Privacy Policy
Preamble
With the following privacy policy we would like to inform you about which types of your personal data (hereinafter also referred to briefly as “data”) we process, for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Last updated: June 22, 2026
Controller
BRUMABA GmbH
Bürgermeister-Graf-Ring 17
82538 Geretsried
Authorized representatives: Benedikt Brustmann, Sebastian Brustmann
Email address: info@brumaba.de
Telephone: +49 (0) 8171 / 2672 – 18
Legal notice: https://www.brumaba.de/impressum/
Contact for the Data Protection Officer
Jürgen Dichtl
DSB@brumaba.de
Overview of Processing Operations
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects concerned.
Types of data processed
- Master data.
- Employee data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Social data.
- Applicant data.
- Image and/or video recordings.
- Audio recordings.
- Event data (Facebook).
- Log data.
- Performance and behavioral data.
- Working time data.
- Credit data.
- Salary data.
Special categories of data
- Health data.
- Religious or ideological beliefs.
- Trade union membership.
Categories of data subjects
- Service recipients and clients.
- Employees.
- Interested parties.
- Communication partners.
- Users.
- Applicants.
- Participants in prize draws and competitions.
- Business and contractual partners.
- Participants.
- Depicted persons.
- Third parties.
- Customers.
Purposes of processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organizational procedures.
- Remarketing.
- Conversion measurement.
- Click tracking.
- Target group formation.
- A/B testing.
- Organizational and administrative procedures.
- Application procedure.
- Conducting prize draws and competitions.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- Assessment of solvency and creditworthiness.
- Establishment and implementation of employment relationships.
- Information technology infrastructure.
- Financial and payment management.
- Public relations.
- Sales promotion.
- Business processes and economic procedures.
- Artificial intelligence (AI).
Automated decisions in individual cases
- Credit report.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 (1) (a) GDPR) – The data subject has given consent to the processing of the personal data concerning them for a specific purpose or several specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) (c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 (1) (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring the protection of personal data do not override such interests.
- Application procedure as a pre-contractual or contractual relationship (Art. 6 (1) (b) GDPR) – Insofar as special categories of personal data within the meaning of Art. 9 (1) GDPR (e.g. health data, such as severe disability status or ethnic origin) are requested from applicants in the context of the application procedure, so that the controller or the data subject can exercise the rights arising from employment law and the law of social security and social protection and fulfill their obligations in this regard, their processing takes place pursuant to Art. 9 (2) (b) GDPR, in the case of the protection of vital interests of the applicants or other persons pursuant to Art. 9 (2) (c) GDPR, or for purposes of preventive health care or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, the provision of care or treatment in the health or social care sector, or for the management of health or social care systems and services pursuant to Art. 9 (2) (h) GDPR. In the case of a communication of special categories of data based on voluntary consent, their processing takes place on the basis of Art. 9 (2) (a) GDPR.
- Processing of special categories of personal data relating to health care, occupation and social security (Art. 9 (2) (h) GDPR) – Processing is necessary for the purposes of preventive health care or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, the provision of care or treatment in the health or social care sector, or for the management of health or social care systems and services on the basis of Union law or the law of a Member State or pursuant to a contract with a health professional.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. These include in particular the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.
Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (in short “Swiss DSG”). Unlike the GDPR, for example, the Swiss DSG in principle does not stipulate that a legal basis for the processing of personal data must be named, and that the processing of personal data is carried out in good faith, lawfully and proportionately (Art. 6 (1) and (2) of the Swiss DSG). In addition, personal data is only obtained by us for a specific purpose that is identifiable to the data subject and is only processed in a manner compatible with that purpose (Art. 6 (3) of the Swiss DSG).
Note on the applicability of the GDPR and the Swiss DSG: This privacy information serves to provide information both under the Swiss DSG and under the General Data Protection Regulation (GDPR). For this reason, we ask you to note that, due to the broader geographical application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms “bearbeitung” (processing) of “Personendaten” (personal data), “überwiegendes Interesse” (overriding interest) and “besonders schützenswerte Personendaten” (particularly sensitive personal data) used in the Swiss DSG, the terms “processing” of “personal data” as well as “legitimate interest” and “special categories of data” used in the GDPR are used. However, the legal meaning of the terms continues to be determined under the Swiss DSG within the scope of the Swiss DSG’s applicability.
Security Measures
In accordance with the legal requirements and taking into account the state of the art, the implementation costs and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability and separation relating to it. Furthermore, we have set up procedures that ensure the exercise of data subjects’ rights, the erasure of data and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and through data protection-friendly default settings.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signaled by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transmission of Personal Data
In the course of our processing of personal data, it may happen that this data is transmitted to other entities, companies, legally independent organizational units or persons, or that it is disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
Data transmission within the group of companies: Data transmission within the group of companies: We may transmit personal data to other companies within our group of companies or grant them access to it. This data sharing takes place on the basis of our legitimate entrepreneurial and economic interests. This includes, for example, the improvement of business processes, ensuring efficient and effective internal communication, the optimal use of our human and technological resources, and the ability to make informed business decisions. In certain cases, the data sharing may also be necessary to fulfill our contractual obligations, or it must be based on the consent of the data subjects or a legal permission.
Data transmission within the organization: We may transmit personal data to other departments or units within our organization or grant them access to it. Insofar as the data sharing takes place for administrative purposes, it is based on our legitimate entrepreneurial and economic interests, or it takes place insofar as it is necessary to fulfill our contractual obligations, or when consent of the data subjects or a legal permission exists.
Disclosure to third-party dealers: To process business inquiries, personal data may be disclosed to authorized dealers or sales partners, insofar as this is necessary to respond to the inquiry or to carry out pre-contractual measures.
International Data Transfers
Data processing in third countries: Insofar as we transmit data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or this occurs in the context of using third-party services or disclosing or transmitting data to other persons, entities or companies (which is recognizable from the postal address of the respective provider or if the privacy policy expressly refers to the data transfer to third countries), this always takes place in accordance with the legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated 07/10/2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.
This twofold safeguard ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes occur within the framework of the DPF, the standard contractual clauses come into effect as a reliable fallback option. In this way, we ensure that your data always remains appropriately protected, even in the event of any political or legal changes.
For the individual service providers, we inform you as to whether they are certified under the DPF and whether standard contractual clauses exist. Further information on the DPF and a list of the certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, corresponding security measures apply, in particular standard contractual clauses, explicit consents or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
Disclosure of personal data abroad: In accordance with the Swiss DSG, we only disclose personal data abroad if adequate protection of the data subjects is ensured (Art. 16 Swiss DSG). Insofar as the Federal Council has not determined adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of Switzerland dated September 15, 2024. In addition, we have concluded standard data protection clauses with the respective providers that have been approved by the Federal Data Protection and Information Commissioner (FDPIC) and establish contractual obligations to protect your data.
This twofold safeguard ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard data protection clauses serve as additional security. Should changes occur within the framework of the DPF, the standard data protection clauses come into effect as a reliable fallback option. In this way, we ensure that your data always remains appropriately protected, even in the event of any political or legal changes.
For the individual service providers, we inform you as to whether they are certified under the DPF and whether standard data protection clauses exist. The list of the certified companies as well as further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, corresponding security measures apply, including international treaties, specific guarantees, standard data protection clauses approved by the FDPIC, or binding corporate data protection rules previously recognized by the FDPIC or a competent data protection authority of another country.
General Information on Data Storage and Erasure
We erase personal data that we process in accordance with the legal provisions as soon as the underlying consents are revoked or no further legal bases for the processing exist. This concerns cases in which the original purpose of the processing ceases to apply or the data is no longer needed. Exceptions to this rule exist when legal obligations or special interests require a longer storage or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy information contains additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where multiple retention periods or erasure deadlines are specified for a piece of data, the longest period is always decisive. Data that is no longer retained for the originally intended purpose but due to legal requirements or other reasons is processed exclusively for the reasons that justify its retention.
Retention and erasure of data: The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the work instructions and other organizational documents necessary for their understanding (§ 147 Abs. 1 Nr. 1 i.V.m. Abs. 3 AO, § 14b Abs. 1 UStG, § 257 Abs. 1 Nr. 1 i.V.m. Abs. 4 HGB).
