Language switch

Privacy Policy

Preamble

With the following privacy policy we would like to inform you about which types of your personal data (hereinafter also referred to briefly as “data”) we process, for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender-specific.

Last updated: June 22, 2026

Controller

BRUMABA GmbH
Bürgermeister-Graf-Ring 17
82538 Geretsried

Authorized representatives: Benedikt Brustmann, Sebastian Brustmann

Email address: info@brumaba.de

Telephone: +49 (0) 8171 / 2672 – 18

Legal notice: https://www.brumaba.de/impressum/

Contact for the Data Protection Officer

Jürgen Dichtl
DSB@brumaba.de

Overview of Processing Operations

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects concerned.

Types of data processed

Special categories of data

Categories of data subjects

Purposes of processing

Automated decisions in individual cases

Relevant Legal Bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. These include in particular the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.

Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (in short “Swiss DSG”). Unlike the GDPR, for example, the Swiss DSG in principle does not stipulate that a legal basis for the processing of personal data must be named, and that the processing of personal data is carried out in good faith, lawfully and proportionately (Art. 6 (1) and (2) of the Swiss DSG). In addition, personal data is only obtained by us for a specific purpose that is identifiable to the data subject and is only processed in a manner compatible with that purpose (Art. 6 (3) of the Swiss DSG).

Note on the applicability of the GDPR and the Swiss DSG: This privacy information serves to provide information both under the Swiss DSG and under the General Data Protection Regulation (GDPR). For this reason, we ask you to note that, due to the broader geographical application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms “bearbeitung” (processing) of “Personendaten” (personal data), “überwiegendes Interesse” (overriding interest) and “besonders schützenswerte Personendaten” (particularly sensitive personal data) used in the Swiss DSG, the terms “processing” of “personal data” as well as “legitimate interest” and “special categories of data” used in the GDPR are used. However, the legal meaning of the terms continues to be determined under the Swiss DSG within the scope of the Swiss DSG’s applicability.

Security Measures

In accordance with the legal requirements and taking into account the state of the art, the implementation costs and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability and separation relating to it. Furthermore, we have set up procedures that ensure the exercise of data subjects’ rights, the erasure of data and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and through data protection-friendly default settings.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signaled by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transmission of Personal Data

In the course of our processing of personal data, it may happen that this data is transmitted to other entities, companies, legally independent organizational units or persons, or that it is disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

Data transmission within the group of companies: Data transmission within the group of companies: We may transmit personal data to other companies within our group of companies or grant them access to it. This data sharing takes place on the basis of our legitimate entrepreneurial and economic interests. This includes, for example, the improvement of business processes, ensuring efficient and effective internal communication, the optimal use of our human and technological resources, and the ability to make informed business decisions. In certain cases, the data sharing may also be necessary to fulfill our contractual obligations, or it must be based on the consent of the data subjects or a legal permission.

Data transmission within the organization: We may transmit personal data to other departments or units within our organization or grant them access to it. Insofar as the data sharing takes place for administrative purposes, it is based on our legitimate entrepreneurial and economic interests, or it takes place insofar as it is necessary to fulfill our contractual obligations, or when consent of the data subjects or a legal permission exists.

Disclosure to third-party dealers: To process business inquiries, personal data may be disclosed to authorized dealers or sales partners, insofar as this is necessary to respond to the inquiry or to carry out pre-contractual measures.

International Data Transfers

Data processing in third countries: Insofar as we transmit data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or this occurs in the context of using third-party services or disclosing or transmitting data to other persons, entities or companies (which is recognizable from the postal address of the respective provider or if the privacy policy expressly refers to the data transfer to third countries), this always takes place in accordance with the legal requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated 07/10/2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.

This twofold safeguard ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes occur within the framework of the DPF, the standard contractual clauses come into effect as a reliable fallback option. In this way, we ensure that your data always remains appropriately protected, even in the event of any political or legal changes.

