Introduction and Overview
We have written this privacy policy (version 01.08.2026-112749124) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We comprehensively inform you about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is intended to describe the most important things to you as simply and transparently as possible. Where it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided and graphics are used. We thus inform you in clear and simple language that we only process personal data in the course of our business activities when there is a corresponding legal basis. This is certainly not possible by providing the briefest, most opaque, jargon-laden legal explanations possible, as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information you did not already know.
If you still have questions, we would like to ask you to contact the responsible body named below or in the legal notice, follow the existing links and look at further information on third-party sites. Our contact details can of course also be found in the legal notice.
Scope
This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and bill for our services and products, whether online or offline. The scope of this privacy policy includes:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile apps for smartphones and other devices
In short: The privacy policy applies to all areas in which personal data is processed in a structured manner in the company via the channels mentioned. Should we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
Legal Bases
In the following privacy policy, we provide you with transparent information about the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, that allow us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this General Data Protection Regulation of the EU online on EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 .
We only process your data if at least one of the following conditions applies:
- Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of data you have entered in a contact form.
- Contract (Article 6(1)(b) GDPR): To fulfil a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and cost-effectively. This processing is therefore a legitimate interest.
Other conditions such as the performance of tasks in the public interest and the exercise of official authority, as well as the protection of vital interests, do not usually apply to us. If such a legal basis is relevant, it will be indicated at the appropriate point.
In addition to the EU regulation, national laws also apply:
- In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated as DSG.
- In Germany, the Federal Data Protection Act, abbreviated as BDSG, applies.
If other regional or national laws apply, we will inform you about them in the following sections.
Contact Details of the Controller
If you have any questions about data protection or the processing of personal data, you will find the contact details of the controller pursuant to Article 4(7) of the EU General Data Protection Regulation (GDPR) below:
Schiegl Informatics FlexCo
Unterer Stadtplatz 11, 6330 Kufstein, Austria
Represented by: Alexander Schiegl
Email: datenschutz@schiegl-informatics.at
Legal notice: https://schiegl-informatics.at/impressum/
Storage Duration
The general criterion for us is that we only store personal data for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
If you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.
We will inform you below about the specific duration of the respective data processing, provided we have further information on this.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you of the following rights to which you are entitled in order to ensure fair and transparent processing of data:
- Under Article 15 GDPR, you have a right of access as to whether we process data about you. If this is the case, you have the right to receive a copy of the data and to know the following information:
- for what purpose we carry out the processing;
- the categories, i.e. the types of data being processed;
- who receives this data, and if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the origin of the data if we did not collect it from you;
- whether profiling is carried out, i.e. whether data is automatically evaluated in order to arrive at a personal profile of you.
- Under Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors.
- Under Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.
- Under Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but no longer use it.
- Under Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
- Under Article 21 GDPR, you have a right to object, which, once enforced, entails a change in processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
- If data is used for direct marketing purposes, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used for profiling purposes, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
- Under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (e.g. profiling).
- Under Article 77 GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights – do not hesitate to contact the responsible body listed above!
If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the Data Protection Authority, whose website you can find at https://www.dsb.gv.at/ . In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) . The following local data protection authority is responsible for our company:
Austrian Data Protection Authority
Director: Dr. Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Data Transfer to Third Countries
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to this processing or there is other legal permission. This applies in particular if the processing is required by law or necessary for the fulfilment of a contractual relationship and in any case only insofar as this is generally permitted. Your consent is in most cases the most important reason that we have data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfer to the USA currently only exists if a US company that processes personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. More information on this can be found at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data not being anonymised and stored. Furthermore, US government authorities may have access to individual data. In addition, it is possible that collected data may be linked with data from other services of the same provider, provided you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.
We will inform you in more detail at the appropriate points in this privacy policy about data transfers to third countries, where applicable.
Security of Data Processing
To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as possible within our capabilities for third parties to infer personal information from our data.
Art. 25 GDPR speaks here of "data protection by design and by default" and means that both software (e.g. forms) and hardware (e.g. access to the server room) should always be designed with security in mind and appropriate measures should be taken. We will go into specific measures below, if necessary.
TLS Encryption with HTTPS
TLS, encryption and HTTPS sound very technical and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data securely on the internet.
This means that the complete transmission of all data from your browser to our web server is secured – no one can "listen in".
We have thus introduced an additional layer of security and comply with data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission security by the small lock symbolin the top left of the browser, to the left of the internet address (e.g. examplesite.com) and by the use of the https scheme (instead of http) as part of our internet address.
If you want to know more about encryption, we recommend a Google search for "Hypertext Transfer Protocol Secure wiki" to get good links to further information.
Communication
| Communication Summary 👥 Data subjects: Anyone who communicates with us by phone, email or online form 📓 Data processed: e.g. phone number, name, email address, form data entered. More details can be found under the respective type of contact used 🤝 Purpose: Handling communication with customers, business partners, etc. 📅 Storage duration: Duration of the business case and statutory provisions ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests) |
When you contact us and communicate by phone, email or online form, personal data may be processed.
The data is processed for the handling and processing of your question and the related business transaction. The data is stored for the same duration or as long as the law requires.
Data Subjects
All persons who seek contact with us via the communication channels we provide are affected by the aforementioned processes.
Phone
When you call us, the call data is stored in pseudonymised form on the respective device and by the telecommunications provider used. In addition, data such as name and phone number may subsequently be sent by email and stored for the purpose of responding to enquiries. The data is deleted once the business case has been concluded and legal requirements permit.
When you communicate with us by email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted once the business case has been concluded and legal requirements permit.
Online Forms
When you communicate with us via an online form, data is stored on our web server and may be forwarded to one of our email addresses. The data is deleted once the business case has been concluded and legal requirements permit.
Legal Bases
The processing of data is based on the following legal bases:
- Art. 6(1)(a) GDPR (consent): You give us consent to store your data and continue to use it for purposes relevant to the business case;
- Art. 6(1)(b) GDPR (contract): There is a necessity for the fulfilment of a contract with you or a processor such as the telephone provider, or we need to process the data for pre-contractual activities, such as preparing a quote;
- Art. 6(1)(f) GDPR (legitimate interests): We want to conduct customer enquiries and business communication in a professional manner. Certain technical facilities such as email programs, Exchange servers and mobile network operators are necessary to operate communication efficiently.
Data Processing Agreement (DPA)
In this section, we would like to explain to you what a data processing agreement is and why it is needed. Because the term "data processing agreement" is quite a mouthful, we will also frequently use the abbreviation DPA here in the text. Like most companies, we do not work alone but also make use of the services of other companies or individuals. By involving various companies or service providers, it may be that we pass on personal data for processing. These partners then act as processors, with whom we conclude a contract, the so-called data processing agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be regulated by the DPA.
Who are processors?