- 8 years – Accounting vouchers, such as invoices and cost receipts (§ 147 Abs. 1 Nr. 4 und 4a i.V.m. Abs. 3 Satz 1 AO sowie § 257 Abs. 1 Nr. 4 i.V.m. Abs. 4 HGB).
- 6 years – Other business documents: received commercial or business letters, copies of the commercial or business letters sent, other documents insofar as they are of importance for taxation, e.g. hourly wage slips, cost accounting sheets, calculation documents, price labels, but also payroll documents insofar as they are not already accounting vouchers, and cash register strips (§ 147 Abs. 1 Nr. 2, 3, 5 i.V.m. Abs. 3 AO, § 257 Abs. 1 Nr. 2 u. 3 i.V.m. Abs. 4 HGB).
- 3 years – Data necessary to take into account potential warranty and damage compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experience and customary industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Retention and erasure of data: The following general periods apply to retention and archiving under Swiss law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers and invoices, as well as all necessary work instructions and other organizational documents (Art. 958f of the Swiss Code of Obligations (OR)).
- 10 years – Data necessary to take into account potential damage compensation claims or similar contractual claims and rights, as well as for processing related inquiries, based on previous business experience and customary industry practices, is stored for the period of the statutory limitation period of ten years, unless a shorter period of five years is decisive, which applies in certain cases (Art. 127, 130 OR). After five years, claims for rent, lease and capital interest as well as other periodic payments, from the supply of food, for board and lodging debts, as well as from craftsmanship, retail sale of goods, medical care, professional work of lawyers, legal agents, procurators and notaries, and from the employment relationship of employees expire (Art. 128 OR).
Commencement of the period at the end of the year: If a period does not expressly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the course of which data is stored, the event triggering the period is the time at which the termination or other ending of the legal relationship takes effect.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to access this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of the data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of the personal data concerning you infringes the GDPR.
Rights of data subjects under the Swiss DSG:
As a data subject, you are entitled to the following rights in accordance with the provisions of the Swiss DSG:
- Right of access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive the information necessary for you to assert your rights under this act and to ensure transparent data processing.
- Right to data disclosure or transfer: You have the right to request the disclosure of your personal data that you have provided to us in a commonly used electronic format.
- Right to rectification: You have the right to request the rectification of inaccurate personal data concerning you.
- Right to object, erasure and destruction: You have the right to object to the processing of your data, as well as to request that the personal data concerning you be erased or destroyed.
Business Processes and Procedures
Personal data of service recipients and clients – including customers, clients, or in special cases mandates, patients or business partners as well as other third parties – is processed in the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates economic operations in areas such as customer management, sales, payment transactions, accounting and project management.
The collected data serves to fulfill contractual obligations and to structure operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimization of sales strategies, and the safeguarding of internal invoicing and financial processes. In addition, the data supports the protection of the controller’s rights and promotes administrative tasks as well as the organization of the company.
Personal data may be disclosed to third parties, insofar as this is necessary to fulfill the stated purposes or legal obligations. After the expiry of statutory retention periods or when the purpose of the processing ceases to apply, the data is erased. This also includes data that must be stored for longer due to tax law and legal proof obligations.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Contract data (e.g. subject matter of the contract, term, customer category); Log data (e.g. log files concerning logins or the retrieval of data or access times.); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Employee data (information on employees and other persons in an employment relationship).
- Data subjects: Service recipients and clients; Interested parties; Communication partners; Business and contractual partners; Third parties; Users (e.g. website visitors, users of online services); Employees (e.g. staff, applicants, temporary workers and other employees). Customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Office and organizational procedures; Business processes and economic procedures; Communication; Marketing; Sales promotion; Public relations; Financial and payment management; Security measures. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR); Legitimate interests (Art. 6 (1) (f) GDPR). Legal obligation (Art. 6 (1) (c) GDPR).
Further information on processing operations, procedures and services:
- Customer management and Customer Relationship Management (CRM): Procedures necessary in the context of customer management and Customer Relationship Management (CRM) (e.g. customer acquisition in compliance with data protection requirements, measures to promote customer loyalty and retention, effective customer communication, complaint management and customer service with regard to data protection, data management and analysis to support the customer relationship, management of CRM systems, secure account management, customer segmentation and target group formation); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- Contact management and contact maintenance: Procedures necessary in the context of the organization, maintenance and securing of contact information (e.g. setting up and maintaining a central contact database, regular updates of the contact information, monitoring data integrity, implementing data protection measures, ensuring access controls, performing backups and restorations of the contact data, training employees in the effective use of contact management software, regularly reviewing communication history and adjusting contact strategies); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- General payment transactions: Procedures necessary for carrying out payment transactions, monitoring bank accounts and controlling payment flows (e.g. creating and checking transfers, processing direct debit transactions, checking account statements, monitoring incoming and outgoing payments, managing returned direct debits, account reconciliation, cash management); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- Accounting, accounts payable, accounts receivable: Procedures necessary for the recording, processing and control of business transactions in the area of accounts payable and accounts receivable (e.g. creating and checking incoming and outgoing invoices, monitoring and managing open items, carrying out payment transactions, processing the dunning system, account reconciliation in the context of receivables and payables, accounts payable accounting and accounts receivable accounting); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legal obligation (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- Financial accounting and taxes: Procedures necessary for the recording, management and control of financially relevant business transactions as well as for the calculation, reporting and payment of taxes (e.g. allocation and posting of business transactions, preparation of quarterly and annual financial statements, carrying out payment transactions, processing the dunning system, account reconciliation, tax advice, preparation and submission of tax returns, handling of tax matters); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legal obligation (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- Sales: Procedures necessary for the planning, implementation and control of measures for the marketing and sale of products or services (e.g. customer acquisition, quotation preparation and follow-up, order processing, customer advice and support, sales promotion, product training, sales controlling and analysis, management of sales channels); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- Marketing, advertising and sales promotion: Procedures necessary in the context of marketing, advertising and sales promotion (e.g. market analysis and target group determination, development of marketing strategies, planning and implementation of advertising campaigns, design and production of advertising materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programs, sales promotion measures, performance measurement and optimization of marketing activities, budget management and cost control); Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
- Public relations: Procedures necessary in the context of public relations (e.g. development and implementation of communication strategies, planning and implementation of PR campaigns, creation and distribution of press releases, maintenance of media contacts, monitoring and analysis of media response, organization of press conferences and public events, crisis communication, creation of content for social media and corporate websites, management of corporate branding); Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
- Guest Wi-Fi: Procedures necessary for the setup, operation, maintenance and monitoring of a wireless network for guests (e.g. installation and configuration of Wi-Fi access points, creation and management of guest accesses, monitoring of the network connection, ensuring network security, resolving connection problems, updating network software, compliance with data protection provisions); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legal obligation (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
Providers and Services Used in the Course of Business Activities
In the course of our business activities, and in compliance with the legal requirements, we use additional services, platforms, interfaces or plug-ins from third-party providers (in short “services”). Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organization.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; Interested parties; Business and contractual partners; Employees (e.g. staff, applicants, temporary workers and other employees). Communication partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Office and organizational procedures; Business processes and economic procedures; Communication. Marketing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- DATEV: Provision of cloud applications for accounting, payroll, document and data exchange as well as collaboration with tax advisors and companies. Processing, storage and transmission of data in data centers (servers) for the use of the respective applications; Service provider: DATEV eG, Paumgartnerstr. 6 – 14, 90429 Nuremberg, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.datev.de/web/de/mydatev/datev-cloud-anwendungen/; Privacy policy: https://www.datev.de/web/de/berufsgruppenuebergreifend/ueber-datev/datenschutz-und-compliance/datenschutz-und-unternehmenssicherheit. Data processing agreement: Provided by the service provider.
- Microsoft Dynamics: Customer relationship management, financial planning and analysis, supply chain operations, automation of business processes, human resources management and service optimization; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/de-de/dynamics-365; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement; Data processing agreement: Provided by the service provider. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF).
