This is a courtesy translation of the German privacy policy. The German version is legally binding; in case of discrepancies it prevails.
Introduction and overview
We have written this privacy policy (version 03.10.2026-313240440) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future and which lawful options you have. The terms used are to be understood as gender-neutral.
In short: we inform you comprehensively about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, by contrast, is meant to describe the most important things as simply and transparently as possible. Where it helps transparency, technical terms are explained in a reader-friendly way, links to further information are provided and graphics are used. In this way we state in clear and simple language that, in the course of our business activities, we only process personal data where a corresponding legal basis exists. That is certainly not possible if one gives the shortest, vaguest and most legalistic-technical explanations, as is often the standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or two pieces of information you did not yet know.
If questions remain, we kindly ask you to contact the responsible body named below or in the legal notice (Impressum), to follow the links provided and to look up further information on third-party sites. Our contact details can of course also be found in the legal notice.
Scope
This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies we commission (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person’s name, e-mail address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline. The scope of this privacy policy includes:
- all online presences (websites, online shops) that we operate
- social media presences and e-mail communication
- mobile apps for smartphones and other devices
In short: the privacy policy applies to all areas in which personal data is processed in a structured way in the company via the channels mentioned. Should we enter into legal relationships with you outside these channels, we will inform you separately where appropriate.
Legal bases
In this privacy policy we give you transparent information on the legal principles and provisions, i.e. the legal bases of the General Data Protection Regulation, that allow us to process personal data.
As regards EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this EU General Data Protection Regulation online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
Contract (Article 6(1)(b) GDPR): To fulfil a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information beforehand.
Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to keep invoices for accounting. These usually contain personal data.
Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.
Other conditions, such as the performance of tasks in the public interest and the exercise of official authority, as well as the protection of vital interests, do not usually arise for us. Should such a legal basis nevertheless be relevant, it will be indicated at the appropriate place.
In addition to the EU regulation, national laws also apply:
In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Datenschutzgesetz), DSG for short.
In Germany the Federal Data Protection Act (Bundesdatenschutzgesetz), BDSG for short, applies.
If further regional or national laws apply, we will inform you about them in the following sections.
Contact details of the controller
If you have questions about data protection or the processing of personal data, you will find below the contact details of the controller pursuant to Article 4(7) of the EU General Data Protection Regulation (GDPR):
Victoria Dzygman
Eickener Straße 123, 41063 Mönchengladbach, Germany
- E-mail: info@victoriadzygman.de
- Phone: +49 17624181312
- Legal notice (Impressum)
Storage period
It is a general criterion for us that we store personal data only for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases we are legally obliged to store certain data even after the original purpose has ceased, for example for accounting purposes.
Should you wish your data to be deleted or withdraw your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.
We will inform you about the specific duration of the respective data processing further below, where we have further information.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you about the following rights to which you are entitled, so that data is processed fairly and transparently:
Under Article 15 GDPR you have a right of access as to whether we process data about you. If so, you have the right to receive a copy of the data and to be told the following information:
the purpose for which we carry out the processing;
the categories, i.e. the types of data being processed;
who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
how long the data will be stored;
the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
the origin of the data, if we did not collect it from you;
whether profiling takes place, i.e. whether data is evaluated automatically in order to arrive at a personal profile of you.
Under Article 16 GDPR you have the right to rectification of data, which means that we must correct data if you find errors.
Under Article 17 GDPR you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
Under Article 18 GDPR you have the right to restriction of processing, which means that we may only store the data but not use it any further.
Under Article 20 GDPR you have the right to data portability, which means that on request we will provide you with your data in a commonly used format.
Under Article 21 GDPR you have a right to object, which, once enforced, entails a change in the processing.
If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
If data is used for direct marketing, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
If data is used for profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
Under Article 22 GDPR you may have the right not to be subject to a decision based solely on automated processing (for example profiling).
Under Article 77 GDPR you have the right to lodge a complaint. This means you can complain to the data protection authority at any time if you believe that the processing of personal data infringes the GDPR.
In short: you have rights – do not hesitate to contact the responsible body listed above!
If you believe that the processing of your data infringes data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria this is the Data Protection Authority, whose website you can find at https://www.dsb.gv.at/. In Germany there is a data protection commissioner for each federal state. For further information you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
North Rhine-Westphalia data protection authority
- State Commissioner for Data Protection: Bettina Gayk
- Address: Kavalleriestraße 2-4, 40213 Düsseldorf
- Phone: 02 11/384 24-0
- E-mail: poststelle@ldi.nrw.de
- Website: https://www.ldi.nrw.de/
Data transfer to third countries
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to this processing or if there is another legal permission. This applies in particular where the processing is required by law or necessary for the performance of a contractual relationship and in any case only to the extent that this is generally permitted. In most cases your consent is the most important reason why we have data processed in third countries. The processing of personal data in third countries such as the USA, where many software providers offer services and have their server locations, can mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists only if a US company that processes personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. You can find more information at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may mean that data is not processed and stored anonymously. Furthermore, US government authorities may under certain circumstances gain access to individual data. In addition, collected data may be linked with data from other services of the same provider if you have a corresponding user account. Where possible, we try to use server locations within the EU, if offered.
We will inform you in more detail about data transfers to third countries at the appropriate places in this privacy policy, where applicable.
Security of data processing
To protect personal data we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In this way, within our means, we make it as difficult as possible for third parties to draw conclusions about personal information from our data.
Art. 25 GDPR speaks here of “data protection by design and by default” and means that one always has to think about security, both with software (e.g. forms) and hardware (e.g. access to the server room), and take appropriate measures. Below we go into specific measures where necessary.