For the individual service providers, we inform you as to whether they are certified under the DPF and whether standard contractual clauses exist. Further information on the DPF and a list of the certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, corresponding security measures apply, in particular standard contractual clauses, explicit consents or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

Disclosure of personal data abroad: In accordance with the Swiss DSG, we only disclose personal data abroad if adequate protection of the data subjects is ensured (Art. 16 Swiss DSG). Insofar as the Federal Council has not determined adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of Switzerland dated September 15, 2024. In addition, we have concluded standard data protection clauses with the respective providers that have been approved by the Federal Data Protection and Information Commissioner (FDPIC) and establish contractual obligations to protect your data.

This twofold safeguard ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard data protection clauses serve as additional security. Should changes occur within the framework of the DPF, the standard data protection clauses come into effect as a reliable fallback option. In this way, we ensure that your data always remains appropriately protected, even in the event of any political or legal changes.

For the individual service providers, we inform you as to whether they are certified under the DPF and whether standard data protection clauses exist. The list of the certified companies as well as further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, corresponding security measures apply, including international treaties, specific guarantees, standard data protection clauses approved by the FDPIC, or binding corporate data protection rules previously recognized by the FDPIC or a competent data protection authority of another country.

General Information on Data Storage and Erasure

We erase personal data that we process in accordance with the legal provisions as soon as the underlying consents are revoked or no further legal bases for the processing exist. This concerns cases in which the original purpose of the processing ceases to apply or the data is no longer needed. Exceptions to this rule exist when legal obligations or special interests require a longer storage or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy information contains additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where multiple retention periods or erasure deadlines are specified for a piece of data, the longest period is always decisive. Data that is no longer retained for the originally intended purpose but due to legal requirements or other reasons is processed exclusively for the reasons that justify its retention.

Retention and erasure of data: The following general periods apply to retention and archiving under German law:

Retention and erasure of data: The following general periods apply to retention and archiving under Swiss law:

Commencement of the period at the end of the year: If a period does not expressly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the course of which data is stored, the event triggering the period is the time at which the termination or other ending of the legal relationship takes effect.

Rights of Data Subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

Rights of data subjects under the Swiss DSG:

As a data subject, you are entitled to the following rights in accordance with the provisions of the Swiss DSG:

Business Processes and Procedures

Personal data of service recipients and clients – including customers, clients, or in special cases mandates, patients or business partners as well as other third parties – is processed in the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates economic operations in areas such as customer management, sales, payment transactions, accounting and project management.

The collected data serves to fulfill contractual obligations and to structure operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimization of sales strategies, and the safeguarding of internal invoicing and financial processes. In addition, the data supports the protection of the controller’s rights and promotes administrative tasks as well as the organization of the company.

Personal data may be disclosed to third parties, insofar as this is necessary to fulfill the stated purposes or legal obligations. After the expiry of statutory retention periods or when the purpose of the processing ceases to apply, the data is erased. This also includes data that must be stored for longer due to tax law and legal proof obligations.

Further information on processing operations, procedures and services:

Providers and Services Used in the Course of Business Activities

In the course of our business activities, and in compliance with the legal requirements, we use additional services, platforms, interfaces or plug-ins from third-party providers (in short “services”). Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organization.

Further information on processing operations, procedures and services:

Credit Check

Insofar as we make advance payments or take on comparable economic risks (e.g. in the case of orders on account), we reserve the right, in order to safeguard our legitimate interests, to obtain identity and credit information for the purpose of assessing the credit risk on the basis of mathematical-statistical procedures from service companies specialized in this (credit agencies).

We process the information received from the credit agencies on the statistical probability of a payment default within the framework of a proper exercise of discretion regarding the establishment, implementation and termination of the contractual relationship. We reserve the right, in the event of a negative result of the credit check, to refuse payment on account or another advance payment.

The decision as to whether we make advance payments is made, in accordance with the legal requirements, solely on the basis of an automated decision in the individual case, which our software makes on the basis of the information provided by the credit agency.

Insofar as we obtain the express consent of contractual partners, the legal basis for the credit report and the transmission of the customer’s data to the agencies is consent. If no consent is obtained, the credit report is provided on the basis of our legitimate interests in the reliability of payment of our payment claims.

Further information on processing operations, procedures and services:

Provision of the Online Offering and Web Hosting

We process users’ data in order to be able to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.