- UPS: Logistics company that offers shipping and delivery services. We share certain personal data with UPS to enable the shipping and delivery of parcels. This information may include the name, address and contact details of the recipients; Service provider: UPS Europe SA, Ave Ariane 5, Brussels, B-1200, Belgium; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.ups.com/. Privacy policy: https://www.ups.com/de/de/support/shipping-support/legal-terms-conditions/privacy-notice.page.
- DHL: Logistics company, shipping and delivery services. We share certain personal data with DHL to enable the shipping and delivery of parcels as well as shipment tracking and notifications to recipients. This information may include the name, address and contact details of the recipients; Service provider: Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: http://www.dhl.com/. Privacy policy: https://www.dhl.com/de-de/home/fusszeile/datenschutzhinweis.html.
Credit Check
Insofar as we make advance payments or take on comparable economic risks (e.g. in the case of orders on account), we reserve the right, in order to safeguard our legitimate interests, to obtain identity and credit information for the purpose of assessing the credit risk on the basis of mathematical-statistical procedures from service companies specialized in this (credit agencies).
We process the information received from the credit agencies on the statistical probability of a payment default within the framework of a proper exercise of discretion regarding the establishment, implementation and termination of the contractual relationship. We reserve the right, in the event of a negative result of the credit check, to refuse payment on account or another advance payment.
The decision as to whether we make advance payments is made, in accordance with the legal requirements, solely on the basis of an automated decision in the individual case, which our software makes on the basis of the information provided by the credit agency.
Insofar as we obtain the express consent of contractual partners, the legal basis for the credit report and the transmission of the customer’s data to the agencies is consent. If no consent is obtained, the credit report is provided on the basis of our legitimate interests in the reliability of payment of our payment claims.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter of the contract, term, customer category); Credit data (e.g. credit score received, estimated probability of default, resulting risk classification, historical payment behavior). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Service recipients and clients; Interested parties. Business and contractual partners.
- Purposes of processing and legitimate interests: Assessment of solvency and creditworthiness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
- Automated decisions in individual cases: Credit report (decision on the basis of a credit check).
Further information on processing operations, procedures and services:
- Verband der Vereine Creditreform e.V.: Credit agency; Service provider: Verband der Vereine Creditreform e.V., Hammfelddamm 13, 41460 Neuss, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.creditreform.de/. Privacy policy: https://www.creditreform.de/datenschutz.
Provision of the Online Offering and Web Hosting
We process users’ data in order to be able to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); Log data (e.g. log files concerning logins or the retrieval of data or access times.). Contact data (e.g. postal and email addresses or telephone numbers).
- Data subjects: Users (e.g. website visitors, users of online services). Interested parties.
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); Security measures; Communication; Direct marketing (e.g. by email or postal mail); Reach measurement (e.g. access statistics, recognition of returning visitors); Conversion measurement (measurement of the effectiveness of marketing measures); Target group formation; A/B testing. Marketing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Provision of online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called a “web host”); Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called “server log files”. The server log files may include the address and name of the retrieved web pages and files, the date and time of retrieval, the amount of data transmitted, notification of successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. The server log files can be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (particularly in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure the utilization of the servers and their stability; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymized. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
- United Domains: Services in the field of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: united-domains AG, Gautinger Straße 10, 82319 Starnberg, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.united-domains.de; Privacy policy: https://www.united-domains.de/unternehmen/datenschutz/. Data processing agreement: https://www.united-domains.de/help/faq-article/wie-erhalte-ich-den-auftragsverarbeitungs-vertrag-avv-nach-dsgvo/.
- Hubspot Forms: Creation and management of forms, collection and storage of user data, integration into websites and CRM systems, automation of follow-up emails, analysis of form performance, segmentation of data for targeted marketing campaigns; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.hubspot.com/products/marketing/forms; Privacy policy: https://legal.hubspot.com/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies can also be used for various purposes, e.g. for the functionality, security and convenience of online offerings, as well as for creating analyses of visitor flows. We use cookies in accordance with the legal provisions. To this end, where required, we obtain users’ consent in advance. If consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to be able to provide expressly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information on its scope and which cookies are used.
Notes on data protection legal bases: Whether we process personal data with the help of cookies depends on a consent. If consent exists, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage duration: With regard to the storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are erased at the latest after a user has left an online offering and closed their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device has been closed. This allows, for example, the login status to be stored and preferred content to be displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Insofar as we do not provide users with explicit information on the type and storage duration of cookies (e.g. in the context of obtaining consent), they should assume that these are permanent and that the storage duration can be up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw the consents they have given at any time and also object to the processing in accordance with the legal requirements, including by means of the privacy settings of their browser.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Consent (Art. 6 (1) (a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution in which the consent of users to the use of cookies or to the procedures and providers named within the consent management solution is obtained. This procedure serves to obtain, log, manage and withdraw consents, in particular relating to the use of cookies and comparable technologies used to store, read and process information on users’ devices. In the context of this procedure, users’ consents for the use of cookies and the associated processing of information, including the specific processing operations and providers named in the consent management procedure, are obtained. Users also have the option to manage and withdraw their consents. The declarations of consent are stored in order to avoid having to request them again and to be able to provide proof of consent in accordance with the legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies, in order to be able to assign the consent to a specific user or their device. Insofar as no specific information on the providers of consent management services is available, the following general information applies: The duration of the storage of the consent is up to two years. In doing so, a pseudonymous user identifier is created, which is stored together with the time of consent, the information on the scope of consent (e.g. relevant categories of cookies and/or service providers), and information about the browser, the system and the device used; Legal bases: Consent (Art. 6 (1) (a) GDPR).
- Cookie opt-out: In the footer of our website you will find a link through which you can change your cookie settings and withdraw the corresponding consents.
- BorlabsCookie: Storage and management of consents (agreement to cookies and data processing), logging of user decisions, display of information on data protection and cookies, enabling the withdrawal or adjustment of consents by users; Service provider: Execution on servers and/or computers under our own data protection responsibility; Website: https://de.borlabs.io/borlabs-cookie/. Further information: An individual user ID, language, as well as types of consents and the time they were given, are stored on the server side and in the cookie on the user’s device.
Contact and Inquiry Management
When you contact us (e.g. by postal mail, contact form, email, telephone or via social media) as well as within the framework of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; Organizational and administrative procedures; Feedback (e.g. collecting feedback via online form); Provision of our online offering and user-friendliness; Direct marketing (e.g. by email or postal mail); Reach measurement (e.g. access statistics, recognition of returning visitors); Conversion measurement (measurement of the effectiveness of marketing measures); Click tracking; Marketing. Profiles with user-related information (creation of user profiles).
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: When contacting us via our contact form, by email or other communication channels, we process the personal data transmitted to us in order to respond to and handle the respective matter. This usually includes information such as name, contact information and, if applicable, further information communicated to us and necessary for appropriate handling. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
- HubSpot CRM: Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support requests, AI-supported content generation, personalized email creation, predictive sales forecasts, automatic workflow descriptions and AI chatbots for customer interaction; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.hubspot.de/pa/crm; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).
- HubSpot WordPress: Collection of visitor data, analysis of user behavior, management of contacts, creation and management of forms, integration with email marketing tools, tracking of the interactions of website visitors; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://wordpress.org/plugins/leadin/; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).
Communication via Messenger
We use messengers for communication purposes and therefore ask you to observe the following information on the functionality of the messengers, on encryption, on the use of the metadata of the communication and on your options to object.
You can also contact us via alternative means, e.g. by telephone or email. Please use the contact options communicated to you or the contact options specified within our online offering.
In the case of end-to-end encryption of content (i.e. the content of your message and attachments), we point out that the communication content (i.e. the content of the message and attached images) is encrypted end-to-end. This means that the content of the messages is not visible, not even by the messenger providers themselves. You should always use a current version of the messengers with encryption enabled, so that the encryption of the message content is ensured.
However, we additionally point out to our communication partners that although the providers of the messengers do not view the content, they can find out that and when communication partners communicate with us, as well as that technical information about the device used by the communication partners and, depending on the settings of their device, also location information (so-called metadata) is processed.
Notes on legal bases: Insofar as we ask communication partners for permission before communicating with them via messenger, the legal basis of our processing of their data is their consent. Otherwise, if we do not ask for consent and they, for example, contact us on their own initiative, we use messengers in relation to our contractual partners as well as within the framework of contract initiation as a contractual measure, and in the case of other interested parties and communication partners on the basis of our legitimate interests in fast and efficient communication and meeting the needs of our communication partners for communication via messenger. Furthermore, we point out to you that we do not transmit the contact details communicated to us to the messengers for the first time without your consent.