TLS encryption with https
TLS, encryption and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the internet in a way that cannot be intercepted.
This means that the entire transmission of all data from your browser to our web server is secured – nobody can “listen in”.
With this we have introduced an additional layer of security and fulfil data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognise the use of this protection of data transmission by the small padlock symbol at the top left of the browser, to the left of the internet address (e.g. beispielseite.de), and the use of the scheme https (instead of http) as part of our internet address.
If you would like to know more about encryption, we recommend a Google search for “Hypertext Transfer Protocol Secure wiki” to find good links to further information.
Communication
Communication summary
👥 Data subjects: everyone who communicates with us by phone, e-mail or online form
📓 Data processed: e.g. phone number, name, e-mail address, form data entered. More details can be found under the respective contact method used
🤝 Purpose: handling communication with customers, business partners etc.
📅 Storage period: duration of the business case and the legal provisions
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate by phone, e-mail or online form, personal data may be processed.
The data is processed for handling and processing your question and the related business matter. The data is stored for as long as the matter lasts or as long as the law prescribes.
Data subjects
All those who seek contact with us via the communication channels we provide are affected by the processes mentioned.
Phone
If you call us, the call data is stored in pseudonymised form on the respective device and with the telecommunications provider used. In addition, data such as name and phone number may subsequently be sent by e-mail and stored in order to answer the enquiry. The data is deleted as soon as the business case has ended and legal requirements allow.
If you communicate with us by e-mail, data may be stored on the respective device (computer, laptop, smartphone, …) and data is stored on the e-mail server. The data is deleted as soon as the business case has ended and legal requirements allow.
Online forms
If you communicate with us via an online form, data is stored on our web server and, where applicable, forwarded to an e-mail address of ours. The data is deleted as soon as the business case has ended and legal requirements allow.
Legal bases
The processing of data is based on the following legal bases:
Art. 6(1)(a) GDPR (consent): You give us consent to store your data and to use it further for purposes relating to the business case;
Art. 6(1)(b) GDPR (contract): It is necessary for the performance of a contract with you or with a processor such as the telephone provider, or we need to process the data for pre-contractual activities, such as preparing an offer;
Art. 6(1)(f) GDPR (legitimate interests): We want to handle customer enquiries and business communication in a professional framework. For this, certain technical facilities such as e-mail programs, Exchange servers and mobile network operators are necessary in order to be able to run communication efficiently.
Data processing agreement (AVV)
In this section we would like to explain what a data processing agreement is and why it is needed. Because the German word “Auftragsverarbeitungsvertrag” is quite a tongue-twister, we will often use only the acronym AVV in this text. Like most companies, we do not work alone, but also use services of other companies or individuals. By involving different companies or service providers, it may happen that we pass on personal data for processing. These partners then act as processors, with whom we conclude a contract, the so-called data processing agreement (AVV). The most important thing for you to know is that the processing of your personal data takes place exclusively on our instructions and must be governed by the AVV.
Who are processors?
As a company and website owner we are responsible for all data that we process about you. Besides controllers there can also be so-called processors. This includes every company or person who processes personal data on our behalf. More precisely and according to the GDPR definition: every natural or legal person, authority, institution or other body that processes personal data on our behalf is a processor. Processors can therefore be service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
For a better understanding of the terms, here is an overview of the three roles in the GDPR:
Data subject (you as customer or prospect) → controller (we as company and client) → processor (service provider such as a web host or cloud provider)
Content of a data processing agreement
As mentioned above, we have concluded an AVV with our partners acting as processors. First and foremost it states that the processor processes the data to be handled exclusively in accordance with the GDPR. The contract must be concluded in writing, although electronic conclusion of a contract also counts as “written” in this context. Only on the basis of the contract does the processing of personal data take place. The contract must contain the following:
- binding to us as controller
- obligations and rights of the controller
- categories of data subjects
- type of personal data
- type and purpose of the data processing
- subject matter and duration of the data processing
- place where the data processing is carried out
The contract also contains all obligations of the processor. The most important obligations are:
- to ensure measures for data security
- to take possible technical and organisational measures to protect the rights of the data subject
- to keep a record of processing activities
- to cooperate with the data protection supervisory authority on request
- to carry out a risk analysis with regard to the personal data received
- sub-processors may only be engaged with the written approval of the controller
What such an AVV looks like in practice can be seen, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A sample contract is presented there.
Cookies
Cookies summary
👥 Data subjects: website visitors
🤝 Purpose: depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
📓 Data processed: depends on the cookie used. You can find more details below or from the manufacturer of the software that sets the cookie.
📅 Storage period: depends on the respective cookie, can vary from hours to years
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you surf the internet, you use a browser. Well-known browsers are, for example, Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder, quasi the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers every cookie has its own file, in others such as Firefox all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be assessed individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and contain no viruses, trojans or other “pests”. Cookies also cannot access information on your PC.
A browser should be able to support these minimum sizes:
- at least 4096 bytes per cookie
- at least 50 cookies per domain
- at least 3000 cookies in total
What types of cookies are there?
Which cookies we specifically use depends on the services used and is explained in the following sections of the privacy policy. At this point we would like to briefly go into the different types of HTTP cookies.
One can distinguish 4 types of cookies:
Essential cookies
These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user puts a product in the shopping cart, then continues surfing on other pages and only goes to the checkout later. These cookies mean the shopping cart is not deleted, even if the user closes the browser window.
Functional cookies
These cookies collect information about user behaviour and whether the user receives any error messages. In addition, these cookies are used to measure loading time and the behaviour of the website in different browsers.