As a company and website owner, we are responsible for all data we process from you. In addition to controllers, there can also be so-called processors. This includes any company or person that processes personal data on our behalf. More precisely, and according to the GDPR definition: any natural or legal person, authority, institution or other body that processes personal data on our behalf is considered a processor. Processors can therefore be service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
For a better understanding of the terminology, here is an overview of the three roles in the GDPR:
Data subject (you as a customer or interested party) → Controller (we as a company and client) → Processor (service providers such as web hosts or cloud providers)
Content of a Data Processing Agreement
As already mentioned above, we have concluded a DPA with our partners who act as processors. First and foremost, it stipulates that the processor processes the data to be processed exclusively in accordance with the GDPR. The contract must be concluded in writing, although electronic contract conclusion is also considered "written" in this context. The processing of personal data only takes place on the basis of the contract. The contract must contain the following:
- Binding to us as the controller
- Obligations and rights of the controller
- Categories of data subjects
- Types of personal data
- Nature and purpose of data processing
- Subject matter and duration of data processing
- Place of data processing
Furthermore, the contract contains all obligations of the processor. The most important obligations are:
- To ensure measures for data security
- To take possible technical and organisational measures to protect the rights of the data subject
- To maintain a data processing register
- To cooperate with the data protection supervisory authority upon request
- To carry out a risk analysis with regard to the personal data received
- Sub-processors may only be commissioned with the written consent of the controller
You can see what such a DPA looks like in concrete terms, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html . A sample contract is presented there.
Cookies
| Cookies Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Depending on the respective cookie. More details can be found below or from the manufacturer of the software that sets the cookie. 📓 Data processed: Depending on the cookie used in each case. More details can be found below or from the manufacturer of the software that sets the cookie. 📅 Storage duration: Depending on the respective cookie, can vary from hours to years ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are cookies?
Our website uses HTTP cookies to store user-specific data.
In the following, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you surf the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other application areas. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, essentially the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, trojans or other "malware". Cookies also cannot access information on your PC.
For example, cookie data can look like this:
Name: _ga
Value: GA1.2.1326744211.152112749124-9
Purpose: Distinguishing website visitors
Expiry date: after 2 years
A browser should be able to support these minimum sizes:
- At least 4096 bytes per cookie
- At least 50 cookies per domain
- At least 3000 cookies in total
What types of cookies are there?
The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly address the different types of HTTP cookies.
4 types of cookies can be distinguished:
Essential cookies
These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user puts a product in the shopping cart, then continues surfing on other pages and only goes to the checkout later. These cookies ensure that the shopping cart is not deleted, even if the user closes the browser window.
Performance cookies
These cookies collect information about user behaviour and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behaviour of the website in different browsers.
Functional cookies
These cookies ensure a better user experience. For example, entered locations, font sizes or form data are saved.
Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually customised advertising to the user. This can be very practical but also very annoying.
Usually, when you first visit a website, you are asked which of these cookie types you wish to allow. And of course, this decision is also stored in a cookie.
If you want to learn more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called "HTTP State Management Mechanism".
Purpose of Processing via Cookies
The purpose ultimately depends on the respective cookie. More details can be found below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are little helpers for many different tasks. Unfortunately, it is not possible to generalise which data is stored in cookies, but we will inform you about the data processed or stored within the framework of the following privacy policy.
Storage Duration of Cookies
The storage duration depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, while others can remain stored on a computer for several years.
You also have an influence on the storage duration yourself. You can manually delete all cookies at any time via your browser (see also "Right to object" below). Furthermore, cookies based on consent will be deleted at the latest after you withdraw your consent, although the lawfulness of storage until that point remains unaffected.
Right to Object – How can I delete cookies?
You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option of deleting, deactivating or only partially allowing cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies to remove data that websites have placed on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want cookies, you can set up your browser to always inform you when a cookie is to be set. This way, you can decide for each individual cookie whether you allow it or not. The procedure varies depending on the browser. It is best to search for the instructions in Google with the search term "delete cookies Chrome" or "disable cookies Chrome" in the case of a Chrome browser.
Legal Basis
Since 2009, there have been the so-called "cookie directives". These state that the storage of cookies requires your consent (Article 6(1)(a) GDPR). Within the EU countries, however, reactions to these directives still vary considerably. In Austria, the implementation of this directive took place in Section 165(3) of the Telecommunications Act (2021). In Germany, the cookie directives were not implemented as national law. Instead, the implementation of this directive was largely carried out in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even without consent, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to provide website visitors with a pleasant user experience, and certain cookies are often strictly necessary for this.
Where non-essential cookies are used, this only occurs with your consent. The legal basis in this regard is Art. 6(1)(a) GDPR.
In the following sections, you will be informed in more detail about the use of cookies, provided that the software used employs cookies.
Web Hosting Introduction
| Web Hosting Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Professional hosting of the website and securing operations 📓 Data processed: IP address, time of website visit, browser used and other data. More details can be found below or from the respective web hosting provider. 📅 Storage duration: Depending on the respective provider, but usually 2 weeks ⚖️ Legal bases: Art. 6(1)(f) GDPR (legitimate interests) |
What is web hosting?
When you visit websites today, certain information – including personal data – is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) to the very last sub-page (like this one). By domain, we mean, for example, example.com or sampleexample.com.
When you want to view a website on a computer, tablet or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We call them browsers or web browsers for short.
To display the website, the browser must connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why this is usually taken over by professional providers, the hosting providers. They offer web hosting and thus ensure reliable and error-free storage of website data. A lot of technical terms, but please stay with us, it gets even better!
When the browser on your computer (desktop, laptop, tablet or smartphone) connects and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server also needs to store data for a period of time to ensure proper operation.
A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the internet and the hosting provider.
Why do we process personal data?
The purposes of data processing are:
- Professional hosting of the website and securing operations
- To maintain operational and IT security
- Anonymous evaluation of access behaviour to improve our offering and, if necessary, for prosecution or pursuit of claims
What data is processed?
Even while you are currently visiting our website, our web server, the computer on which this website is stored, usually automatically stores data such as
- the complete internet address (URL) of the accessed web page
- browser and browser version (e.g. Chrome 87)
- the operating system used (e.g. Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
- the hostname and IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
- date and time
- in files, the so-called web server log files
How long is data stored?
As a rule, the above-mentioned data is stored for two weeks and then automatically deleted. We do not pass on this data, but cannot exclude the possibility that this data may be viewed by authorities in the event of unlawful behaviour.
In short: Your visit is logged by our provider (company that runs our website on special computers (servers)), but we do not pass on your data without consent!
Legal Basis
The lawfulness of processing personal data in the context of web hosting results from Art. 6(1)(f) GDPR (safeguarding legitimate interests), as the use of professional hosting with a provider is necessary to present the company on the internet in a secure and user-friendly manner and to be able to prosecute any such attacks and pursue resulting claims arising from this if necessary.