Withdrawal, objection and erasure: You can withdraw a given consent at any time and object to communication with us via messenger at any time. In the case of communication via messenger, we erase the messages in accordance with our general erasure policies (i.e. e.g., as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) and otherwise as soon as we can assume that we have answered any inquiries of the communication partners, if no reference to a previous conversation is to be expected and there are no legal retention obligations that prevent erasure.
Reservation of the reference to other communication channels: To ensure your security, we ask for your understanding that for certain reasons we may not be able to respond to inquiries via messenger. This concerns situations in which, for example, contract details must be treated with particular confidentiality or a response via messenger does not meet the formal requirements. In these cases, we recommend that you resort to more suitable communication channels.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication. Direct marketing (e.g. by email or postal mail).
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Consent (Art. 6 (1) (a) GDPR); Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Sending messages via the social network Instagram; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/.
- Facebook Messenger: Sending and receiving text messages, making voice and video calls, creating group chats, sharing files and media, transmitting location information, synchronizing contacts, encrypting messages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- WhatsApp: A communication service that enables the sending and receiving of text messages, voice messages, images, videos, documents as well as voice and video calls over the internet. Communication takes place via end-to-end encryption, whereby content is only accessible to the communication partners involved. To provide the service, the platform processes metadata (e.g. telephone numbers, timestamps, device information) and may use this to improve functions, security and service optimization; Service provider: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.whatsapp.com/. Privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea.
Chatbots and Chat Functions
We offer online chats and chatbot functions as a communication option (together referred to as “chat services”). A chat is an online conversation conducted with a certain immediacy. A chatbot is software that answers users’ questions or informs them via messages. When you use our chat functions, we may process your personal data.
If you use our chat services within an online platform, your identification number within the respective platform is additionally stored. We can also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove them in accordance with legal requirements.
We point out to users that the respective platform provider can find out that and when users communicate with our chat services, as well as collect technical information about the device used by the users and, depending on the settings of their device, also location information (so-called metadata) for the purposes of optimizing the respective services and for security purposes. Likewise, the metadata of the communication via chat services (i.e. e.g. the information about who communicated with whom) could be used by the respective platform providers in accordance with their provisions, to which we refer for further information, for the purposes of marketing or for displaying advertising tailored to users.
Insofar as users agree to a chatbot to activate information with regular messages, they have the option at any time to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. By unsubscribing from the chatbot messages, users’ data is erased from the directory of message recipients.
We use the aforementioned information to operate our chat services, e.g. to address users personally, to answer their inquiries, to transmit any requested content, and also to improve our chat services (e.g. to “teach” chatbots answers to frequently asked questions or to recognize unanswered inquiries).
Notes on legal bases: We use the chat services on the basis of consent if we have previously obtained the users’ permission to process their data in the context of our chat services (this applies to cases in which users are asked for consent, e.g. so that a chatbot regularly sends them messages). Insofar as we use chat services to answer users’ inquiries about our services or our company, this takes place for contractual and pre-contractual communication. Otherwise, we use chat services on the basis of our legitimate interests in optimizing the chat services, their economic efficiency, and increasing the positive user experience.
Withdrawal, objection and erasure: You can withdraw a given consent at any time or object to the processing of your data in the context of our chat services.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Master data (e.g. full name, residential address, contact information, customer number, etc.); Contract data (e.g. subject matter of the contract, term, customer category). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners; Users (e.g. website visitors, users of online services). Business and contractual partners.
- Purposes of processing and legitimate interests: Communication; Provision of contractual services and fulfillment of contractual obligations; Marketing. Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Consent (Art. 6 (1) (a) GDPR); Performance of a contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- HubSpot chatbot software: Automation of customer interactions, answering of frequently asked questions, appointment scheduling, forwarding to human employees, integration with CRM systems for data storage and management, adaptation of conversations based on user behavior and preferences; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.hubspot.de/products/crm/chatbot-builder; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).o
- 3CX: Chat functions, video and audio conferences; Service provider: 3CX GmbH, Walter-Gieseking-Straße 22, 30519 Hannover, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.3cx.de/. Privacy policy: https://www.3cx.com/company/privacy/.
Artificial Intelligence (AI)
We use artificial intelligence (AI), whereby personal data is processed. The specific purposes and our interest in the use of AI are stated below. By AI we understand, in accordance with the concept of an “AI system” pursuant to Article 3 No. 1 of the AI Regulation, a machine-based system that is designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, from the input it receives, infers how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
Our AI systems are used in strict compliance with the legal requirements. These include both specific regulations for artificial intelligence and data protection requirements. In doing so, we comply in particular with the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimization, and integrity and confidentiality. We ensure that the processing of personal data always takes place on a legal basis. This can be either the consent of the data subjects or a legal permission.
When using external AI systems, we carefully select their providers (hereinafter “AI providers”). In accordance with our legal obligations, we ensure that the AI providers comply with the applicable provisions. Likewise, we observe the obligations incumbent upon us when using or operating the AI services obtained. The processing of personal data by us and the AI providers takes place exclusively on the basis of consent or legal authorization. In doing so, we place particular emphasis on transparency, fairness, and maintaining human oversight over AI-supported decision-making processes.
To protect the processed data, we implement appropriate and robust technical and organizational measures. These ensure the integrity and confidentiality of the processed data and minimize potential risks. Through regular reviews of the AI providers and their services, we ensure ongoing compliance with current legal and ethical standards.
- Types of data processed: Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g. website visitors, users of online services). Third parties.
- Purposes of processing and legitimate interests: Artificial intelligence (AI).
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- DeepL: Translation of texts into various languages and provision of synonyms as well as context examples. Support in the correction and improvement of texts in various languages; Service provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.deepl.com; Privacy policy: https://www.deepl.com/de/privacy. Data processing agreement: Provided by the service provider.
- Microsoft Copilot: Microsoft Copilot: Support in the creation and editing of texts, tables and presentations, analysis of data, automation of tasks and integration into Office applications. Processed are content data (files, conversations, metadata) as well as employee credentials (Org ID/Entra ID) for the purposes of efficiency and productivity increases, cost efficiency, flexibility, mobility and integration with M365. Chat histories are stored for up to 30 days, content until erasure by the user. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/de-de/microsoft-copilot/organizations; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Video Conferences, Online Meetings, Webinars and Screen Sharing
We use platforms and applications from other providers (hereinafter referred to as “conference platforms”) for the purposes of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conference”). When selecting the conference platforms and their services, we observe the legal requirements.
Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of the participants named below. The scope of the processing depends, on the one hand, on which data is required in the context of a specific conference (e.g. provision of access data or real names) and which optional information is provided by the participants. In addition to processing for conducting the conference, the participants’ data may also be processed by the conference platforms for security purposes or service optimization. The processed data includes personal data (first name, surname), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants’ devices, their operating system, the browser and its technical and language settings, information on the content-related communication processes, i.e. entries in chats as well as audio and video data, and the use of other available functions (e.g. surveys). The content of the communications is encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: If text entries, participation results (e.g. of surveys) as well as video or audio recordings are logged, this is transparently communicated to the participants in advance and they are – insofar as necessary – asked for consent.
Data protection measures of the participants: Please observe the details of the processing of your data by the conference platforms in their privacy information and, within the framework of the settings of the conference platforms, choose the security and data protection settings that are optimal for you. Furthermore, please ensure data and privacy protection in the background of your recording for the duration of a video conference (e.g. by informing housemates, locking doors and using, insofar as technically possible, the function to blur the background). Links to the conference rooms as well as access data must not be passed on to unauthorized third parties.