Targeted cookies
These cookies provide better user-friendliness. For example, entered locations, font sizes or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually adapted advertising to the user. This can be very handy, but also very annoying.
Usually, on your first visit to a website you are asked which of these types of cookies you wish to allow. And of course this decision is also stored in a cookie.
If you want to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.
Purpose of processing via cookies
The purpose ultimately depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are small helpers for many different tasks. Unfortunately, what data is stored in cookies cannot be generalised, but we will inform you about the processed or stored data within the following privacy policy.
Storage period of cookies
The storage period depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.
You also have influence over the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below). Furthermore, cookies based on consent are deleted at the latest after you withdraw your consent, whereby the lawfulness of the storage until then remains unaffected.
Right to object – how can I delete cookies?
You decide yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete cookies, deactivate them or allow them only partially. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, or change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies to remove data that websites have placed on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want cookies, you can set up your browser so that it always informs you when a cookie is to be set. In this way you can decide for each individual cookie whether you allow it or not. The procedure differs depending on the browser. It is best to look for the instructions on Google with the search term “Cookies löschen Chrome” or “Cookies deaktivieren Chrome” in the case of a Chrome browser.
Legal basis
Since 2009 there have been the so-called “cookie directives”. They state that storing cookies requires your consent (Article 6(1)(a) GDPR). Within the EU countries, however, reactions to these directives are still very different. In Austria this directive was implemented in § 165(3) of the Telecommunications Act (2021). In Germany the cookie directives were not implemented as national law. Instead, this directive was largely implemented in § 15(3) of the Telemedia Act (TMG), which since May 2024 has been replaced by the Digital Services Act (DDG).
For absolutely necessary cookies, even where there is no consent, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to give visitors to the website a pleasant user experience, and for that certain cookies are often absolutely necessary.
Where cookies that are not absolutely necessary are used, this only happens with your consent. The legal basis in that respect is Art. 6(1)(a) GDPR.
In the following sections you will be informed in more detail about the use of cookies, where the software used uses cookies.
An overview of all cookies used on this website can be found in our Cookie Policy.
Web hosting introduction
Web hosting summary
👥 Data subjects: website visitors
🤝 Purpose: professional hosting of the website and securing its operation
📓 Data processed: IP address, time of the website visit, browser used and other data. You can find more details below or from the web hosting provider used.
📅 Storage period: depends on the provider, but generally 2 weeks
⚖️ Legal bases: Art. 6(1)(f) GDPR (legitimate interests)
What is web hosting?
When you visit websites today, certain information – including personal data – is created and stored automatically, including on this website. This data should be processed as sparingly as possible and only with justification. By website, by the way, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) to the very last subpage (like this one). By domain we mean, for example, beispiel.de or musterbeispiel.com.
When you want to view a website on a computer, tablet or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We call them browser or web browser for short.
To display the website, the browser must connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and laborious task, which is why it is usually taken over by professional providers. They offer web hosting and thereby ensure reliable and error-free storage of website data. Quite a lot of technical terms, but please stay with us, it gets better!
When the browser on your computer (desktop, laptop, tablet or smartphone) connects, and during data transfer to and from the web server, personal data may be processed. On the one hand your computer stores data, on the other hand the web server must also store data for some time in order to ensure proper operation.
A picture says more than a thousand words, so the following graphic illustrates the interplay between browser, the internet and the hosting provider.
Why do we process personal data?
The purposes of the data processing are:
Professional hosting of the website and securing operations
to maintain operational and IT security
anonymous analysis of access behaviour to improve our offering and, where applicable, for criminal prosecution or the pursuit of claims
What data is processed?
Even while you are visiting our website right now, our web server, that is the computer on which this web page is stored, usually automatically stores data such as
- the complete internet address (URL) of the web page accessed
- browser and browser version (e.g. Chrome 87)
- the operating system used (e.g. Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
- the host name and IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
- date and time
- in files, the so-called web server log files
How long is the data stored?
As a rule, the above data is stored for two weeks and then deleted automatically. We do not pass on this data, but cannot rule out that this data may be viewed by authorities in the event of unlawful conduct.
In short: your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without consent!
Legal basis
The lawfulness of processing personal data in the context of web hosting arises from Art. 6(1)(f) GDPR (protection of legitimate interests), as the use of professional hosting with a provider is necessary in order to present the business on the internet securely and in a user-friendly way and, where necessary, to be able to pursue attacks and claims arising from them.
As a rule there is a contract on data processing between us and the hosting provider pursuant to Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.
Data processing agreement (AVV) STRATO
We have concluded a data processing agreement (AVV) with STRATO within the meaning of Article 28 of the General Data Protection Regulation (GDPR). What an AVV is exactly and above all what must be contained in an AVV you can read in our general section “Data processing agreement (AVV)”.
This contract is required by law because STRATO processes personal data on our behalf. It clarifies that STRATO may only process data it receives from us on our instructions and must comply with the GDPR.
External hosting provider: details
Below you will find the contact details of our external hosting provider, where, in addition to the information above, you can find out more about the data processing:
- STRATO GmbH
- Otto-Ostrowski-Straße 7
- 10249 Berlin
You can learn more about the data processing at this provider in its privacy policy.
Web analytics introduction
Web analytics summary
👥 Data subjects: website visitors
🤝 Purpose: evaluation of visitor information to optimise the web offering.
📓 Data processed: access statistics containing data such as locations of access, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses. You can find more details with the respective web analytics tool used.
📅 Storage period: depends on the web analytics tool used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is web analytics?
