization.
In addition to web analytics, we may use testing procedures, for example to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles (i.e. data summarized for a usage process) may be created for these purposes, and information stored in and read from a browser or end device. Data collected includes in particular websites visited and elements used there, as well as technical information such as the browser used, the computer system used, and usage times. Where users have consented to the collection of their location data with us or with providers of the services we use, processing of location data is also possible.
In addition, users' IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users. In general, no plain-text user data (such as email addresses or names) is stored within the scope of web analytics, A/B testing and optimization, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, only the information stored in their profiles for the purposes of the respective procedures.
Legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services).
- Categories of data processed: Usage data; meta, communication and procedural data.
- Data subjects: Users.
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information; provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the section "General Information on Data Storage and Deletion". Cookies are stored for up to 2 years, unless otherwise stated.
- Security measures: IP masking (pseudonymization of the IP address).
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional information on processing activities, procedures and services:
- Google Analytics: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to associate analytics information with a device to recognize which content users accessed within one or more usage sessions, which search terms they used, whether they revisited content, or interacted with our online offering. The time and duration of use are also stored, as well as the sources referring users to our online offering and technical aspects of their devices and browsers. Pseudonymous user profiles are created from data collected across different devices, potentially involving the use of cookies. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographic location data by deriving certain metadata from IP addresses, such as city, continent, country, region and subcontinent. For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted; it is not logged, is not accessible, and is not used for any further purpose. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent (Art. 6(1)(a) GDPR); website: https://marketingplatform.google.com/intl/en/about/analytics/; security measures: IP masking; privacy policy: https://business.safety.google/privacy/; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses; opt-out: opt-out plugin at https://tools.google.com/dlpage/gaoptout, ad personalization settings at https://myadcenter.google.com/personalizationoff.
Online Marketing
We process personal data for the purpose of online marketing, which includes in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on users' potential interests, as well as measuring its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (a "cookie") or similar procedures are used to store information about the user relevant to displaying the aforementioned content. This may include, for example, content viewed, websites visited, online networks used, communication partners, and technical information such as the browser used, the computer system, and usage times and functions used. Where users have consented to the collection of their location data, this may also be processed.
In addition, users' IP addresses are stored. However, we use available IP masking procedures for user protection. Generally, no plain-text user data is stored as part of online marketing procedures, only pseudonyms. This means neither we nor the providers of the online marketing procedures know the actual identity of users, only the information stored in their profiles.
The information contained in profiles is generally stored in cookies or via similar methods. These cookies can later generally also be read on other websites using the same online marketing procedure and analyzed for the purpose of displaying content, supplemented with additional data, and stored on the server of the online marketing procedure provider.
Exceptionally, it is possible for plain-text data to be linked to profiles, particularly where users are, for example, members of a social network whose online marketing procedures we use, and the network links the user profiles with the aforementioned data. Please note that users may enter into additional agreements with providers, for example through consent given during registration.
We generally only have access to summarized information about the success of our advertisements. However, as part of so-called conversion measurement, we may determine which of our online marketing procedures led to a so-called conversion, e.g. the conclusion of a contract with us. Conversion measurement is used solely to analyze the success of our marketing efforts.
Unless stated otherwise, please assume that cookies used are stored for a period of two years.
Notes on withdrawal and objection: We refer to the privacy notices of the respective providers and their stated opt-out options. Where no explicit opt-out option is provided, you may disable cookies in your browser settings. This may, however, limit the functionality of our online offering. We therefore additionally recommend the following region-specific opt-out options: (a) Europe: https://youronlinechoices.eu/; (b) Canada: https://youradchoices.ca/; (c) USA: https://optout.aboutads.info/; (d) cross-region: https://optout.aboutads.info.
- Categories of data processed: Usage data; meta, communication and procedural data.
- Data subjects: Users.
- Purposes of processing and legitimate interests: Reach measurement; tracking (e.g. interest-/behavior-based profiling, use of cookies); audience formation; marketing; profiles with user-related information.