Further information on processing operations, procedures and services:

Use of Cookies

The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies can also be used for various purposes, e.g. for the functionality, security and convenience of online offerings, as well as for creating analyses of visitor flows. We use cookies in accordance with the legal provisions. To this end, where required, we obtain users’ consent in advance. If consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to be able to provide expressly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information on its scope and which cookies are used.

Notes on data protection legal bases: Whether we process personal data with the help of cookies depends on a consent. If consent exists, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.

Storage duration: With regard to the storage duration, the following types of cookies are distinguished:

General information on withdrawal and objection (opt-out): Users can withdraw the consents they have given at any time and also object to the processing in accordance with the legal requirements, including by means of the privacy settings of their browser.

Further information on processing operations, procedures and services:

Contact and Inquiry Management

When you contact us (e.g. by postal mail, contact form, email, telephone or via social media) as well as within the framework of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.

Further information on processing operations, procedures and services:

Communication via Messenger

We use messengers for communication purposes and therefore ask you to observe the following information on the functionality of the messengers, on encryption, on the use of the metadata of the communication and on your options to object.

You can also contact us via alternative means, e.g. by telephone or email. Please use the contact options communicated to you or the contact options specified within our online offering.

In the case of end-to-end encryption of content (i.e. the content of your message and attachments), we point out that the communication content (i.e. the content of the message and attached images) is encrypted end-to-end. This means that the content of the messages is not visible, not even by the messenger providers themselves. You should always use a current version of the messengers with encryption enabled, so that the encryption of the message content is ensured.

However, we additionally point out to our communication partners that although the providers of the messengers do not view the content, they can find out that and when communication partners communicate with us, as well as that technical information about the device used by the communication partners and, depending on the settings of their device, also location information (so-called metadata) is processed.

Notes on legal bases: Insofar as we ask communication partners for permission before communicating with them via messenger, the legal basis of our processing of their data is their consent. Otherwise, if we do not ask for consent and they, for example, contact us on their own initiative, we use messengers in relation to our contractual partners as well as within the framework of contract initiation as a contractual measure, and in the case of other interested parties and communication partners on the basis of our legitimate interests in fast and efficient communication and meeting the needs of our communication partners for communication via messenger. Furthermore, we point out to you that we do not transmit the contact details communicated to us to the messengers for the first time without your consent.

Withdrawal, objection and erasure: You can withdraw a given consent at any time and object to communication with us via messenger at any time. In the case of communication via messenger, we erase the messages in accordance with our general erasure policies (i.e. e.g., as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) and otherwise as soon as we can assume that we have answered any inquiries of the communication partners, if no reference to a previous conversation is to be expected and there are no legal retention obligations that prevent erasure.

Reservation of the reference to other communication channels: To ensure your security, we ask for your understanding that for certain reasons we may not be able to respond to inquiries via messenger. This concerns situations in which, for example, contract details must be treated with particular confidentiality or a response via messenger does not meet the formal requirements. In these cases, we recommend that you resort to more suitable communication channels.

Further information on processing operations, procedures and services:

Chatbots and Chat Functions

We offer online chats and chatbot functions as a communication option (together referred to as “chat services”). A chat is an online conversation conducted with a certain immediacy. A chatbot is software that answers users’ questions or informs them via messages. When you use our chat functions, we may process your personal data.

If you use our chat services within an online platform, your identification number within the respective platform is additionally stored. We can also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove them in accordance with legal requirements.

We point out to users that the respective platform provider can find out that and when users communicate with our chat services, as well as collect technical information about the device used by the users and, depending on the settings of their device, also location information (so-called metadata) for the purposes of optimizing the respective services and for security purposes. Likewise, the metadata of the communication via chat services (i.e. e.g. the information about who communicated with whom) could be used by the respective platform providers in accordance with their provisions, to which we refer for further information, for the purposes of marketing or for displaying advertising tailored to users.

Insofar as users agree to a chatbot to activate information with regular messages, they have the option at any time to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. By unsubscribing from the chatbot messages, users’ data is erased from the directory of message recipients.

We use the aforementioned information to operate our chat services, e.g. to address users personally, to answer their inquiries, to transmit any requested content, and also to improve our chat services (e.g. to “teach” chatbots answers to frequently asked questions or to recognize unanswered inquiries).