On our website we use software to evaluate the behaviour of website visitors, called web analytics or web analysis for short. In doing so, data is collected that the respective analytics tool provider (also called tracking tool) stores, manages and processes. With the help of the data, analyses of user behaviour on our website are created and made available to us as website operators. In addition, most tools offer various testing options. For example, we can test which offers or content are most popular with our visitors. For this we show you two different offers for a limited period. After the test (a so-called A/B test) we know which product or content our website visitors find more interesting. For such testing procedures, as for other analytics procedures, user profiles may also be created and the data stored in cookies.
Why do we operate web analytics?
With our website we have a clear goal: we want to deliver the best web offering on the market for our industry. To achieve this goal, we want on the one hand to offer the best and most interesting content and on the other hand to make sure that you feel completely at ease on our website. With the help of web analysis tools we can take a closer look at the behaviour of our website visitors and then improve our web offering accordingly for you and for us. For example, we can see how old our visitors are on average, where they come from, when our website is visited most or which content or products are particularly popular. All this information helps us optimise the website and thus adapt it best to your needs, interests and wishes.
What data is processed?
Exactly what data is stored of course depends on the analytics tools used. As a rule, however, it is stored, for example, which content you view on our website, which buttons or links you click, when you open a page, which browser you use, with which device (PC, tablet, smartphone etc.) you visit the website or which computer system you use. If you agreed that location data may also be collected, this too may be processed by the web analytics tool provider.
In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are personal data. However, your IP address is as a rule stored in pseudonymised form (i.e. in unrecognisable and shortened form). For the purposes of tests, web analysis and web optimisation, in principle no direct data such as your name, age, address or e-mail address are stored. All this data, where collected, is stored in pseudonymised form. In this way you cannot be identified as a person.
How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website again, other cookies can store data for several years.
Duration of data processing
We inform you about the duration of the data processing further below, where we have further information. In general, we process personal data only for as long as is absolutely necessary for the provision of our services and products. Where legally required, as for example in the case of accounting, this storage period may also be exceeded.
Right to object
You also have the right and the possibility at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.
Legal basis
The use of web analytics requires your consent, which we obtained with our cookie popup. According to Art. 6(1)(a) GDPR (consent), this consent is the legal basis for the processing of personal data, as may occur in collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of web analytics we identify errors on the website, can identify attacks and improve cost-effectiveness. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use the tools to the extent that you have given consent.
As cookies are used in web analytics tools, we also recommend that you read our general privacy policy on cookies. To find out exactly which data about you is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools, where applicable, can be found in the following sections.
Matomo On-Premise privacy policy
Matomo On-Premise summary
👥 Data subjects: website visitors
🤝 Purpose: evaluation of visitor information to optimise the web offering.
📓 Data processed: data such as number of visitors to the website, page views, length of stay or search terms used. You can find more details below and in the privacy policy of Matomo On-Premise.
📅 Storage period: in principle the data is stored by us for as long as the business purposes require.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is Matomo On-Premise?
On our website we use the privacy-friendly analytics program Matomo On-Premise. In the on-premise variant Matomo is installed on our own server. We therefore act as the operator of the software, and any data that we might collect about you is stored directly with us. The data processing thus remains completely in our hands. The manufacturer of the tool is the New Zealand company InnoCraft Ltd, 7 Waterloo Quay PO625, 6140 Wellington, New Zealand.
Matomo On-Premise is a web analytics platform that takes data protection very seriously and nevertheless provides us as website operators with accurate statistics about your behaviour on our website. A big difference from other analytics programs is the possibility of storing data on our own server. Matomo On-Premise also offers various options for anonymising the IP addresses of our website visitors and deactivating cookies.
Why do we use Matomo On-Premise?
Many of the usual analytics tools collect huge amounts of personal data and may also pass it on to third parties. This means that control over your data is very hard to maintain. Data protection is very important to us, and that is why we decided on Matomo On-Premise and thus on a considerably more privacy-friendly alternative. However, we also do not want to dispense with web analysis altogether. After all, with the help of statistics about behaviour on the website we can optimise our service and adapt it to your individual needs.
What data is stored by Matomo On-Premise?
In addition to personal data such as your IP address or information about you (e.g. name, address, date of birth) that you actively transmit to us, information about your visitor behaviour in particular is stored. This is mostly not personal data but information such as the number of visitors to the website, page views, length of stay or search terms used. Furthermore, technical data such as browser type, your operating system and your screen resolution may also be stored. Matomo On-Premise can also collect information about which website you came to us from. The data collected is stored with us and is not passed on or sold to third parties.
How long and where is the data stored?
Matomo On-Premise is a self-hosted analytics platform, which means we store all collected data directly on our own servers. Our server is located in Europe, therefore data is also not processed in any third countries, i.e. in countries outside the scope of the GDPR.
In principle the data is stored with us for as long as the business purposes require. Unfortunately we cannot give exact retention periods at this point because they depend very much on our individual configurations. If you would like to learn more about our data retention period and our configurations, please do not hesitate to contact us.
How can I delete my data or prevent data storage?
You have the right and the possibility at any time to access your personal data and to object to its use and processing. You can also lodge a complaint at any time with a state supervisory authority or simply with us.
In your browser you also have the option to manage, delete or deactivate cookies individually. Please note, however, that deactivated or deleted cookies may have negative effects on the functions of our website. Depending on which browser you use, managing cookies works slightly differently. In the section “Cookies” you will find the corresponding links to the instructions for the best-known browsers. If you want to request data deletion, you are also welcome to contact us.
Legal basis
The use of Matomo On-Premise requires your consent, which we obtained with our consent management tool (popup). According to Art. 6(1)(a) GDPR (consent), this consent is the legal basis for the processing of personal data, as may occur in collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of Matomo On-Premise we identify optimisation potential for our website and can improve cost-effectiveness. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use Matomo On-Premise to the extent that you have given consent.