- Retention and deletion: Deletion in accordance with the section "General Information on Data Storage and Deletion". Cookies stored for up to 2 years, unless otherwise stated.
- Security measures: IP masking (pseudonymization of the IP address).
Social Media Presence
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to provide information about us.
We would like to point out that user data may be processed outside the European Union in this context. This may pose risks to users, as it could, for example, make it more difficult to enforce user rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on user behavior and resulting interests. These profiles may in turn be used, for example, to place advertisements within and outside the networks that are presumed to correspond to users' interests. For this purpose, cookies are generally stored on users' computers, recording their usage behavior and interests. Data may also be stored in usage profiles independently of the devices used by users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and opt-out options, please refer to the privacy policies and information provided by the operators of the respective networks.
Even in the case of requests for information and the exercise of data subject rights, we note that these can be most effectively asserted directly with the providers, as only they have access to user data and can take appropriate action and provide information directly. Should you nevertheless require assistance, you may contact us.
- Categories of data processed: Contact data; content data; usage data.
- Data subjects: Users.
- Purposes of processing and legitimate interests: Communication; feedback; public relations.
- Retention and deletion: Deletion in accordance with the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Additional information on processing activities, procedures and services:
- Facebook pages: Profile within the Facebook social network – The controller is jointly responsible, together with Meta Platforms Ireland Limited, for the collection and transmission of data from visitors to our Facebook page ("fan page"). This includes in particular information about user behavior (e.g. content viewed or interacted with, actions taken) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook's data policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical analyses via the "Page Insights" service, which provide insight into how people interact with our page and its content. This is based on an agreement with Facebook ("Information about Page Insights"), which regulates, among other things, security measures and the exercise of data subject rights. Users may therefore direct requests for information or deletion directly to Facebook. Users' rights (in particular access, deletion, objection, and complaints to a supervisory authority) remain unaffected. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for further processing, including any transfer to Meta Platforms Inc. in the USA; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses.
Plugins and Embedded Functions and Content
We embed functional and content elements in our online offering that are sourced from the servers of their respective providers (hereinafter "third-party providers"). These may include, for example, graphics, videos or maps (collectively referred to as "content").
Embedding always requires that the third-party providers of this content process the user's IP address, as without the IP address they would not be able to send the content to the user's browser. The IP address is therefore required to display this content or function. We strive to use only content whose respective providers use the IP address solely for delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. These "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on the user's device and may include technical information about the browser and operating system, referring websites, time of visit, and other information about the use of our online offering, and may also be combined with such information from other sources.
Legal bases: Where we ask users for consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services).
- Categories of data processed: Usage data; meta, communication and procedural data.
- Data subjects: Users.
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; reach measurement; tracking; audience formation; marketing.
- Retention and deletion: Deletion in accordance with the section "General Information on Data Storage and Deletion". Cookies stored for up to 2 years, unless otherwise stated.
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional information on processing activities, procedures and services:
- Google Fonts (retrieved from Google servers): We use Google Fonts to load fonts (and icons) for technically secure, maintenance-free and efficient use in terms of currency and loading times, uniform display, and consideration of possible licensing restrictions. The font provider is informed of the user's IP address so that the fonts can be made available in the user's browser. Technical data (language settings, screen resolution, operating system, hardware used) required to deliver fonts depending on the devices and technical environment used is also transmitted. This data may be processed on a server of the font provider in the USA. When visiting our online offering, users' browsers send HTTP requests to the Google Fonts Web API. The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and then the fonts specified therein. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the user agent describing the browser and operating system versions of website visitors, as well as the referrer URL. According to Google, IP addresses are neither logged nor stored on Google servers and are not analyzed. The Google Fonts Web API logs details of HTTP requests (requested URL, user agent and referrer URL); access to this data is restricted and strictly controlled. The requested URL identifies the font families the user wishes to load; this data is logged so Google can determine how often a particular font family is requested. The user agent is primarily logged for debugging purposes and used to generate aggregated usage statistics measuring the popularity of font families; these aggregated statistics are published on Google Fonts' "Analytics" page. Finally, the referrer URL is logged so the data can be used for production maintenance and to generate an aggregated report on top integrations based on the number of font requests. According to Google, none of the information collected through Google Fonts is used to build end-user profiles or to serve targeted ads; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://fonts.google.com/; privacy policy: https://business.safety.google/privacy/; basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://fonts.google.com/faq.