Notes on legal bases: We use the chat services on the basis of consent if we have previously obtained the users’ permission to process their data in the context of our chat services (this applies to cases in which users are asked for consent, e.g. so that a chatbot regularly sends them messages). Insofar as we use chat services to answer users’ inquiries about our services or our company, this takes place for contractual and pre-contractual communication. Otherwise, we use chat services on the basis of our legitimate interests in optimizing the chat services, their economic efficiency, and increasing the positive user experience.

Withdrawal, objection and erasure: You can withdraw a given consent at any time or object to the processing of your data in the context of our chat services.

Further information on processing operations, procedures and services:

Artificial Intelligence (AI)

We use artificial intelligence (AI), whereby personal data is processed. The specific purposes and our interest in the use of AI are stated below. By AI we understand, in accordance with the concept of an “AI system” pursuant to Article 3 No. 1 of the AI Regulation, a machine-based system that is designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, from the input it receives, infers how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

Our AI systems are used in strict compliance with the legal requirements. These include both specific regulations for artificial intelligence and data protection requirements. In doing so, we comply in particular with the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimization, and integrity and confidentiality. We ensure that the processing of personal data always takes place on a legal basis. This can be either the consent of the data subjects or a legal permission.

When using external AI systems, we carefully select their providers (hereinafter “AI providers”). In accordance with our legal obligations, we ensure that the AI providers comply with the applicable provisions. Likewise, we observe the obligations incumbent upon us when using or operating the AI services obtained. The processing of personal data by us and the AI providers takes place exclusively on the basis of consent or legal authorization. In doing so, we place particular emphasis on transparency, fairness, and maintaining human oversight over AI-supported decision-making processes.

To protect the processed data, we implement appropriate and robust technical and organizational measures. These ensure the integrity and confidentiality of the processed data and minimize potential risks. Through regular reviews of the AI providers and their services, we ensure ongoing compliance with current legal and ethical standards.

Further information on processing operations, procedures and services:

Video Conferences, Online Meetings, Webinars and Screen Sharing

We use platforms and applications from other providers (hereinafter referred to as “conference platforms”) for the purposes of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conference”). When selecting the conference platforms and their services, we observe the legal requirements.

Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of the participants named below. The scope of the processing depends, on the one hand, on which data is required in the context of a specific conference (e.g. provision of access data or real names) and which optional information is provided by the participants. In addition to processing for conducting the conference, the participants’ data may also be processed by the conference platforms for security purposes or service optimization. The processed data includes personal data (first name, surname), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants’ devices, their operating system, the browser and its technical and language settings, information on the content-related communication processes, i.e. entries in chats as well as audio and video data, and the use of other available functions (e.g. surveys). The content of the communications is encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.

Logging and recordings: If text entries, participation results (e.g. of surveys) as well as video or audio recordings are logged, this is transparently communicated to the participants in advance and they are – insofar as necessary – asked for consent.

Data protection measures of the participants: Please observe the details of the processing of your data by the conference platforms in their privacy information and, within the framework of the settings of the conference platforms, choose the security and data protection settings that are optimal for you. Furthermore, please ensure data and privacy protection in the background of your recording for the duration of a video conference (e.g. by informing housemates, locking doors and using, insofar as technically possible, the function to blur the background). Links to the conference rooms as well as access data must not be passed on to unauthorized third parties.

Notes on legal bases: Insofar as, in addition to the conference platforms, we also process the users’ data and ask users for their consent to the use of the conference platforms or certain functions (e.g. consent to a recording of conferences), the legal basis of the processing is this consent. Furthermore, our processing may be necessary to fulfill our contractual obligations (e.g. in participant lists, in the case of processing meeting results, etc.). Otherwise, the users’ data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.

Further information on processing operations, procedures and services:

Cloud Services

We use software services accessible via the internet and executed on the servers of their providers (so-called “cloud services”, also referred to as “Software as a Service”) for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with certain recipients, or publication of content and information).

In this context, personal data may be processed and stored on the servers of the providers, insofar as this is part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact data of users, data on processes, contracts, other operations and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and service optimization.

Insofar as we provide forms or other documents and content for other users or publicly accessible websites with the help of the cloud services, the providers may store cookies on the users’ devices for the purposes of web analysis or to remember the users’ settings (e.g. in the case of media control).