If you would like to know more about data processing by Matomo On-Premise, you are also welcome to contact us. We also recommend Matomo’s privacy policy at https://matomo.org/privacy-policy/.
Messenger and communication introduction
Messenger and communication summary
👥 Data subjects: website visitors
🤝 Purpose: contact requests and general communication between us and you
📓 Data processed: data such as name, address, e-mail address, phone number, general content data, where applicable IP address
You can find more details with the respective tools used.
📅 Storage period: depends on the messenger and communication functions used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1) sentence 1 (b) GDPR (contractual or pre-contractual obligations)
What are messenger and communication functions?
On our website we offer various ways (such as messenger and chat functions, online or contact forms, e-mail, phone) to communicate with us. In doing so, your data is also processed and stored, insofar as it is necessary to answer your enquiry and for our subsequent measures.
In addition to classic means of communication such as e-mail, contact forms or phone, we also use chats and messengers. The most commonly used messenger function at present is WhatsApp, but of course there are many different providers offering messenger functions, especially for websites. If content is end-to-end encrypted, this is pointed out in the individual privacy texts or in the privacy policy of the respective provider. End-to-end encryption means nothing other than that the content of a message is not visible even to the provider. However, information about your device, location settings and other technical data may nevertheless be processed and stored.
Why do we use messenger and communication functions?
Ways of communicating with you are of great importance to us. After all, we want to talk to you and answer all possible questions about our service as well as possible. Well-functioning communication is an important part of our service. With the practical messenger and communication functions you can choose at any time the ones you like best. In exceptional cases, however, we may not answer certain questions via chat or messenger. This is the case, for example, when internal contractual matters are involved. For these we recommend other means of communication such as e-mail or phone.
We generally assume that we remain responsible under data protection law even if we use services of a social media platform. However, the European Court of Justice has ruled that in certain cases the operator of the social media platform can be jointly responsible with us within the meaning of Art. 26 GDPR. Where this is the case, we point it out separately and work on the basis of a corresponding agreement. The essence of the agreement is reproduced further below for the platform concerned.
Please note that when using our integrated elements, data about you may also be processed outside the European Union, as many providers, for example Facebook Messenger or WhatsApp, are American companies. As a result you may no longer be able to claim or enforce your rights regarding your personal data as easily.
What data is processed?
Exactly what data is stored and processed depends on the respective provider of the messenger and communication functions. In principle it is data such as name, address, phone number, e-mail address and content data such as all information you enter in a contact form. Most of the time information about your device and the IP address are also stored. Data collected via a messenger and communication function is also stored on the providers’ servers.
If you want to know exactly which data is stored and processed by the respective providers and how you can object to the data processing, you should read the respective privacy policy of the company carefully.
How long is the data stored?
How long the data is processed and stored depends primarily on the tools we use. You can find out more about the data processing of the individual tools below. The providers’ privacy policies usually state exactly which data is stored and processed and for how long. In principle personal data is only processed for as long as necessary for the provision of our services. If data is stored in cookies, the storage period varies greatly. The data can be deleted again right after leaving a website, but can also remain stored for several years. You should therefore look at each individual cookie in detail if you want to know more about data storage. Mostly you will also find informative details about the individual cookies in the privacy policies of the individual providers.
Right to object
You also have the right and the possibility at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. For further information we refer to the section on consent.
As cookies may be used in messenger and communication functions, we also recommend our general privacy policy on cookies. To find out exactly which data about you is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
If you have consented to data about you being processed and stored by integrated messenger and communication functions, this consent is the legal basis for the data processing (Art. 6(1)(a) GDPR). We process your enquiry and manage your data within the framework of contractual or pre-contractual relationships in order to fulfil our pre-contractual and contractual obligations or to answer enquiries. The basis for this is Art. 6(1) sentence 1 (b) GDPR. In principle, where consent exists, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners.
WhatsApp privacy policy
WhatsApp summary
👥 Data subjects: WhatsApp users
🤝 Purpose: communication
📓 Data processed: contact data, messages, media
📅 Storage period: until account deletion or deactivation
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is WhatsApp?
On our website we use the instant messaging service WhatsApp. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. (until October 2021 Facebook Inc.). For the European region the company WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland is responsible.
We probably do not need to introduce WhatsApp to you in more detail. The probability that you use this well-known messaging service on your smartphone yourself is relatively high. For many years there have been voices criticising WhatsApp and its parent company Meta Platforms regarding the handling of personal data. In past years the main criticism related to the merging of WhatsApp user data with Facebook. Facebook responded in 2021 and adapted the terms of use. In them Facebook stated that currently (as of 2021) no personal data of WhatsApp users is shared with Facebook.
Nevertheless, of course, quite a lot of personal data about you is processed by WhatsApp if you use WhatsApp and have agreed to the data processing. Besides your phone number and chat messages this includes photos, videos and profile data sent. Photos and videos, however, are supposed to be cached only briefly and all messages and calls are provided with end-to-end encryption. They should therefore not be viewable even by Meta itself. In addition, information from your address book and other metadata is stored at WhatsApp.
Why do we use WhatsApp?
We want to stay in touch with you, and that works best via WhatsApp. On the one hand because the service works flawlessly, on the other hand because WhatsApp is still the most widely used instant messaging tool worldwide. The service is practical and enables uncomplicated and fast communication with you.
What data is processed by WhatsApp?