Between us and the hosting provider, there is usually a contract for data processing agreement (DPA) in accordance with Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.
External Web Hosting Provider Privacy Policy
Below you will find the contact details of our external hosting provider, where you can learn more about data processing in addition to the information above:
netcup GmbH
Daimlerstrasse 25, 76185 Karlsruhe, Germany
You can learn more about data processing at this provider in their privacy policy.
Web Analytics Introduction
| Web Analytics Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Evaluation of visitor information to optimise the web offering. 📓 Data processed: Access statistics containing data such as access locations, device data, access duration and time, navigation behaviour, click behaviour and IP addresses. More details can be found in the respective web analytics tool used. 📅 Storage duration: Depending on the web analytics tool used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is web analytics?
We use software on our website to evaluate the behaviour of website visitors, known as web analytics or web analysis. Data is collected that the respective analytics tool provider (also called a tracking tool) stores, manages and processes. Analyses of user behaviour on our website are created with the help of the data and made available to us as website operators. In addition, most tools offer various testing options. For example, we can test which offers or content appeal most to our visitors. For this purpose, we show you two different offers for a limited period of time. After the test (so-called A/B test), we know which product or content our website visitors find more interesting. For such test procedures, as well as other analytics procedures, user profiles can also be created and the data stored in cookies.
Why do we use web analytics?
With our website, we have a clear goal in mind: we want to deliver the best web offering on the market for our industry. To achieve this goal, we want to offer the best and most interesting offering on the one hand, and on the other hand, make sure that you feel completely comfortable on our website. With the help of web analytics tools, we can take a closer look at the behaviour of our website visitors and then improve our web offering accordingly for you and for us. For example, we can see how old our visitors are on average, where they come from, when our website is most visited or which content or products are particularly popular. All this information helps us to optimise the website and thus adapt it best to your needs, interests and wishes.
What data is processed?
Which data is stored exactly depends on the analysis tools used. However, as a rule, for example, which content you view on our website, which buttons or links you click, when you access a page, which browser you use, which device (PC, tablet, smartphone, etc.) you use to visit the website or which computer system you use is stored. If you agreed that location data may also be collected, this can also be processed by the web analytics tool provider.
In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are personal data. However, your IP address is usually stored in pseudonymised (i.e. unrecognisable and abbreviated) form. For the purpose of tests, web analytics and web optimisation, no direct data such as your name, age, address or email address is stored. All this data, if collected, is stored pseudonymised. This means you cannot be identified as a person.
The following example shows schematically the functionality of Google Analytics as an example of client-based web tracking with JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data for only a few minutes or until you leave the website, while other cookies can store data for several years.
Duration of Data Processing
We will inform you about the duration of data processing below, if we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. If required by law, such as in the case of accounting, this storage period may also be exceeded.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.
Legal Basis
The use of web analytics requires your consent, which we have obtained with our cookie popup. This consent constitutes, according to Art. 6(1)(a) GDPR (consent) the legal basis for the processing of personal data, as may occur when collected by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of web analytics, we can identify errors on the website, identify attacks and improve profitability. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use the tools insofar as you have given your consent.
Since cookies are used in web analytics tools, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools can be found – if available – in the following sections.
Google Analytics Privacy Policy
| Google Analytics Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Evaluation of visitor information to optimise the web offering. 📓 Data processed: Access statistics containing data such as access locations, device data, access duration and time, navigation behaviour and click behaviour. More details can be found further below in this privacy policy. 📅 Storage duration: Individually configurable; by default, Google Analytics 4 stores data for 14 months ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Google Analytics?
We use the analysis tracking tool Google Analytics in the version Google Analytics 4 (GA4) from the American company Google Inc. on our website. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. Through the combination of various technologies such as cookies, device IDs and login information, you can be identified as a user across different devices. This means your actions can also be analysed across platforms.
For example, when you click a link, this event is stored in a cookie and sent to Google Analytics. With the help of the reports we receive from Google Analytics, we can better tailor our website and service to your wishes. In the following, we will go into more detail about the tracking tool and inform you above all about which data is processed and how you can prevent this.
Google Analytics is a tracking tool that serves to analyse website traffic. The basis of these measurements and analyses is a pseudonymous user identification number. This number does not contain personal data such as name or address, but is used to assign events to a device. GA4 uses an event-based model that captures detailed information about user interactions such as page views, clicks, scrolling and conversion events. In addition, various machine learning functions have been built into GA4 to better understand user behaviour and certain trends. GA4 relies on modelling with the help of machine learning functions. This means that on the basis of the data collected, missing data can also be extrapolated in order to optimise the analysis and to be able to make forecasts.
For Google Analytics to work, a tracking code is built into the code of our website. When you visit our website, this code records various events that you perform on our website. With the event-based data model of GA4, we as website operators can define and track specific events to obtain analyses of user interactions. In addition to general information such as clicks or page views, specific events that are important for our business can also be tracked. Such special events can be, for example, submitting a contact form or purchasing a product.
Once you leave our website, this data is sent to and stored on the Google Analytics servers.
Google processes the data and we receive reports about your user behaviour. These may include the following reports, among others:
- Audience reports: Through audience reports, we get to know our users better and know more precisely who is interested in our service.
- Display reports: Display reports make it easier for us to analyse and improve our online advertising.
- Acquisition reports: Acquisition reports give us helpful information about how we can attract more people to our service.
- Behaviour reports: Here we learn how you interact with our website. We can trace the path you take on our site and which links you click.
- Conversion reports: Conversion refers to a process in which you perform a desired action as a result of a marketing message. For example, when you go from being a mere website visitor to a buyer or newsletter subscriber. With the help of these reports, we learn more about how our marketing measures resonate with you. This is how we want to increase our conversion rate.
- Real-time reports: Here we always find out immediately what is happening on our website. For example, we can see how many users are currently reading this text.
In addition to the above-mentioned analysis reports, Google Analytics 4 also offers the following functions, among others:
- Event-based data model: This model captures very specific events that can take place on our website. For example, playing a video, purchasing a product or signing up for our newsletter.
- Advanced analysis functions: With these functions, we can better understand your behaviour on our website or certain general trends. For example, we can segment user groups, make comparative analyses of target groups or trace your path on our website.
- Predictive modelling: On the basis of collected data, missing data can be extrapolated through machine learning to predict future events and trends. This can help us develop better marketing strategies.
- Cross-platform analysis: Data collection and analysis is possible from both websites and apps. This gives us the opportunity to analyse user behaviour across platforms, provided you have of course consented to data processing.
Why do we use Google Analytics on our website?
Our goal with this website is clear: We want to provide you with the best possible service. The statistics and data from Google Analytics help us achieve this goal.