- YouTube videos: Video content; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6(1)(a) GDPR); website: https://www.youtube.com; privacy policy: https://business.safety.google/privacy/; basis for third-country transfers: Data Privacy Framework (DPF); opt-out: opt-out plugin at https://tools.google.com/dlpage/gaoptout, ad personalization settings at https://myadcenter.google.com/personalizationoff.
Changes and Updates
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as changes require your cooperation (e.g. consent) or other individual notification.
Where we provide addresses and contact information for companies and organizations in this privacy policy, please note that these addresses may change over time; please verify the information before making contact.
Definitions
This section provides you with an overview of the terms used in this privacy policy. Where terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.
- Registration data: Registration data includes essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic information such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Registration data forms the basis for any formal interaction between individuals and services, institutions or systems by enabling clear identification and communication.
- Content data: Content data includes information generated in the course of creating, editing and publishing content of any kind. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself, but also includes metadata providing information about the content, such as tags, descriptions, author information and publication dates.
- Contact data: Contact data is essential information that enables communication with individuals or organizations. It includes phone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: These categories contain information about how data is processed, transmitted and managed. Metadata, also known as data about data, includes information describing the context, origin and structure of other data. It may include file size, creation date, document author, and revision history. Communication data captures the exchange of information between users via various channels, such as email traffic, call logs, social media messages and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes processes and workflows within systems or organizations, including workflow documentation, transaction and activity logs, and audit logs used to track and review processes.
- Usage data: Usage data refers to information that records how users interact with digital products, services, or platforms. It includes a wide range of information showing how users use applications, which features they prefer, how long they stay on certain pages, and which paths they take through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experience, personalizing content, and improving products or services. It also plays a crucial role in identifying trends, preferences, and potential problem areas within digital offerings.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (the "data subject"); a natural person is considered identifiable who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of "profiles with user-related information" (or "profiles" for short) encompasses any type of automated processing of personal data used to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may involve different information relating to demographics, behavior and interests, such as interaction with websites and their content, etc.), for example interests in certain content or products, click behavior on a website, or location. Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities recorded in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used for analyzing system issues, security monitoring, or generating performance reports.
- Reach measurement: Reach measurement (also known as web analytics) is used to evaluate visitor flows to an online offering and may include information about visitor behavior or interests in particular content, such as website content. Reach analysis allows operators of online offerings to identify, for example, when users visit their websites and what content interests them, enabling them to better adapt website content to visitors' needs. Pseudonymous cookies and web beacons are frequently used for reach analysis purposes, to recognize returning visitors and obtain more accurate usage analytics.
- Tracking: "Tracking" refers to the ability to track user behavior across multiple online offerings. Typically, behavioral and interest information relating to the online offerings used is stored in cookies or on the servers of tracking technology providers (so-called profiling). This information may subsequently be used, for example, to display advertisements to users that are likely to match their interests.
- Controller: "Controller" refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether collecting, evaluating, storing, transmitting, or deleting it.
- Audience formation: "Audience formation" (in English, "custom audiences") refers to determining target groups for advertising purposes, e.g. displaying advertisements. For example, based on a user's interest in certain products or topics on the internet, it may be inferred that this user is interested in advertisements for similar products or the online shop where they viewed the products. "Lookalike audiences" (or similar audiences) refers to displaying content deemed suitable to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are generally used for the purposes of creating custom and lookalike audiences.