By using WhatsApp, various types of data, including personal data, may be processed. This includes account information such as your phone number, your profile picture, your user name or other information that you provide to WhatsApp when creating and managing the WhatsApp account. Of course WhatsApp also stores the content of your messages (text, photos, videos, voice messages). WhatsApp also stores so-called metadata, such as the date and time at which a message was sent or received. Phone numbers of the persons involved and technical data such as device type, operating system or location data are also stored.
How long and where is the data stored?
In principle the data is stored at WhatsApp for as long as is necessary for the legitimate purposes and to fulfil legal obligations. Exactly how long the data is stored cannot be answered concretely at this point, as this depends heavily on the type of data. As a rule, messages are only stored in encrypted form at WhatsApp during delivery and are deleted from the servers once a message has been delivered. Messages are stored longer only on your own device. If media is sent, WhatsApp stores this data in encrypted form for up to 30 days in order to optimise delivery. Account data is stored for as long as you have an active WhatsApp account. If you delete or deactivate the account, your account data is normally also deleted. The data stored at WhatsApp is stored by the company on its own servers, which are distributed all over the world. To operate the web-based WhatsApp services, data is also collected with the help of cookies.
How can I delete my data or prevent data storage?
You have the right at any time to access, rectification or deletion and restriction of the processing of your personal data. You can also withdraw your consent to the data processing at any time.
If you do not want cookies to be set in the desktop version and data to be stored as a result, you can also prevent cookies from being set in your browser. In your browser you can manage, deactivate or delete cookies. Depending on your browser this always works slightly differently. You can find more in our section on cookies.
Legal basis
The use of WhatsApp requires your consent, which we obtained with our consent tool (popup). According to Art. 6(1)(a) GDPR (consent), this consent is the legal basis for the processing of personal data, as may occur in collection by WhatsApp.
In addition to consent, we have a legitimate interest in improving our communication offering. With the help of WhatsApp we can respond to your enquiries faster and better, give you important messages and thus take our service to the next level. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use WhatsApp to the extent that you have given consent.
WhatsApp processes data about you, among other places, in the USA. WhatsApp is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition WhatsApp uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard contractual clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, WhatsApp undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
Information on data transfers at WhatsApp that correspond to the standard contractual clauses can be found at https://www.whatsapp.com/legal/business-data-transfer-addendum-20210927
We hope we have given you the most important information about the use and data processing by WhatsApp. You can find out more about the data processed through the use of WhatsApp in the privacy policy at https://www.whatsapp.com/privacy.
Video conferencing and streaming introduction
Video conferencing and streaming summary
👥 Data subjects: users who use our video conferencing or streaming tool
🤝 Purpose: communication and presentation of content
📓 Data processed: access statistics containing data such as name, address, contact details, e-mail address, phone number or your IP address. You can find more details with the respective video conferencing or streaming tool used.
📅 Storage period: depends on the video conferencing or streaming tool used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract)
What are video conferences and streaming?
We use software programs that enable us to hold video conferences, online meetings, webinars, display sharing and/or streaming. In a video conference or streaming, information is transmitted simultaneously via sound and moving image. With the help of such video conferencing or streaming tools we can communicate quickly and easily with customers, business partners, clients and also employees over the internet. Of course we pay attention to the legal framework when choosing the service provider.
In principle, third-party providers can process data as soon as you interact with the software program. Providers of video conferencing and streaming solutions use your data and metadata for different purposes. The data helps, for example, to make the tool more secure and to improve the service. Most of the time the data may also be used for the third-party provider’s own marketing purposes.
Why do we use video conferencing and streaming on our website?
We want to communicate with you, our customers and business partners digitally as well, quickly, simply and securely. That works best with video conferencing solutions that are very easy to use. Most tools also work directly via your browser and after just a few clicks you are in the middle of a video meeting. The tools also offer helpful extra features such as a chat and screen sharing function or the possibility to share content between meeting participants.
What data is processed?
If you take part in our video conference or in a streaming, data about you is also processed and stored on the servers of the respective service provider.
Exactly what data is stored depends on the solution used. Each provider stores and processes different data and different amounts of data. As a rule, however, most providers store your name, your address, contact data such as your e-mail address or phone number, and your IP address. In addition, information about your device used and usage data such as which websites you visit, when you visit a website or which buttons you click may be stored. Data shared within the video conference (photos, videos, texts) may also be stored.
Duration of data processing
We inform you about the duration of the data processing further below in connection with the service used, where we have further information. In general, we process personal data only for as long as is absolutely necessary for the provision of our services and products. It may be that the provider stores data about you according to its own rules, over which we then have no influence.
Right to object
You always have the right to access, rectification and deletion of your personal data. If you have questions, you can also contact those responsible for the video conferencing or streaming tool used at any time. You can find contact details either in our specific privacy policy or on the website of the respective provider.
Cookies that providers use for their functions can be deleted, deactivated or managed in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
Legal basis
If you have consented to data about you being processed and stored by the video or streaming solution, this consent is the legal basis for the data processing (Art. 6(1)(a) GDPR). In addition we may also offer a video conference as part of our services if this was agreed with you in advance (Art. 6(1)(b) GDPR). In principle your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners, but only insofar as you have at least consented. Most video and streaming solutions also set cookies in your browser to store data. We therefore recommend that you read our privacy text on cookies carefully and look at the privacy policy or cookie policy of the respective service provider.
Information on specific video conferencing and streaming solutions, where available, can be found in the following sections.
Zoom privacy policy
Zoom summary
👥 Data subjects: users who use Zoom
🤝 Purpose: an additional service for our website visitors
📓 Data processed: access statistics containing data such as name, address, contact details, e-mail address, phone number or your IP address. You can find more details further below in this privacy policy
📅 Storage period: data is stored for as long as Zoom needs it for the purpose of the service
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract)
What is Zoom?