The statistically evaluated data gives us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimise our site so that it can be found more easily by interested people on Google. On the other hand, the data helps us to better understand you as a visitor. We therefore know very precisely what we need to improve on our website to provide you with the best possible service. The data also helps us to carry out our advertising and marketing measures more individually and cost-effectively. After all, it only makes sense to show our products and services to people who are interested in them.
What data is stored by Google Analytics?
Google Analytics creates a random, unique ID associated with your browser cookie using a tracking code. This is how Google Analytics recognises you as a new user and you are assigned a user ID. The next time you visit our site, you are recognised as a "returning" user. All collected data is stored together with this user ID. This is the only way pseudonymous user profiles can be evaluated.
To be able to analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. The Google Analytics 4 property is the default for every newly created property. Depending on the property used, data is stored for different lengths of time.
Through identifiers such as cookies, app instance IDs, user IDs or custom event parameters, your interactions are measured across platforms, provided you have consented. Interactions are all types of actions you perform on our website. If you also use other Google systems (such as a Google Account), data generated via Google Analytics can be linked with third-party cookies. Google does not pass on Google Analytics data unless we as website operators authorise it. Exceptions may occur if required by law.
According to Google, no IP addresses are logged or stored in Google Analytics 4. However, Google uses IP address data to derive location data and deletes it immediately afterwards. All IP addresses collected from users in the EU are deleted before the data is stored in a data centre or on a server.
Since Google Analytics 4 focuses on event-based data, the tool uses significantly fewer cookies compared to earlier versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies used by GA4. These include, for example:
Name: _ga
Value: 2.1326744211.152112749124-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Basically, it serves to distinguish website visitors.
Expiry date: after 2 years
Name: _gid
Value: 2.1687193234.152112749124-1
Purpose: The cookie also serves to distinguish website visitors
Expiry date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose:Used to throttle the request rate. When Google Analytics is deployed via Google Tag Manager, this cookie is named _dc_gtm_ <property-id>.
Expiry date: after 1 minute
Note: This list cannot claim to be exhaustive, as Google also changes its choice of cookies from time to time. The aim of GA4 is also to improve data protection. Therefore, the tool offers some options for controlling data collection. For example, we can set the storage duration ourselves and also control data collection.
Here we show you an overview of the main types of data collected with Google Analytics:
Heatmaps:Google creates so-called heatmaps. Heatmaps show exactly those areas that you click on. This gives us information about where you "travel" on our site.
Session duration: Google defines session duration as the time you spend on our site without leaving. If you have been inactive for 20 minutes, the session ends automatically.
Bounce rate: A bounce occurs when you only view one page on our website and then leave our website again.
Account creation: When you create an account or place an order on our website, Google Analytics collects this data.
Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, derivations for location data are used.
Technical information: Technical information includes, among other things, your browser type, your internet provider or your screen resolution.
Source of origin: Google Analytics or we are of course also interested in which website or which advertisement brought you to our site.
Other data includes contact details, any reviews, playing media (e.g. when you play a video via our site), sharing content via social media or adding to your favourites. The list makes no claim to completeness and only serves as a general guide to data storage by Google Analytics.
How long and where is the data stored?
Google has its servers distributed around the world. You can read exactly where the Google data centres are located here: https://datacenters.google/
Your data is distributed across different physical data carriers. This has the advantage that the data is more quickly retrievable and better protected against manipulation. Every Google data centre has appropriate emergency programmes for your data. If, for example, Google's hardware fails or natural disasters paralyse servers, the risk of a service interruption at Google remains low.
The retention period of the data depends on the properties used. The storage period is always set separately for each individual property. Google Analytics offers us four options for controlling the storage period:
- 2 months: this is the shortest storage period.
- 14 months: by default, data is stored in GA4 for 14 months.
- 26 months: data can also be stored for 26 months.
- Data is only deleted when we delete it manually
In addition, there is also the option that data is only deleted when you no longer visit our website within the period we have chosen. In this case, the retention period is reset each time you visit our website within the set period.
When the set period has expired, the data is deleted once a month. This retention period applies to your data linked to cookies, user recognition and advertising IDs (e.g. DoubleClick domain cookies). Report results are based on aggregated data and are stored independently of user data. Aggregated data is a merging of individual data into a larger unit.
How can I delete my data or prevent data storage?
Under the data protection law of the European Union, you have the right to obtain access to, update, delete or restrict your data. Using the browser add-on to disable Google Analytics JavaScript (analytics.js, gtag.js), you can prevent Google Analytics 4 from using your data. The browser add-on can be downloaded and installed at https://tools.google.com/dlpage/gaoptout?hl=de . Please note that this add-on only disables data collection by Google Analytics.
If you generally want to deactivate, delete or manage cookies, you will find the corresponding links to the respective instructions of the most common browsers under the "Cookies" section.
Legal Basis
The use of Google Analytics requires your consent, which we have obtained with our cookie popup. This consent constitutes, according to Art. 6(1)(a) GDPR (consent) the legal basis for the processing of personal data, as may occur when collected by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of Google Analytics, we can identify website errors, identify attacks and improve profitability. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Google Analytics insofar as you have given your consent.
Google also processes your data in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
We hope we have been able to provide you with the most important information about data processing by Google Analytics. If you want to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.
If you want to learn more about data processing, please refer to the Google privacy policy at https://policies.google.com/privacy?hl=de.
Data Processing Agreement (DPA) Google Analytics
We have concluded a data processing agreement (DPA) with Google within the meaning of Article 28 of the General Data Protection Regulation (GDPR). You can read what a DPA is and what must be included in a DPA in our general section "Data Processing Agreement (DPA)".
This contract is required by law because Google processes personal data on our behalf. It clarifies that Google may only process data that it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the data processing terms at https://business.safety.google/intl/de/adsprocessorterms/
Google Analytics Reports on Demographics and Interests
We have activated the advertising reporting functions in Google Analytics. The reports on demographics and interests contain information about age, gender and interests. This allows us – without being able to assign this data to individual persons – to get a better picture of our users. You can learn more about the advertising functions at https://support.google.com/analytics/answer/3450482?hl=de_AT&utm_id=ad.
You can stop the use of activities and information from your Google Account under "Ad Settings" at https://adssettings.google.com/authenticated via the checkbox.
Google Analytics in Consent Mode
Depending on your consent, personal data from you is processed by Google Analytics in the so-called consent mode. You can choose whether or not to consent to Google Analytics cookies. This also determines which data Google Analytics may process from you. This collected data is primarily used to carry out measurements of user behaviour on the website, deliver targeted advertising and provide us with web analytics reports. As a rule, you consent to data processing by Google via a cookie consent tool. If you do not consent to data processing, only aggregated data is collected and processed. This means that data cannot be assigned to individual users and no user profile is created for you. You can also only consent to statistical measurement. In this case, no personal data is processed and consequently not used for advertising or advertising measurement results.