Notes on legal bases: Insofar as, in addition to the conference platforms, we also process the users’ data and ask users for their consent to the use of the conference platforms or certain functions (e.g. consent to a recording of conferences), the legal basis of the processing is this consent. Furthermore, our processing may be necessary to fulfill our contractual obligations (e.g. in participant lists, in the case of processing meeting results, etc.). Otherwise, the users’ data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Image and/or video recordings (e.g. photographs or video recordings of a person); Audio recordings; Log data (e.g. log files concerning logins or the retrieval of data or access times.); Contract data (e.g. subject matter of the contract, term, customer category). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners; Users (e.g. website visitors, users of online services); Depicted persons; Service recipients and clients; Interested parties. Participants.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Communication; Office and organizational procedures. Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Microsoft Teams: Use for conducting online events, conferences as well as communication with internal and external participants. Voice transmission, direct messages, group communication and collaboration functions are used; processed are name, business contact data, work profile, participation as well as content (audio/video, voice, chat, files, voice transcription) for the purposes of and interest in efficiency and productivity increases, cost efficiency, flexibility, mobility, improved communication, IT security, use of a central platform as well as business processing by Microsoft. Audio signals are generally not stored, except when recording is activated. Meeting and conference recordings are stored by default for 90 days, unless a different duration is specified. Chat and file content is stored according to the policies determined by the administrator or user; the default setting is no automatic erasure. Channels must be renewed every 180 days, otherwise the content is erased. In addition, system-generated log, diagnostic and metadata are processed, as well as diagnostic data collected for product stability, security and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/de-de/microsoft-teams/; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Cloud Services
We use software services accessible via the internet and executed on the servers of their providers (so-called “cloud services”, also referred to as “Software as a Service”) for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with certain recipients, or publication of content and information).
In this context, personal data may be processed and stored on the servers of the providers, insofar as this is part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact data of users, data on processes, contracts, other operations and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and service optimization.
Insofar as we provide forms or other documents and content for other users or publicly accessible websites with the help of the cloud services, the providers may store cookies on the users’ devices for the purposes of web analysis or to remember the users’ settings (e.g. in the case of media control).
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Interested parties; Communication partners; Business and contractual partners; Users (e.g. website visitors, users of online services). Third parties.
- Purposes of processing and legitimate interests: Office and organizational procedures; Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); Organizational and administrative procedures; Business processes and economic procedures. Provision of contractual services and fulfillment of contractual obligations.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Microsoft 365 and Microsoft cloud services: Provision of applications, protection of data and IT systems, as well as use of system-generated log, diagnostic and metadata for contract performance by Microsoft. Processed are contact data (name, email address), content data (files, comments, profiles), software setup and inventory data, device connectivity and configuration data, work interactions (badge swipe) as well as log and metadata. The processing takes place for the purposes of efficiency and productivity increases, cost efficiency, flexibility, mobility, improved communication, integration of Microsoft services, IT security and business processing by Microsoft. The retention of data is based on the respective documents and company policies, for Defender (protection of data and IT systems) up to 12 months, for print management 10 days. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/de-de; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement, Security information: https://www.microsoft.com/de-de/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
- Microsoft Sharepoint: Support of collaboration through storage and access management for documents, tables, presentations, etc. Processed are content data (files) as well as contact data (name, email address) for the purposes of and interest in efficiency and productivity increases, cost efficiency, flexibility, mobility, integration with M365 and improved collaboration. Retention is based on the business function of the content; SharePoint sites must be renewed every 180 days, otherwise the content is erased. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
- Microsoft 365 Outlook: Use of email and calendar functions for communication and organization of meetings. Processed are contact data (name, email address), content data (messages, attachments, meeting content) and metadata for the purposes of and interest in efficiency and productivity increases, cost efficiency, flexibility, mobility, improved communication and integration with M365. Retention of emails and calendar entries is based on the policies specified by the administrator or user; by default, no automatic erasure takes place. Mailboxes and calendars are generally removed 30 days after departure. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.microsoft.com/; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement, Security information: https://www.microsoft.com/de-de/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Newsletter and Electronic Notifications
We send newsletters, emails and further electronic notifications (hereinafter “newsletter”) exclusively with the consent of the recipients or on the basis of a legal basis. Insofar as the content of a newsletter is described during registration for it, this content is decisive for the users’ consent. To register for our newsletter, it is normally sufficient to provide your email address. However, in order to be able to offer you a personalized service, we may ask for your name for a personal address in the newsletter, or for further information if this is necessary for the purpose of the newsletter.
Erasure and restriction of processing: We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to prove a previously given consent. The processing of this data is restricted to the purpose of a potential defense against claims. An individual erasure request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (so-called “blocklist”).
The logging of the registration process takes place on the basis of our legitimate interests for the purpose of proving its proper conduct. Insofar as we commission a service provider with the sending of emails, this takes place on the basis of our legitimate interests in an efficient and secure sending system.
Content:
Information about us, our services, promotions and offers.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or postal mail).
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
- Option to object (opt-out): You can cancel the receipt of our newsletter at any time, i.e. withdraw your consents, or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter, or you can otherwise use one of the contact options specified above, preferably email, for this purpose.
Further information on processing operations, procedures and services:
- Measurement of open and click rates: The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from our server, or from that of the sending service provider if we use one, when the newsletter is opened. In the course of this retrieval, technical information such as details about the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This information is used for the technical improvement of our newsletter on the basis of the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. This information is assigned to the individual newsletter recipients and stored in their profiles until erasure. On this basis, user profiles are created in which usage behavior and user characteristics are stored. The measurement of open and click rates as well as the storage of the measurement results in the users’ profiles and their further processing take place on the basis of the users’ consent. A separate withdrawal of the success measurement is unfortunately not possible; in this case, the entire newsletter subscription must be cancelled or objected to. In that case, the stored profile information is erased; Legal bases: Consent (Art. 6 (1) (a) GDPR).
- Sending via SMS: The electronic notifications can also be sent as SMS text messages (or are sent exclusively via SMS if the sending authorization, e.g. a consent, only covers sending via SMS); Legal bases: Consent (Art. 6 (1) (a) GDPR).
- HubSpot email marketing: Sending of emails, creation of personalized campaigns, automation of workflows, segmentation of target groups, integration with CRM systems, analysis of performance through reports and dashboards; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.hubspot.com/products/marketing/email; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).
Promotional Communication via Email, Postal Mail, Fax or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as e.g. email, telephone, postal mail or fax, in accordance with the legal requirements.
Recipients have the right to withdraw given consents at any time or to object to the promotional communication at any time free of charge via the contact option specified above.
After withdrawal or objection, we store the data necessary to prove the previous authorization for contact or sending for up to three years after the end of the year of the withdrawal or objection on the basis of our legitimate interests. The processing of this data is restricted to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing the withdrawal or objection of the users, we also store the data necessary to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or postal mail); Marketing. Sales promotion.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Prize Draws and Raffles
We may occasionally conduct small prize draws or raffles in the context of trade fairs, congresses or comparable events. In doing so, we process the personal data provided by the participants, in particular name, contact data and, if applicable, company affiliation, exclusively for conducting the prize draw, for determining and notifying the winners, and for handing over or sending the prize.
The legal basis is the conduct of the prize draw or our legitimate interests in the proper organization and documentation of the campaign. Insofar as further promotional contact is to take place, this only takes place on the basis of a separate consent or another legal permission.
The participants’ data is erased as soon as the prize draw is completed and no further inquiries are to be expected, but at the latest after twelve months. Winners’ data may be stored for longer, insofar as this is necessary for handling the prize, for documentation or for fulfilling legal obligations.
Web Analysis, Monitoring and Optimization
Web analysis (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behavior, interests or demographic information about the visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offering or its functions or content are used most frequently, or invite reuse. Likewise, it is possible for us to understand which areas require optimization.
In addition to web analysis, we may also use test procedures, e.g. to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e. data combined into a usage process, may be created for these purposes, and information may be stored in a browser or in a device and then read out. The information collected includes, in particular, visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. Insofar as users have consented to the collection of their location data vis-à-vis us or vis-à-vis the providers of the services we use, the processing of location data is also possible.
In addition, the IP addresses of the users are stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users. In general, no plain-text data of the users (such as email addresses or names) is stored in the context of web analysis, A/B testing and optimization, but rather pseudonyms. This means that we, as well as the providers of the software used, do not know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.
Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is consent. Otherwise, the users’ data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); Profiles with user-related information (creation of user profiles); Provision of our online offering and user-friendliness; Tracking (e.g. interest/behavior-based profiling, use of cookies); Remarketing; Target group formation. Marketing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Google Analytics: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to assign analysis information to a device in order to recognize which content the users have accessed within one or various usage processes, which search terms they have used, have accessed again or have interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of the users referring to our online offering and technical aspects of their devices and browsers.
In doing so, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies can be used. Google Analytics does not log and store individual IP addresses for EU users. However, Analytics provides coarse geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively for this derivation of geolocation data before it is immediately erased. It is not logged, is not accessible and is not used for further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy policy: https://business.safety.google/privacy/; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://business.safety.google/adsprocessorterms), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses ( https://business.safety.google/adsprocessorterms); Option to object (opt-out): Opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing as well as of the data processed). - Google Tag Manager: We use Google Tag Manager, software from Google that enables us to manage so-called website tags centrally via a user interface. Tags are small code elements on our website that serve to record and analyze visitor activities. This technology supports us in improving our website and the content offered on it. Google Tag Manager itself does not create user profiles, does not store cookies with user profiles and does not carry out any independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when using Google Tag Manager, the users’ IP address is transmitted to Google, which is necessary for technical reasons in order to implement the services we use. Cookies may also be set in the process. However, this data processing only takes place if services are integrated via the Tag Manager. For more detailed information on these services and their data processing, we refer to the further sections of this privacy policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Data processing agreement:
https://business.safety.google/adsprocessorterms. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://business.safety.google/adsprocessorterms), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses ( https://business.safety.google/adsprocessorterms). - HubSpot Tracking Code: The tracking code and the tracking pixel collect visitor data, including website activities, IP addresses and online identifiers, in order to monitor website traffic and analyze user behavior. This data helps to identify visiting companies, assign visits to known contacts, and store information about browsers and devices. The insights obtained contribute to the optimization of the user experience and website performance. The collected data includes the company domain (in the case of self-identification by filling out a form or a registration), IP address, timestamp of the visits, visitor ID, page views, clicks and device information. In addition, interactions such as scroll behavior, dwell time on pages, navigation paths and referring URLs are collected in order to enable a more precise analysis of user behavior and detailed insights into visitor journeys. This data is processed on the basis of cookie consent and account settings, in order to improve digital services, create reports on website traffic and interactions, and refine strategies for optimizing content and user engagement. By analyzing user behavior, companies can adapt content in a targeted manner, improve conversion rates and optimize marketing measures. In addition, the collection serves to identify recurring visits, segment target groups and personalize user experiences based on past interactions. Furthermore, the tracking mechanisms enable companies to track leads and evaluate the effectiveness of marketing campaigns by analyzing click rates, form submissions and interactions with call-to-action elements. This data helps to optimize strategies, address target groups more specifically and maximize interaction with digital content; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://knowledge.hubspot.com/account/how-does-hubspot-track-visitors; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Standard contractual clauses (https://legal.hubspot.com/dpa).
- HubSpot Analytics: Web analysis, reach measurement and analysis of user behavior with regard to use and interests concerning functions and content as well as their duration of use on the basis of a pseudonymous user identification number and profiling; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://www.hubspot.com/products/marketing/analytics; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://legal.hubspot.com/dpa).
- RankMath: Analysis and optimization of meta titles and meta descriptions (texts for search engines), generation of sitemaps (overview of all pages of a website), monitoring of technical SEO errors (problems with discoverability by search engines), management of structured data (additional information for search engines); Service provider: ONE.COM INDIA PRIVATE LIMITED, Office No. 2, 5th Floor, Tower A, Building 9 DLF Cyber City Complex, Phase III, 122002 Gurgaon, India; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://rankmath.com. Privacy policy: https://rankmath.com/de/privacy-policy/.
Online Marketing
We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “content”) based on the potential interests of users, as well as the measurement of their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (the so-called “cookie”), or similar procedures are used, by means of which the information about the user relevant for displaying the aforementioned content is stored. This may include, for example, viewed content, visited websites, online networks used, but also communication partners and technical information, such as the browser used, the computer system used, and information on usage times and functions used. Insofar as users have consented to the collection of their location data, this may also be processed.
In addition, the IP addresses of the users are stored. However, we use available IP masking procedures (i.e. pseudonymization by shortening the IP address) to protect users. In general, no plain-text data of the users (such as email addresses or names) is stored in the context of the online marketing procedure, but rather pseudonyms. This means that we, as well as the providers of the online marketing procedures, do not know the actual user identity, but only the information stored in their profiles.
The information in the profiles is generally stored in the cookies or by means of similar procedures. These cookies can later generally also be read out on other websites that use the same online marketing procedure and analyzed for the purpose of displaying content, as well as supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases, it is possible to assign plain-text data to the profiles, primarily if the users are, for example, members of a social network whose online marketing procedure we use and the network connects the user profiles with the aforementioned information. We ask you to note that users can make additional agreements with the providers, for example by consent within the framework of registration.
In principle, we only receive access to summarized information on the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to the conclusion of a contract with us. The conversion measurement is used solely for the analysis of the success of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.
Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is permission. Otherwise, the users’ data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Notes on withdrawal and objection:
We refer to the privacy information of the respective providers and the options to object (so-called “opt-out”) specified for the providers. Insofar as no explicit opt-out option has been specified, there is, on the one hand, the possibility that you disable cookies in the settings of your browser. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered in summary form directed at the respective areas:
a) Europe: https://youronlinechoices.eu/.
b) Canada: https://youradchoices.ca/.
c) USA: https://optout.aboutads.info/.
d) Cross-regional: https://optout.aboutads.info.
- Types of data processed: Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); Event data (Facebook) (“Event data” is information that is sent, for example, via Meta pixels (whether via apps or other channels) to the provider Meta and relates to persons or their actions. This data includes, for example, details of website visits, interactions with content and functions, app installations as well as product purchases. The processing of the event data takes place with the aim of creating target groups for content and advertising messages (Custom Audiences). It is important to note that event data does not include actual content such as written comments, no login information and no contact information such as names, email addresses or telephone numbers. “Event data” is erased by Meta after a maximum of two years, and the target groups formed from it disappear with the erasure of our Meta user accounts.). Master data (e.g. full name, residential address, contact information, customer number, etc.).
- Data subjects: Users (e.g. website visitors, users of online services). Service recipients and clients.
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); Tracking (e.g. interest/behavior-based profiling, use of cookies); Conversion measurement (measurement of the effectiveness of marketing measures); Target group formation; Marketing; Profiles with user-related information (creation of user profiles); Provision of our online offering and user-friendliness. Remarketing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Meta Pixel and target group formation (Custom Audiences): With the help of the Meta Pixel (or comparable functions, for the transmission of event data or contact information by means of interfaces in apps), it is possible for the company Meta, on the one hand, to determine the visitors of our online offering as a target group for the display of advertisements (so-called “Meta Ads”). Accordingly, we use the Meta Pixel to display the Meta Ads placed by us only to those users on platforms of Meta and within the services of the partners cooperating with Meta (so-called “Audience Network” https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interest in certain topics or products, which are evident from the websites visited) that we transmit to Meta (so-called “Custom Audiences”). With the help of the Meta Pixel, we also want to ensure that our Meta Ads correspond to the potential interest of the users and are not annoying. With the help of the Meta Pixel, we can also track the effectiveness of the Meta Ads for statistical and market research purposes by seeing whether users were forwarded to our website after clicking on a Meta Ad (so-called “conversion measurement”); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further information: Event data of the users, i.e. behavioral and interest information, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint responsibility (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum). The joint responsibility is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Google Ad Manager: We use the “Google Ad Manager” service to place advertisements in the Google advertising network (e.g. in search results, in videos, on websites, etc.). Google Ad Manager is characterized by the fact that advertisements are displayed in real time based on the presumed interests of the users. This allows us to display advertisements for our online offering to users who could have a potential interest in our offering or who had previously been interested in it, as well as to measure the success of the advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF); Further information: Types of processing as well as of the data processed: https://business.safety.google/adsservices/; Data processing terms for Google advertising products: Information on the services Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms. insofar as Google acts as a processor, Data processing terms for Google advertising products and standard contractual clauses for third-country transfers of data: https://business.safety.google/adsprocessorterms.
- Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the advertising network of the service provider (e.g. in search results, in videos, on websites, etc.), so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether the users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF); Further information: Types of processing as well as of the data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
- Google Ads Remarketing: Google Remarketing, also called retargeting, is a technology with which users who use an online service are included in a pseudonymous remarketing list, so that advertisements can be displayed to the users on other online offerings on the basis of their visit to the online service; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF); Further information: Types of processing as well as of the data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
- Google Adsense with personalized advertisements: We integrate the Google Adsense service, which makes it possible to place personalized advertisements within our online offering. Google Adsense analyzes user behavior and uses this data to display targeted advertising that is tailored to the interests of our visitors. For each ad placement or other use of these advertisements, we receive financial compensation; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF); Further information: Types of processing as well as of the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: Information on the services Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
- Facebook Conversions API: We use the “Conversions API” from Facebook. The Conversions API is an interface with which event data is sent directly from our servers to Facebook. The functioning and the processing of data in the context of the Conversions API corresponds to the functioning and processing in the context of the use of the Facebook Pixel, which is why we refer in this respect to the privacy information on the Facebook Pixel and target group formation; Legal bases: Consent (Art. 6 (1) (a) GDPR).
- LinkedIn advertisements: Placement of advertisements within the LinkedIn platform and evaluation of the ad results; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://business.linkedin.com/de-de/marketing-solutions/ads; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Data processing agreement: https://www.linkedin.com/legal/l/dpa; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://de.linkedin.com/legal/l/dpa), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://de.linkedin.com/legal/l/dpa); Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. Further information: https://www.linkedin.com/legal/l/dpa.
Customer Reviews and Rating Procedures
We participate in review and rating procedures in order to evaluate, optimize and promote our services. If users rate us via the participating rating platforms or procedures or otherwise give feedback, the general terms and conditions or terms of use and the privacy information of the providers additionally apply. As a rule, the rating also requires registration with the respective providers.
In order to ensure that the rating persons have actually made use of our services, we transmit the data necessary for this regarding the customer and the service used to the respective rating platform (including name, email address and order number or article number) with the consent of the customers. This data is used solely to verify the authenticity of the user.
- Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form). Marketing.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Google Customer Reviews: Service for obtaining and/or displaying customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.google.com/; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF); Further information: In the context of obtaining customer reviews, an identification number and time for the business transaction to be rated, in the case of review requests sent directly to customers the customer’s email address as well as their information on the country of residence, and the review information itself are processed; Further information on the types of processing as well as of the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: Information on the services Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
Presences in Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the area of the European Union. This may result in risks for the users, because, for example, the enforcement of user rights could be made more difficult.
Furthermore, the users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of the usage behavior and the resulting interests of the users. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For this purpose, cookies are generally stored on the users’ computers, in which the usage behavior and the interests of the users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (in particular if they are members of the respective platforms and are logged in there).
For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the privacy policies and information of the operators of the respective networks.
Also in the case of requests for information and the assertion of data subjects’ rights, we point out that these can be asserted most effectively with the providers. Only the latter each have access to the users’ data and can directly take appropriate measures and provide information. Should you nevertheless need help, you can contact us.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Master data (e.g. full name, residential address, contact information, customer number, etc.). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; Feedback (e.g. collecting feedback via online form); Public relations; Marketing. Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Consent (Art. 6 (1) (a) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Social network, enables the sharing of photos and videos, the commenting on and favoriting of posts, the sending of messages, the following of profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF).
- Facebook pages: Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of the visitors of our Facebook page (“fan page”). This includes, in particular, information on user behavior (e.g. viewed or interacted content, actions carried out) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details on this can be found in the Facebook Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations via the “Page Insights” service, which give information on how people interact with our page and its content. The basis for this is an agreement with Facebook (“Information on Page Insights”: https://www.facebook.com/legal/terms/page_controller_addendum), in which, among other things, security measures as well as the exercise of data subjects’ rights are regulated. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users can therefore direct requests for information or erasure directly to Facebook. The rights of the users (in particular access, erasure, objection, complaint to a supervisory authority) remain unaffected by this. The joint responsibility is limited exclusively to the collection of the data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for the further processing, including a possible transmission to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- LinkedIn: Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of the visitors that is used to create the “Page Insights” (statistics) of our LinkedIn profiles. This data includes information about the types of content that users view or interact with, as well as the actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from the user profiles, such as job function, country, industry, hierarchy level, company size and employment status. Data protection information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
We have concluded a special agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill the rights of the data subjects (i.e. users can, for example, direct requests for information or erasure directly to LinkedIn). The rights of the users (in particular the right to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection and transmission of the data to LinkedIn Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular as regards the transmission of the data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard contractual clauses (https://www.linkedin.com/legal/privacy-policy), Switzerland – Data Privacy Framework (DPF), Standard contractual clauses (https://www.linkedin.com/legal/privacy-policy). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - TikTok Business: Social network, enables the sharing of photos and videos, the commenting on and favoriting of posts, the sending of messages, the following of accounts – We and TikTok are jointly responsible for the collection and transmission of event data as well as for the measurement and creation of insights reports (statistics) for profile owners. This event data includes information on the types of content that users view or interact with, or the actions they take, as well as information about the devices used by the users (e.g. IP addresses, operating system, browser type, language settings, cookie data) and information from the users’ profile, such as country or location. Data protection information on the processing of users’ data by TikTok can be found in TikTok’s privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/de. We have concluded a special agreement on joint responsibility with TikTok, which regulates in particular which security measures TikTok must observe and in which TikTok has agreed to fulfill the data subjects’ rights (i.e. users can, for example, direct requests for information or erasure directly to TikTok). The rights of the users (in particular to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with TikTok. The agreement on joint responsibility can be found in TikTok’s “Jurisdiction Specific Terms”: https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms.; Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://www.tiktok.com; Privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/de. Basis for third-country transfers: EU/EEA – Standard contractual clauses (https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms), Switzerland – Standard contractual clauses (https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms).
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF). Option to object (opt-out): https://myadcenter.google.com/.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These can be, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process the users’ IP address, since without the IP address they could not send the content to their browser. The IP address is thus necessary for the display of this content or functions. We endeavor to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and the operating system, referring websites, the time of visit, and further information on the use of our online offering, but may also be connected with such information from other sources.
Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is permission. Otherwise, the user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Location data (information on the geographical position of a device or a person).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; Reach measurement (e.g. access statistics, recognition of returning visitors); Tracking (e.g. interest/behavior-based profiling, use of cookies); Target group formation. Marketing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Legal bases: Consent (Art. 6 (1) (a) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Google Fonts (provision on our own server): Provision of font files for the purpose of a user-friendly display of our online offering; Service provider: The Google Fonts are hosted on our server, no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
- Google Fonts (obtained from the Google server): Obtaining fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to timeliness and loading times, their uniform display and consideration of possible license restrictions. The provider of the fonts is informed of the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server of the provider of the fonts in the USA – When visiting our online offering, the users’ browsers send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving the fonts). The Google Fonts Web API provides the users with the Cascading Style Sheets (CSS) of Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of the website visitors, as well as the referrer URL (i.e. the web page on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent must adapt the font that is generated for the respective browser type. The user agent is logged and used primarily for debugging and to generate aggregated usage statistics with which the popularity of font families is measured. These summarized usage statistics are published on the “Analytics” page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for the maintenance of production and an aggregated report on the top integrations based on the number of font requests can be generated. According to its own information, Google does not use any of the information collected by Google Fonts to create profiles of end users or to display targeted advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://fonts.google.com/; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
- Google Maps: We integrate the maps of the “Google Maps” service from the provider Google. The processed data may include, in particular, IP addresses and location data of the users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://business.safety.google/privacy/. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF).
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) (a) GDPR); Website: https://www.youtube.com; Privacy policy: https://business.safety.google/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Switzerland – Data Privacy Framework (DPF). Option to object (opt-out): Opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.
Management, Organization and Tools
We use services, platforms and software from other providers (hereinafter referred to as “third-party providers”) for the purposes of the organization, administration, planning and provision of our services. When selecting the third-party providers and their services, we observe the legal requirements.