For our website we use the video conferencing tool Zoom from the American software company Zoom Video Communications. The company headquarters is in San Jose, California, 55 Almaden Boulevard, 6th Floor, CA 95113. Thanks to “Zoom” we can hold a video conference with customers, business partners, clients and also employees very easily and without installing software. In this privacy policy we go into more detail about the service and inform you about the most important data protection aspects.
Zoom is one of the world’s best-known video conferencing solutions. With the “Zoom Meetings” service we can, for example, hold an online video conference with you, but also with employees or other users, in a digital conference room. In this way we can very easily get in touch digitally, discuss various topics, send text messages or even make phone calls. In addition, with Zoom you can also share the screen, exchange files and use a whiteboard.
Why do we use Zoom on our website?
It is important to us that we can communicate with you quickly and easily. And Zoom offers us exactly this possibility. The software program also works directly via a browser. This means we can simply send you a link and start the video conference right away. In addition, extra functions such as screen sharing or exchanging files are of course very practical.
What data is stored by Zoom?
When you use Zoom, data about you is also collected so that Zoom can provide its services. On the one hand this is data that you knowingly provide to the company. This includes, for example, name, phone number or your e-mail address. But data is also automatically transmitted to Zoom and stored. This includes, for example, technical data of your browser or your IP address. Below we go into more detail about the data that Zoom can collect and store:
If you provide data such as your name, your user name, your e-mail address or your phone number, this data is stored at Zoom. Content that you upload while using Zoom is also stored. This includes, for example, files or chat logs.
The technical data that Zoom automatically stores includes, besides the IP address already mentioned above, also the MAC address, other device IDs, device type, which operating system you use, which client you use, camera type, microphone and speaker type. Your approximate location is also determined and stored. Furthermore, Zoom also stores information about how you use the service. For example, whether you “zoom” via desktop or smartphone, whether you use a phone call or VoIP, whether you take part with or without video or whether you request a password. Zoom also records so-called metadata such as the duration of the meeting/call, start and end of meeting participation, meeting name and chat status.
In its own privacy policy Zoom mentions that the company does not use advertising cookies or tracking technologies for its services. These tracking methods are only used on its own marketing websites such as https://explore.zoom.us/docs/de-de/home.html. Zoom does not sell personal data on and does not use it for advertising purposes.
How long and where is the data stored?
Zoom does not give a specific timeframe in this regard, but emphasises that the data collected remains stored for as long as necessary to provide the services or for its own purposes. The data is only stored longer if this is required for legal reasons.
In principle Zoom stores the data collected on American servers, but data may arrive at different data centres worldwide.
How can I delete my data or prevent data storage?
If you do not want data to be stored during the Zoom meeting, you must forgo the meeting. But you also always have the right and the possibility to have all your personal data deleted. If you have a Zoom account, you can find instructions on how to delete your account at https://support.zoom.us/hc/en-us/articles/201363243-How-Do-I-Delete-Terminate-My-Account.
Please note that when using this tool, data about you may also be stored and processed outside the EU. Most third countries (including the USA) are considered not safe under current European data protection law. Data may therefore not simply be transferred to unsafe third countries, stored and processed there, unless there are suitable guarantees (such as EU standard contractual clauses) between us and the non-European service provider.
Legal basis
If you have consented to data about you being processed and stored by the video or streaming solution, this consent is the legal basis for the data processing (Art. 6(1)(a) GDPR). In addition we may also offer a video conference as part of our services if this was agreed with you in advance (Art. 6(1)(b) GDPR). In principle your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners, but only insofar as you have at least consented.
Zoom processes data about you, among other places, in the USA. Zoom is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition Zoom uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard contractual clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Zoom undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
We hope to have given you an overview of the data processing by Zoom. Of course it can always happen that the company’s privacy policies change. We therefore recommend that you also consult Zoom’s privacy policy at https://explore.zoom.us/de/privacy/ for more information on the processed data and the standard contractual clauses.
Data processing agreement (AVV) Zoom
We have concluded a data processing agreement (AVV) with Zoom within the meaning of Article 28 of the General Data Protection Regulation (GDPR). What an AVV is exactly and above all what must be contained in an AVV you can read in our general section “Data processing agreement (AVV)”.
This contract is required by law because Zoom processes personal data on our behalf. It clarifies that Zoom may only process data it receives from us on our instructions and must comply with the GDPR. You can find more about the data processing agreement (AVV) with Zoom at https://sdpc.a4l.org/agreements/2023-02-27_2547_1974_signed_agreement_file.pdf.
Contact form and enquiries
If you send us an enquiry via the contact form on our website, we process the data you entered (name, e-mail address, phone number and the content of your message) as well as the date and time of the enquiry, in order to process your enquiry and get in touch with you. The fields marked as mandatory are required so that we can answer your enquiry.
The data from the form is sent to us by e-mail via the mail server of our provider STRATO GmbH (see section Web hosting). In addition, we store the enquiry in an enquiry log on our own server so that no enquiry is lost. The form data is not passed on to any other third parties.
The legal basis is Art. 6(1)(b) GDPR, insofar as your enquiry is related to the performance of a contract or pre-contractual measures, otherwise our legitimate interest in answering your enquiry (Art. 6(1)(f) GDPR).
We store your enquiry for up to 12 months after receipt and then delete it automatically. If a contractual relationship results, we keep the data required for it for as long as statutory retention obligations demand. You can request early deletion of your enquiry at any time.