Google Analytics IP Anonymisation
We have implemented IP address anonymisation from Google Analytics on this website. This function was developed by Google so that this website can comply with the applicable data protection regulations and recommendations of the local data protection authorities if they prohibit the storage of the full IP address. The anonymisation or masking of the IP takes place as soon as the IP addresses arrive in the Google Analytics data collection network and before any storage or processing of the data takes place.
More information on IP anonymisation can be found at https://support.google.com/analytics/answer/2763052?hl=de.
Messenger & Communication Introduction
| Messenger & Communication Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Contact requests and general communication between us and you 📓 Data processed: Data such as name, address, email address, phone number, general content data, IP address if applicable More details can be found with the respective tools used. 📅Storage duration: Depending on the messenger & communication functions used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1) sentence 1 (b) GDPR (contractual or pre-contractual obligations) |
What are messenger & communication functions?
We offer various ways on our website (such as messenger and chat functions, online or contact forms, email, phone) to communicate with us. In doing so, your data is also processed and stored to the extent necessary for answering your enquiry and our subsequent measures.
In addition to classic means of communication such as email, contact forms or phone, we also use chats and messengers. The most commonly used messenger function is currently WhatsApp, but of course there are many different providers, especially for websites, that offer messenger functions. If content is end-to-end encrypted, this is indicated in the individual data protection texts or in the privacy policy of the respective provider. End-to-end encryption means nothing other than that the content of a message is not visible even to the provider. However, information about your device, location settings and other technical data may still be processed and stored.
Why do we use messenger & communication functions?
Communication options with you are of great importance to us. After all, we want to talk to you and answer all possible questions about our service in the best possible way. Well-functioning communication is an important part of our service. With the practical messenger & communication functions, you can always choose those that you prefer. In exceptional cases, however, it may happen that we do not answer certain questions via chat or messenger. This is the case, for example, when it involves internal contractual matters. Here we recommend other communication options such as email or phone.
We generally assume that we remain responsible under data protection law, even if we use services of a social media platform. However, the European Court of Justice has ruled that in certain cases the operator of the social media platform can be jointly responsible with us within the meaning of Art. 26 GDPR. If this is the case, we will point this out separately and work on the basis of a relevant agreement. The essence of the agreement is reproduced below for the relevant platform.
Please note that when using our embedded elements, data from you may also be processed outside the European Union, as many providers, such as Facebook Messenger or WhatsApp, are American companies. As a result, you may no longer be able to easily assert or enforce your rights with regard to your personal data.
What data is processed?
Exactly which data is stored and processed depends on the respective provider of the messenger & communication functions. Basically, this involves data such as name, address, phone number, email address and content data, such as all information you enter into a contact form. In most cases, information about your device and IP address is also stored. Data collected via a messenger & communication function is also stored on the providers' servers.
If you want to know exactly which data is stored and processed by the respective providers and how you can object to the data processing, you should carefully read the respective privacy policy of the company.
How long is data stored?
How long the data is processed and stored depends primarily on the tools we use. Below you can learn more about the data processing of the individual tools. The providers' privacy policies usually state exactly which data is stored and processed for how long. In principle, personal data is only processed for as long as is necessary for the provision of our services. When data is stored in cookies, the storage duration varies greatly. The data can be deleted immediately after leaving a website, or it can be stored for several years. You should therefore look at each individual cookie in detail if you want to know more about data storage. In most cases, you will also find detailed information about the individual cookies in the privacy policies of the individual providers.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating or deleting cookies in your browser. For further information, we refer to the section on consent.
Since cookies may be used in messenger & communication functions, we also recommend our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Legal Basis
If you have consented to data being processed and stored by embedded messenger & communication functions, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). We process your enquiry and manage your data within the framework of contractual or pre-contractual relationships in order to fulfil our pre-contractual and contractual obligations or to respond to enquiries. The basis for this is Art. 6(1) sentence 1 (b) GDPR. In principle, your data is also stored and processed, with your consent, on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners.
Telegram Privacy Policy
| Telegram Privacy Policy Summary 👥 Data subjects: Telegram users 🤝 Purpose: Communication 📓 Data processed: Contact details, messages, media 📅 Storage duration: After account deletion or deactivation ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Telegram?
We also use the instant messaging service Telegram. The service provider is the international company Telegram Messenger LLP, operated under a London address (71-75 Shelton Street, Covent Garden, London, United Kingdom) and developed in Russia.
Telegram was founded in 2013 by Nikolai and Pavel Durov. Since the Telegram team sees itself as so-called digital nomads, you never know exactly where the team works. The Telegram website also does not have a legal notice.
Similar to other messaging services such as WhatsApp, you can send messages, photos, videos and other files via Telegram and also make phone calls. This messaging service has been growing in popularity in recent years. In 2022, it already had over 700 million users.
When you use Telegram, personal data is also processed and stored on Telegram's servers. This includes chat messages as well as sent photos, videos and profile data, IP address and synchronised contacts. Telegram does encrypt data between the server and your device, but can only offer end-to-end encryption for secret chats. Data stored in the cloud can be viewed by the company and also by third-party providers.
Why do we use Telegram?
Many people now use Telegram as an alternative to other messaging services such as WhatsApp. We want to stay in contact with you and this works best via an instant messaging service that many of our customers also use. The service works flawlessly, is practical and enables uncomplicated communication with you.
What data does Telegram process?
Through the use of Telegram, various types of data, including personal data, may be processed. This includes account information such as your phone number, your profile picture, your username or other information that you provide to Telegram in the course of creating and managing your account. Of course, Telegram also stores the content of your messages (text, photos, videos, voice messages). Telegram also stores so-called metadata, such as the date and time at which a message was sent or received. Telegram may also access your contacts in order to enable communication with your contacts. Furthermore, technical data such as device type, operating system or location data is also stored.
How long and where is the data stored?
In principle, data is stored by Telegram for as long as is necessary for the legitimate purposes and for the fulfilment of legal obligations. Exactly how long the data is stored cannot be answered specifically at this point, as this depends heavily on the type of data. According to Telegram, the data is stored for up to 12 months. The data is stored on Telegram's own servers, which are distributed around the world. The exact locations of these servers are unfortunately not known.
How can I delete my data or prevent data storage?
You always have the right to access, rectify or delete and restrict the processing of your personal data. You can also revoke your consent to the processing of the data at any time. You can delete individual messages and also entire chat histories directly in Telegram. In the settings, you also have the option of deactivating or deleting your account. Initially, a copy of the data is deleted, and it may take some time until the data is also deleted from the Telegram servers.
Legal Basis
The use of Telegram requires your consent, which we have obtained with our consent tool (popup). This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when collected by Telegram.