In this context, personal data may be processed and stored on the servers of the third-party providers. This may affect various data that we process in accordance with this privacy policy. This data may include, in particular, master data and contact data of users, data on processes, contracts, other operations and their content.
Insofar as users are referred to the third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security purposes, service optimization or marketing purposes. We therefore ask you to observe the privacy information of the respective third-party providers.
- Types of data processed: Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); Master data (e.g. full name, residential address, contact information, customer number, etc.). Contact data (e.g. postal and email addresses or telephone numbers).
- Data subjects: Communication partners; Users (e.g. website visitors, users of online services); Service recipients and clients; Interested parties; Business and contractual partners. Participants.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Office and organizational procedures; Communication. Organizational and administrative procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Storage and Erasure”.
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- The Events Calendar: Creation and management of events, display in calendar view or list view, integration with Google Maps for event locations, support for recurring events, import of events from other calendars, customization of the event fields, enabling of RSVPs and ticket sales; Service provider: Execution on servers and/or computers under our own data protection responsibility; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Website: https://wordpress.org/plugins/the-events-calendar/.
Application Procedure
When you apply to us, we process the personal data transmitted by you exclusively for conducting the application procedure and for deciding on the establishment of an employment relationship. This includes, in particular, your contact data, application documents, information on qualifications and career, as well as further information that you provide to us in the context of the application.
The legal basis is Art. 6 (1) (b) GDPR in conjunction with § 26 BDSG. Insofar as special categories of personal data are transmitted, the processing only takes place insofar as this is legally required or you provide this data voluntarily.
If no employment relationship comes about, we generally erase the application data at the latest six months after the completion of the application procedure, insofar as no longer storage is necessary for the establishment, exercise or defense of legal claims or you have consented to a longer storage.
Amendment and Update
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or another individual notification.
Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, we ask you to note that the addresses may change over time and ask you to check the information before contacting them.
Definitions of Terms
In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are legally defined, their legal definitions apply. The following explanations, on the other hand, are intended primarily to aid understanding.
- A/B testing: A/B testing serves to improve the user-friendliness and performance of online offerings. For this purpose, users are shown, for example, different versions of a web page or its elements, such as input forms, on which the placement of the content or the labels of the navigation elements may differ. Subsequently, on the basis of the users’ behavior, e.g. longer dwell time on the web page or more frequent interaction with the elements, it can be determined which of these web pages or elements better correspond to the needs of the users.
- Employees: Employees are persons who are in an employment relationship, whether as staff, employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee, which is established by an employment contract or an agreement. It includes the employer’s obligation to pay the employee remuneration, while the employee provides their work performance. The employment relationship comprises various phases, including the establishment, in which the employment contract is concluded, the performance, in which the employee carries out their work activity, and the termination, when the employment relationship ends, whether by dismissal, termination agreement or otherwise. Employee data is all information relating to these persons and in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank data, working hours, vacation entitlements, health data and performance assessments.
- Master data: Master data includes essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, among other things, personal and demographic information such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between persons and services, facilities or systems, by enabling a unique assignment and communication.
- Credit report: Automated decisions are based on automatic data processing without human involvement (e.g. in the case of an automatic rejection of a purchase on account, an online credit application or an online application procedure without any human intervention). Such automated decisions are only permissible under Art. 22 GDPR if data subjects consent, if they are necessary for the performance of a contract, or if national laws permit these decisions.
- Content data: Content data comprises information generated in the course of the creation, editing and publication of content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not only limited to the actual content, but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication data
- Click tracking: Click tracking makes it possible to survey the movements of users within an entire online offering. Since the results of these tests are more accurate if the interaction of the users can be tracked over a certain period of time (e.g. so that we can find out whether a user likes to return), cookies are generally stored on the users’ computers for these test purposes.
- Contact data: Contact data is essential information that enables communication with persons or organizations. It includes, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Conversion measurement: Conversion measurement (also referred to as “visit action evaluation”) is a procedure with which the effectiveness of marketing measures can be determined. For this purpose, a cookie is generally stored on the users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, this allows us to understand whether the advertisements we have placed on other websites were successful.
- Artificial intelligence (AI): The purpose of the processing of data by artificial intelligence (AI) comprises the automated analysis and processing of user data in order to recognize patterns, make predictions and improve the efficiency and quality of our services. This includes the collection, cleansing and structuring of the data, the training and application of AI models, and the continuous review and optimization of the results, and takes place exclusively with the consent of the users or on the basis of statutory grounds for permission.
- Performance and behavioral data: Performance and behavioral data refers to information relating to how persons perform tasks or behave in a particular context, such as in an educational, work or social environment. This data may include metrics such as productivity, efficiency, work quality, attendance and compliance with policies or procedures. Behavioral data could include interactions with colleagues, communication styles, decision-making processes and reactions to various situations. These types of data are often used for performance assessments, training and development measures, and decision-making within organizations.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the manner in which data is processed, transmitted and managed. Metadata, also known as data about data, comprises information that describes the context, origin and structure of other data. It may include information on the file size, the creation date, the author of a document and the modification histories. Communication data captures the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organizations, including workflow documentation, logs of transactions and activities, as well as audit logs used for the tracking and review of operations.
- Usage data: Usage data refers to information that captures how users interact with digital products, services or platforms. This data comprises a wide range of information showing how users use applications, which functions they prefer, how long they dwell on certain pages and through which paths they navigate through an application. Usage data may also include the frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for the analysis of user behavior, the optimization of user experiences, the personalization of content and the improvement of products or services. In addition, usage data plays a decisive role in recognizing trends, preferences and possible problem areas within digital offerings
- Personal data: “Personal data” is any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, comprises any type of automated processing of personal data that consists of using this personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information concerning demographics, behavior and interests, such as the interaction with websites and their content, etc.) (e.g. the interests in certain content or products, the click behavior on a website or the whereabouts). Cookies and web beacons are frequently used for the purposes of profiling.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used for the analysis of system problems, for security monitoring or for the creation of performance reports.
- Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may include the behavior or interests of the visitors in certain information, such as content of web pages. With the help of reach analysis, operators of online offerings can, for example, recognize at what time users visit their web pages and which content they are interested in. As a result, they can, for example, better adapt the content of the web pages to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used in order to recognize returning visitors and thus obtain more precise analyses on the use of an online offering.
- Remarketing: “Remarketing” or “retargeting” is when, for example, for advertising purposes, a note is made of which products a user has been interested in on a website, in order to remind the user of these products on other websites, e.g. in advertisements.
- Location data: Location data is generated when a mobile device (or another device with the technical prerequisites for location determination) connects to a radio cell, a Wi-Fi or similar technical means and functions for location determination. Location data serves to indicate at which geographically determinable position on earth the respective device is located. Location data can be used, for example, to display map functions or other location-dependent information.
- Tracking: “Tracking” is when the behavior of users can be traced across multiple online offerings. Generally, behavior and interest information with regard to the online offerings used is stored in cookies or on servers of the providers of the tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to the users that presumably correspond to their interests.
- Controller: The “controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: “Processing” is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and encompasses practically any handling of data, whether it be collection, evaluation, storage, transmission or erasure.
- Contract data: Contract data is specific information relating to the formalization of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This data category is essential for the management and fulfillment of contractual obligations and comprises both the identification of the contractual parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of agreed services or products, price agreements, payment terms, termination rights, renewal options and special conditions or clauses. It serves as a legal basis for the relationship between the parties and is decisive for the clarification of rights and obligations, the enforcement of claims and the resolution of disputes.
- Payment data: Payment data comprises all information required for the processing of payment transactions between buyers and sellers. This data is of decisive importance for electronic commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and invoice information. Payment data may also contain information about the payment status, chargebacks, authorizations and fees.
- Target group formation: Target group formation (English “Custom Audiences”) is when target groups are determined for advertising purposes, e.g. the display of advertisements. For example, on the basis of a user’s interest in certain products or topics on the internet, it can be concluded that this user is interested in advertisements for similar products or the online shop in which they viewed the products. “Lookalike Audiences” (or similar target groups), in turn, is when the content assessed as suitable is displayed to users whose profiles or interests presumably correspond to the users for whom the profiles were formed. For the purposes of forming Custom Audiences and Lookalike Audiences, cookies and web beacons are generally used.