Cookie consent with Complianz
On our website we use the WordPress plugin Complianz to obtain your consent to cookies and comparable technologies. Complianz runs on our own server. On your first visit you are informed by a banner and can choose which categories of cookies you agree to (e.g. statistics and marketing). Technically non-essential services, including Google Tag Manager, Google Ads, the Meta Pixel and Matomo, are only loaded after your consent.
Your decision is stored in a cookie in your browser so that you are not asked again on further visits. This cookie is technically necessary. The legal basis is § 25(2) No. 2 TDDDG and Art. 6(1)(f) GDPR (legitimate interest in storing your settings and being able to prove them). You can change or withdraw your consent at any time via the cookie settings on our website.
Proof of your consent
So that we can prove that and how you consented to or rejected the use of cookies (Art. 7(1) GDPR), we keep a consent log. When you make a choice in the cookie banner, we store: a randomly generated number (consent ID), date and time, your choice (statistics, marketing, preferences), the language of the website and the version of the banner. Your IP address, name and e-mail address are not stored for this purpose. The consent ID is also stored in a technically necessary cookie (vd_consent_id) in your browser so that we can match your choice if you contact us.
The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (obligation to demonstrate consent) and Art. 6(1)(f) GDPR (legitimate interest in providing evidence); for the cookie § 25(2) No. 2 TDDDG. Entries are deleted after three years.
Your consent ID in this browser is: no choice made yet. If you contact us, please give us this number so that we can find your entry.
Language selection
Our website is available in several languages (German, Russian and English). To save the language you have chosen, we set a technically necessary cookie. It contains no information about your person. The legal basis is § 25(2) No. 2 TDDDG and Art. 6(1)(f) GDPR (legitimate interest in a user-friendly display of the website).
Links to social networks
On our website you will find links to our profiles on Instagram (Meta Platforms Ireland Limited), TikTok (TikTok Technology Limited, Ireland) and YouTube (Google Ireland Limited). These are simple links, not embedded content or plugins. When you open our page, therefore, no data is transmitted to these providers. Only when you click on a link are you forwarded to the page of the respective provider, and its privacy policy applies there.
Use of Google Tag Manager
We use Google Tag Manager to manage JavaScript tags (so-called tags) on our website. Google Tag Manager itself does not set cookies and does not collect personal data. When a page is loaded, a technical connection to Google servers is established and your IP address is transmitted.
Google Tag Manager is provided to us by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). GTM is only loaded after your consent. The legal basis is Art. 6(1)(a) GDPR.
The following services that process personal data are integrated on our website via Google Tag Manager: Google Ads, Meta Pixel. You will find the privacy information on these services in the following sections of this privacy policy.
Source: traffic3.net
Use of Google Ads
We advertise in Google search and on other websites via the Google Ads service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google processes the data on our behalf and contractually undertakes to take measures to ensure the security and confidentiality of the processed data. This data is transferred to Google servers in the USA. Google LLC is certified under the EU-US Data Privacy Framework (DPF). For data transfers to the USA there are therefore adequate guarantees within the meaning of Art. 45 GDPR.
The legal basis for all of the following processing is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our cookie settings dialogue.
Conversion tracking
Google Ads conversion tracking enables us to measure the success of our advertising campaigns. If you click on one of our ads and then visit our website, a cookie is set in your browser. Via this cookie we can see whether, after clicking on one of our ads, you carried out a desired action on our website, for example filled in a form or made an enquiry.
In doing so, the following data, among others, is transmitted to Google:
- pages or URLs visited
- achievement of conversion goals (e.g. enquiries)
- your internet address (IP address)
- technical information such as browser, device and screen resolution
- a randomly generated user ID
The conversion tracking cookie and the click ID (gclid) set when you click on an ad are stored in your web browser for 90 days.
Remarketing
We also use Google Remarketing to show you personalised ads on other websites, in Google search and on YouTube after you have visited our website. For this a cookie is stored in your browser containing information about the pages you visited on our website. The remarketing cookie is stored in your web browser for up to 13 months.
You can object to the collection via our cookie settings dialogue. In addition you can prevent interest-based advertising via Google’s ad settings or by installing the browser plugin for deactivating Google ad personalisation.
Source: traffic3.net
Use of the Meta Pixel (Facebook Pixel)
We advertise on Facebook and Instagram. In this context we have integrated the “Meta Pixel” on our website.
The Meta Pixel enables us to:
- measure the success of our advertising measures on Facebook and Instagram (conversion tracking)
- address visitors to our website again with ads on Facebook and Instagram (remarketing)
- tailor personalised ads to previously viewed pages or products
The Meta Pixel is provided to us by Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland). Meta processes the data on our behalf and contractually undertakes to take measures to ensure the security and confidentiality of the processed data.
During your visit to the website, the following data, among others, is transmitted to Meta:
- pages visited
- achievement of website goals (e.g. enquiries)
- your internet address (IP address)
- technical information such as browser, device and screen resolution
- a randomly generated user ID
- a randomly generated ad click ID, if you reached our website via an ad
No personal data such as name, address or contact details is transmitted to Meta.
This data is transferred to Meta servers in the USA. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework (DPF). For data transfers to the USA there are therefore adequate guarantees within the meaning of Art. 45 GDPR.
Meta stores cookies in your web browser for one year from your last visit. These cookies contain a randomly generated user ID with which you can be recognised on future visits. If you are logged in to Meta services such as Facebook or Instagram, Meta can additionally assign the visit to your account.
The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. You can withdraw your consent at any time via our cookie settings dialogue.
Source: traffic3.net
All texts are protected by copyright.
Source: Privacy policy created with the Datenschutz Generator für Deutschland by AdSimple. Also take a look at our sample privacy policy.