Further information on processing operations, procedures and services:

Newsletter and Electronic Notifications

We send newsletters, emails and further electronic notifications (hereinafter “newsletter”) exclusively with the consent of the recipients or on the basis of a legal basis. Insofar as the content of a newsletter is described during registration for it, this content is decisive for the users’ consent. To register for our newsletter, it is normally sufficient to provide your email address. However, in order to be able to offer you a personalized service, we may ask for your name for a personal address in the newsletter, or for further information if this is necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to prove a previously given consent. The processing of this data is restricted to the purpose of a potential defense against claims. An individual erasure request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (so-called “blocklist”).

The logging of the registration process takes place on the basis of our legitimate interests for the purpose of proving its proper conduct. Insofar as we commission a service provider with the sending of emails, this takes place on the basis of our legitimate interests in an efficient and secure sending system.

Content:

Information about us, our services, promotions and offers.

Further information on processing operations, procedures and services:

Promotional Communication via Email, Postal Mail, Fax or Telephone

We process personal data for the purposes of promotional communication, which may take place via various channels, such as e.g. email, telephone, postal mail or fax, in accordance with the legal requirements.

Recipients have the right to withdraw given consents at any time or to object to the promotional communication at any time free of charge via the contact option specified above.

After withdrawal or objection, we store the data necessary to prove the previous authorization for contact or sending for up to three years after the end of the year of the withdrawal or objection on the basis of our legitimate interests. The processing of this data is restricted to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing the withdrawal or objection of the users, we also store the data necessary to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).

Prize Draws and Raffles

We may occasionally conduct small prize draws or raffles in the context of trade fairs, congresses or comparable events. In doing so, we process the personal data provided by the participants, in particular name, contact data and, if applicable, company affiliation, exclusively for conducting the prize draw, for determining and notifying the winners, and for handing over or sending the prize.

The legal basis is the conduct of the prize draw or our legitimate interests in the proper organization and documentation of the campaign. Insofar as further promotional contact is to take place, this only takes place on the basis of a separate consent or another legal permission.

The participants’ data is erased as soon as the prize draw is completed and no further inquiries are to be expected, but at the latest after twelve months. Winners’ data may be stored for longer, insofar as this is necessary for handling the prize, for documentation or for fulfilling legal obligations.

Web Analysis, Monitoring and Optimization

Web analysis (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behavior, interests or demographic information about the visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offering or its functions or content are used most frequently, or invite reuse. Likewise, it is possible for us to understand which areas require optimization.

In addition to web analysis, we may also use test procedures, e.g. to test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles, i.e. data combined into a usage process, may be created for these purposes, and information may be stored in a browser or in a device and then read out. The information collected includes, in particular, visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. Insofar as users have consented to the collection of their location data vis-à-vis us or vis-à-vis the providers of the services we use, the processing of location data is also possible.

In addition, the IP addresses of the users are stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users. In general, no plain-text data of the users (such as email addresses or names) is stored in the context of web analysis, A/B testing and optimization, but rather pseudonyms. This means that we, as well as the providers of the software used, do not know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is consent. Otherwise, the users’ data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Further information on processing operations, procedures and services:

Online Marketing

We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “content”) based on the potential interests of users, as well as the measurement of their effectiveness.

For these purposes, so-called user profiles are created and stored in a file (the so-called “cookie”), or similar procedures are used, by means of which the information about the user relevant for displaying the aforementioned content is stored. This may include, for example, viewed content, visited websites, online networks used, but also communication partners and technical information, such as the browser used, the computer system used, and information on usage times and functions used. Insofar as users have consented to the collection of their location data, this may also be processed.

In addition, the IP addresses of the users are stored. However, we use available IP masking procedures (i.e. pseudonymization by shortening the IP address) to protect users. In general, no plain-text data of the users (such as email addresses or names) is stored in the context of the online marketing procedure, but rather pseudonyms. This means that we, as well as the providers of the online marketing procedures, do not know the actual user identity, but only the information stored in their profiles.

The information in the profiles is generally stored in the cookies or by means of similar procedures. These cookies can later generally also be read out on other websites that use the same online marketing procedure and analyzed for the purpose of displaying content, as well as supplemented with further data and stored on the server of the online marketing procedure provider.