In addition to consent, we have a legitimate interest in improving our communication offering. With the help of Telegram, we can respond to your enquiries more quickly and effectively, share important news with you and thus take our service to the next level. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Telegram insofar as you have given your consent.
You can learn more about the data processed through the use of Telegram in the Privacy Policy at https://telegram.org/privacy.
WhatsApp Privacy Policy
| WhatsApp Privacy Policy Summary 👥 Data subjects: WhatsApp users 🤝 Purpose: Communication 📓 Data processed: Contact details, messages, media 📅 Storage duration: After account deletion or deactivation ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is WhatsApp?
We use the instant messaging service WhatsApp on our website. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. (until October 2021 Facebook Inc.). For the European area, the company WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland is responsible.
We probably do not need to introduce WhatsApp to you in more detail. The likelihood that you yourself use this well-known messaging service on your smartphone is relatively high. For many years, there have been voices criticising WhatsApp or its parent company Meta Platforms regarding the handling of personal data. The main criticism in recent years was about the merging of WhatsApp user data with Facebook. Facebook reacted in 2021 and adjusted the terms of use. Facebook stated that currently (as of 2021) no personal data from WhatsApp users is shared with Facebook.
Nevertheless, a significant amount of your personal data is processed by WhatsApp, provided you use WhatsApp and have consented to data processing. This includes, in addition to your phone number and chat messages, also sent photos, videos and profile data. However, photos and videos are said to be only temporarily cached, and all messages and phone calls are provided with end-to-end encryption. They should therefore not be viewable even by Meta itself. In addition, information from your address book and other metadata is stored on WhatsApp.
Why do we use WhatsApp?
We want to stay in contact with you and this works best via WhatsApp. On the one hand, because the service works flawlessly, and on the other hand, because WhatsApp is still the most widely used instant messaging tool worldwide. The service is practical and enables uncomplicated and fast communication with you.
What data does WhatsApp process?
Through the use of WhatsApp, various types of data, including personal data, may be processed. This includes account information such as your phone number, your profile picture, your username or other information that you provide to WhatsApp in the course of creating and managing your WhatsApp account. Of course, WhatsApp also stores the content of your messages (text, photos, videos, voice messages). WhatsApp also stores so-called metadata, such as the date and time at which a message was sent or received. The phone numbers of the persons involved and technical data such as device type, operating system or location data are also stored.
How long and where is the data stored?
In principle, data is stored by WhatsApp for as long as is necessary for the legitimate purposes and for the fulfilment of legal obligations. Exactly how long the data is stored cannot be answered specifically at this point, as this depends heavily on the type of data. As a rule, messages are only stored by WhatsApp in encrypted form during delivery and are deleted from the servers as soon as a message has been delivered. Messages are only stored for longer on your own device. When media is sent, WhatsApp stores this data in encrypted form for up to 30 days in order to optimise delivery. Account data is stored for as long as you have an active WhatsApp account. If you delete or deactivate the account, your account data is normally also deleted. The data that is stored by WhatsApp is stored by the company on its own servers, which are distributed around the world. In order to operate the web-based WhatsApp services, data is also collected with the help of cookies.
How can I delete my data or prevent data storage?
You always have the right to access, rectify or delete and restrict the processing of your personal data. You can also revoke your consent to the processing of the data at any time.
If you do not want cookies to be set in the desktop version and data to be stored as a result, you can also prevent cookies from being set in your browser. In your browser, you can manage, deactivate or delete cookies. Depending on your browser, this always works slightly differently. You can find out more in our section on cookies.
Legal Basis
The use of WhatsApp requires your consent, which we have obtained with our consent tool (popup). This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when collected by WhatsApp.
In addition to consent, we have a legitimate interest in improving our communication offering. With the help of WhatsApp, we can respond to your enquiries more quickly and effectively, share important news with you and thus take our service to the next level. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use WhatsApp insofar as you have given your consent.
WhatsApp also processes your data in the USA, among other places. WhatsApp is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, WhatsApp uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, WhatsApp undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
Information about data transfers at WhatsApp, which correspond to the Standard Contractual Clauses, can be found at https://www.whatsapp.com/legal/business-data-transfer-addendum-20210927
We hope we have provided you with the most important information about the use and data processing by WhatsApp. You can learn more about the data processed through the use of WhatsApp in the Privacy Policy at https://www.whatsapp.com/privacy.
Cloud Services
| Cloud Services Privacy Policy Summary 👥 Data subjects: Us as website operators and you as website visitors 🤝 Purpose: Security and data storage 📓 Data processed: Data such as your IP address, name or technical data such as browser version More details can be found below and in the individual data protection texts or privacy policies of the providers 📅 Storage duration: Most data is stored as long as it is needed to fulfil the service ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are cloud services?
Cloud services provide us as website operators with storage space and computing power via the internet. Data can be transferred to an external system, processed and stored via the internet. The management of this data is handled by the respective cloud provider. Depending on the requirements, an individual person or a company can choose the storage space size or computing power. Cloud storage is accessed via an API or via storage protocols. API stands for Application Programming Interface and refers to a programming interface that connects software with hardware components.
Why do we use cloud services?
We use cloud services for several reasons. A cloud service offers us the ability to store our data securely. We also have access to the data from various locations and devices, giving us more flexibility and facilitating our work processes. Cloud storage also saves us costs because we do not have to set up and manage our own infrastructure for data storage and data security. By centrally storing our data in the cloud, we can also expand our application areas and manage our information significantly better.
As website operators or as a company, we primarily use cloud services for our own purposes. For example, we use the services to manage our calendar, to store documents or other important information in the cloud. However, personal data from you may also be stored. This is the case, for example, when you provide us with your contact details (such as name and email address) and we store our customer data with a cloud provider. Consequently, data that we process from you may also be stored and processed on external servers. When we offer certain forms or content from cloud services on our website, cookies for web analytics and advertising purposes may also be set. Furthermore, such cookies remember your settings (such as the language used) so that you find your familiar web environment on your next visit to our website.
What data is processed by cloud services?
Many of the data we store in the cloud have no personal reference; however, some data counts as personal data according to the GDPR definition. This often involves customer data such as name, address, IP address or phone number, or technical device information. Videos, images and audio files can also be stored in the cloud. How exactly the data is collected and stored depends on the respective service. We try to use only services that handle data very reliably and professionally. In principle, the services, such as Amazon Drive, have access to the stored files in order to offer their own service accordingly. However, the services need permissions for this, such as the right to copy files for security reasons. This data is processed and managed as part of the services and in compliance with applicable laws. GDPR compliance is also ensured for US-based providers, via the Standard Contractual Clauses. In some cases, these cloud services also work with third-party providers who can process data under instruction and in accordance with data protection guidelines and further security measures. We would like to emphasise once again that all well-known cloud services (such as Amazon Drive, Google Drive or Microsoft OneDrive) obtain the right to have access to stored content in order to be able to offer and optimise their own service accordingly.
Duration of Data Processing
We will inform you about the duration of data processing below, if we have further information on this. In general, cloud services store data until you withdraw your consent or we end the data storage or delete the data again. In general, personal data is only stored for as long as is absolutely necessary for the provision of the services. However, permanent data deletion from the cloud can take several months. This is because the data is usually not stored on just one server but distributed across different servers.
Right to Object
You also have the right and the option at any time to withdraw your consent to data storage in a cloud. If cookies are used, you also have a right of withdrawal here. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating or deleting cookies in your browser. We also recommend our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective cloud providers.
Legal Basis
We use cloud services primarily on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in a good security and storage system.
Certain processing activities, in particular the use of cookies and the use of storage functions, require your consent. If you have consented to data being processed and stored by cloud services, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the services we use set cookies in your browser to store data. We therefore recommend that you read our privacy text about cookies carefully and view the privacy policy or cookie policy of the respective service provider.
Information on specific tools can be found – if available – in the following sections.
Credit Rating Agencies Introduction
| Credit Rating Agencies Privacy Policy Summary 👥 Data subjects: Customers 🤝 Purpose: Creditworthiness and credit assessment 📓 Data processed: Master data, payment data, contact data, contract data 📅 Storage duration: Depending on the agencies used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are credit rating agencies?
For our online business, we use credit rating agencies in some cases so that we can obtain information about your creditworthiness if we provide advance services. The agencies calculate a statistical probability of a payment default. This means we receive information about how likely it is that you can pay your invoice, for example. Based on this information, we can better decide whether to provide certain advance services or not. We can therefore also refuse advance services (such as payment on account) in the event of a negative credit check result.
Why do we use credit rating agencies?
In our business, it regularly happens that we provide a service before the contractually agreed consideration or take on similar economic risks. This is always the case with orders on account, for example. To safeguard our legitimate interests, we can obtain so-called identity and credit information. The credit risk is assessed using a mathematical-statistical procedure by credit rating agencies (credit agencies).
What data is processed?
The decision to provide advance services or not is made by software that works with the information from the credit rating agency, on the basis of an automated decision in individual cases (= Art. 22 GDPR). The data typically processed includes name, address, bank details, invoices, payment history, contact data such as email address and phone number, as well as contract data such as term, customer information and the subject matter of the contract. More detailed information about data processing can be found in the privacy policies of the respective credit rating agencies.
Duration of Data Processing
How long the data is processed and stored depends primarily on the credit rating agencies we use. Below you can learn more about the data processing of the individual providers. The providers' privacy policies usually state exactly which data is stored and processed for how long. In principle, personal data is only processed for as long as is necessary for the provision of our services. When data is stored in cookies, the storage duration varies greatly. In most cases, you will also find detailed information about the individual cookies in the privacy policies of the individual providers.
Legal Basis
If we obtain consent from our contractual partners, this is also the legal basis (Article 6(1)(a) GDPR) for the credit information and also for the transmission of customer data to an agency. If this consent does not exist, the legal basis is our legitimate interest (Article 6(1)(f) GDPR) in protection against payment defaults. If we obtain your consent, this is also the legal basis for credit information and data transmission.
We have no influence on the specific review process or profiling of the credit rating agencies we use and therefore on the accuracy or appropriateness of the result. In this respect, we are not responsible under data protection law. The responsibility lies solely with the credit rating agency, to whose data protection notices we refer below. Our responsibility only exists for obtaining and using a credit report created by a third party in individual cases.
SCHUFA Privacy Policy
We use SCHUFA, a credit reporting agency, for our business. The service provider is the German company SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany.
You can learn more about the data processed through the use of SCHUFA in the privacy policy at https://www.schufa.de/global/datenschutz-dsgvo/.
Audio & Video Introduction
| Audio & Video Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as contact data, user behaviour data, information about your device and your IP address may be stored. More details can be found below in the corresponding privacy texts. 📅 Storage duration: Data is generally stored as long as it is needed for the service purpose ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are audio and video elements?
We have embedded audio and video elements on our website so that you can watch videos or listen to music/podcasts directly via our website. The content is provided by service providers. All content is therefore also sourced from the corresponding servers of the providers.
These are embedded functional elements from platforms such as YouTube, Vimeo or Spotify. The use of these portals is usually free of charge, but paid content can also be published. With the help of these embedded elements, you can listen to or watch the respective content via our website.
When you use audio or video elements on our website, personal data from you may also be transmitted to, processed and stored by the service providers.
Why do we use audio & video elements on our website?
Of course, we want to offer you the best experience on our website. And we are aware that content is no longer conveyed merely through text and static images. Instead of simply giving you a link to a video, we offer you audio and video formats directly on our website that are entertaining or informative and ideally both. This enhances our service and makes it easier for you to access interesting content. Thus, in addition to our texts and images, we also offer video and/or audio content.
What data is stored by audio & video elements?
When you access a page on our website that has, for example, an embedded video, your server connects to the service provider's server. In doing so, data from you is also transferred to the third-party provider and stored there. Some data is collected and stored completely independently of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system and other general information about your device. Furthermore, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which button you clicked or which website you used to access the service. All this information is usually stored via cookies or pixel tags (also called web beacons). Pseudonymised data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
Duration of Data Processing
You can find out how long the data is stored exactly on the third-party provider's servers either below in the data protection text of the respective tool or in the provider's privacy policy. In principle, personal data is always only processed for as long as is absolutely necessary for the provision of our services or products. This generally also applies to third-party providers. Usually, you can assume that certain data is stored on the servers of third-party providers for several years. Data can be stored in cookies for different lengths of time. Some cookies are already deleted after leaving the website, while others can be stored in your browser for several years.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating or deleting cookies in your browser. The lawfulness of processing based on consent before its withdrawal remains unaffected.
Since the embedded audio and video functions on our site usually also use cookies, you should also read our general privacy policy on cookies. In the privacy policies of the respective third-party providers, you will learn more about how your data is handled and stored.
Legal Basis
If you have consented to data being processed and stored by embedded audio and video elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners. However, we only use the embedded audio and video elements insofar as you have given your consent.
YouTube Privacy Policy
| YouTube Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as contact data, user behaviour data, information about your device and your IP address may be stored. More details can be found below in this privacy policy. 📅 Storage duration: Data is generally stored as long as it is needed for the service purpose ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is YouTube?
We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video portal that has been a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you access a page on our website that has an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. Various data is transferred (depending on the settings). Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all data processing in the European area.
In the following, we want to explain to you in more detail which data is processed, why we have embedded YouTube videos and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on and upload videos for free. Over the last few years, YouTube has become one of the most important social media channels worldwide. So that we can display videos on our website, YouTube provides a code snippet that we have embedded on our site.