In exceptional cases, it is possible to assign plain-text data to the profiles, primarily if the users are, for example, members of a social network whose online marketing procedure we use and the network connects the user profiles with the aforementioned information. We ask you to note that users can make additional agreements with the providers, for example by consent within the framework of registration.

In principle, we only receive access to summarized information on the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to the conclusion of a contract with us. The conversion measurement is used solely for the analysis of the success of our marketing measures.

Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is permission. Otherwise, the users’ data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Notes on withdrawal and objection:

We refer to the privacy information of the respective providers and the options to object (so-called “opt-out”) specified for the providers. Insofar as no explicit opt-out option has been specified, there is, on the one hand, the possibility that you disable cookies in the settings of your browser. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered in summary form directed at the respective areas:

a) Europe: https://youronlinechoices.eu/.

b) Canada: https://youradchoices.ca/.

c) USA: https://optout.aboutads.info/.

d) Cross-regional: https://optout.aboutads.info.

Further information on processing operations, procedures and services:

Customer Reviews and Rating Procedures

We participate in review and rating procedures in order to evaluate, optimize and promote our services. If users rate us via the participating rating platforms or procedures or otherwise give feedback, the general terms and conditions or terms of use and the privacy information of the providers additionally apply. As a rule, the rating also requires registration with the respective providers.

In order to ensure that the rating persons have actually made use of our services, we transmit the data necessary for this regarding the customer and the service used to the respective rating platform (including name, email address and order number or article number) with the consent of the customers. This data is used solely to verify the authenticity of the user.

Further information on processing operations, procedures and services:

Presences in Social Networks (Social Media)

We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.

We point out that user data may be processed outside the area of the European Union. This may result in risks for the users, because, for example, the enforcement of user rights could be made more difficult.

Furthermore, the users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of the usage behavior and the resulting interests of the users. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For this purpose, cookies are generally stored on the users’ computers, in which the usage behavior and the interests of the users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (in particular if they are members of the respective platforms and are logged in there).

For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

Also in the case of requests for information and the assertion of data subjects’ rights, we point out that these can be asserted most effectively with the providers. Only the latter each have access to the users’ data and can directly take appropriate measures and provide information. Should you nevertheless need help, you can contact us.

Further information on processing operations, procedures and services:

Plug-ins and Embedded Functions and Content

We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These can be, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).

The integration always requires that the third-party providers of this content process the users’ IP address, since without the IP address they could not send the content to their browser. The IP address is thus necessary for the display of this content or functions. We endeavor to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and the operating system, referring websites, the time of visit, and further information on the use of our online offering, but may also be connected with such information from other sources.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is permission. Otherwise, the user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Further information on processing operations, procedures and services:

Management, Organization and Tools

We use services, platforms and software from other providers (hereinafter referred to as “third-party providers”) for the purposes of the organization, administration, planning and provision of our services. When selecting the third-party providers and their services, we observe the legal requirements.

In this context, personal data may be processed and stored on the servers of the third-party providers. This may affect various data that we process in accordance with this privacy policy. This data may include, in particular, master data and contact data of users, data on processes, contracts, other operations and their content.

Insofar as users are referred to the third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security purposes, service optimization or marketing purposes. We therefore ask you to observe the privacy information of the respective third-party providers.

Further information on processing operations, procedures and services:

Application Procedure

When you apply to us, we process the personal data transmitted by you exclusively for conducting the application procedure and for deciding on the establishment of an employment relationship. This includes, in particular, your contact data, application documents, information on qualifications and career, as well as further information that you provide to us in the context of the application.

The legal basis is Art. 6 (1) (b) GDPR in conjunction with § 26 BDSG. Insofar as special categories of personal data are transmitted, the processing only takes place insofar as this is legally required or you provide this data voluntarily.

If no employment relationship comes about, we generally erase the application data at the latest six months after the completion of the application procedure, insofar as no longer storage is necessary for the establishment, exercise or defense of legal claims or you have consented to a longer storage.

Amendment and Update

We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or another individual notification.

Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, we ask you to note that the addresses may change over time and ask you to check the information before contacting them.

Definitions of Terms

In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are legally defined, their legal definitions apply. The following explanations, on the other hand, are intended primarily to aid understanding.