Why do we use YouTube videos on our website?
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our website. And of course, interesting videos should not be missing. With the help of our embedded videos, we provide you with further helpful content in addition to our texts and images. In addition, our website is easier to find on the Google search engine thanks to the embedded videos. Even if we place advertisements via Google Ads, Google can – thanks to the collected data – really only show these ads to people who are interested in our offerings.
What data is stored by YouTube?
As soon as you visit one of our pages that has a YouTube video embedded, YouTube sets at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually associate your interactions on our website with your profile using cookies. This includes data such as session duration, bounce rate, approximate location, technical information such as browser type, screen resolution or your internet provider. Further data may include contact details, any reviews, sharing content via social media or adding to your favourites on YouTube.
If you are not logged into a Google Account or YouTube account, Google stores data with a unique identifier linked to your device, browser or app. For example, your preferred language setting is retained. But much interaction data cannot be stored because fewer cookies are set.
The list below shows cookies that were set in a test in the browser. On the one hand, we show cookies that are set without a logged-in YouTube account; on the other, cookies that are set with a logged-in account. The list is not exhaustive, as user data always depends on your interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y112749124-1
Purpose: This cookie registers a unique ID to store statistics on the video watched.
Expiry date: after end of session
Name: PREF
Value: f1=50000000
Purpose: This cookie also registers your unique ID. Through PREF, Google receives statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie registers your unique ID on mobile devices in order to track GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our pages (which embed a YouTube video).
Expiry date: after 8 months
Further cookies that are set when you are logged in to your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7112749124-
Purpose: This cookie is used to build a profile of your interests. The data is used for personalised advertising.
Expiry date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user’s consent to the use of various Google services. CONSENT also serves security purposes, verifying users and protecting user data from unauthorised access.
Expiry date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to build a profile of your interests. This data helps in displaying personalised advertising.
Expiry date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login credentials.
Expiry date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to build a profile of your interests.
Expiry date: after 2 years
Name: SID
Value: oQfNKjAsI112749124-
Purpose: This cookie stores your Google Account ID and the timestamp of your last sign-in in digitally signed and encrypted form.
Expiry date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and which advertising you may have seen before visiting our site.
Expiry date: after 3 months
How long and where is the data stored?
The data that YouTube receives and processes from you is stored on the Google servers. Most of these servers are located in America. At https://datacenters.google/ you can see exactly where the Google data centres are located. Your data is distributed across the servers. This means the data is more quickly retrievable and better protected against manipulation.
Google stores the collected data for different lengths of time. Some data you can delete at any time, others are automatically deleted after a limited time and still others are stored by Google for a longer period. Some data (such as elements from "My Activity", photos or documents, products) stored in your Google Account remain stored until you delete them. Even if you are not logged into a Google Account, you can delete some data linked to your device, browser or app.
How can I delete my data or prevent data storage?
In principle, you can manually delete data in your Google Account. With the automatic deletion function for location and activity data introduced in 2019, information is stored and then deleted for either 3 or 18 months, depending on your decision.
Regardless of whether you have a Google Account or not, you can configure your browser so that Google cookies are deleted or deactivated. Depending on which browser you use, this works in different ways. Under the "Cookies" section, you will find the corresponding links to the instructions for the most common browsers.
If you generally do not want cookies, you can set up your browser to always inform you when a cookie is to be set. This way, you can decide for each individual cookie whether you allow it or not.
Legal Basis
If you have consented to data being processed and stored by embedded YouTube elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners. However, we only use the embedded YouTube elements insofar as you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you read our privacy text about cookies carefully and view the privacy policy or cookie policy of the respective service provider.
YouTube also processes your data in the USA, among other places. YouTube or Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
Since YouTube is a subsidiary of Google, there is a shared privacy policy. If you want to learn more about how your data is handled, we recommend the privacy policy at https://policies.google.com/privacy?hl=de.
YouTube Subscribe Button Privacy Policy
We have integrated the YouTube Subscribe Button on our website. You can usually recognise the button by the classic YouTube logo. The logo displays the words “Subscribe” or “YouTube” in white text on a red background, with the white “Play symbol” to the left of it. However, the button can also be presented in a different design.
Our YouTube channel regularly offers you funny, interesting or exciting videos. With the built-in “Subscribe button”, you can subscribe to our channel directly from our website without having to visit the YouTube website separately. We therefore want to make access to our comprehensive content as easy as possible for you. Please note that YouTube can thereby store and process data about you.
If you see an integrated subscribe button on our page, YouTube sets – according to Google – at least one cookie. This cookie stores your IP address and our URL. YouTube can also learn information about your browser, your approximate location and your default language. In our test, the following four cookies were set without being logged into YouTube:
Name: YSC
Value: b9-CV6ojI5112749124Y
Purpose: This cookie registers a unique ID to store statistics of the video watched.
Expiry date: after end of session
Name: PREF
Value: f1=50000000
Purpose: This cookie also registers your unique ID. Google receives statistics via PREF on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie registers your unique ID on mobile devices in order to track GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 11274912495Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube video).
Expiry date: after 8 months
Note: These cookies were set after a test and cannot claim to be complete.
If you are logged into your YouTube account, YouTube can store many of your actions/interactions on our website with the help of cookies and assign them to your YouTube account. YouTube thereby receives, for example, information about how long you surf on our page, what type of browser you use, what screen resolution you prefer or what actions you carry out.
YouTube uses this data on the one hand to improve its own services and offers, and on the other hand to provide analyses and statistics for advertisers (who use Google Ads).
Video Conferencing & Streaming Introduction
| Video Conferencing & Streaming Privacy Policy Summary 👥Data subjects: Users who use our video conferencing or streaming tool 🤝 Purpose: Communication and presentation of content 📓Data processed: Access statistics containing data such as name, address, contact details, email address, phone number or your IP address. More details can be found in the respective video conferencing or streaming tool used. 📅Storage duration: Depending on the video conferencing or streaming tool used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract) |
What are video conferences & streaming?
We use software programs that enable us to hold video conferences, online meetings, webinars, display sharing and/or streaming. In a video conference or streaming, information is transmitted simultaneously via audio and moving images. With the help of such video conferencing or streaming tools, we can communicate quickly and easily with customers, business partners, clients and employees via the internet. Of course, when selecting the service provider, we pay attention to the prescribed legal framework.
In principle, third-party providers can process data as soon as you interact with the software program. Third-party providers of the video conferencing or streaming solutions use your data and metadata for various purposes. The data helps, for example, to make the tool more secure and to improve the service. In most cases, the data may also be used for the third-party provider's own marketing purposes.
Why do we use video conferencing & streaming on our website?
We want to communicate with you, our customers and business partners, quickly, straightforwardly and securely, even digitally. This works best with video conferencing solutions that are very easy to use. Most tools also work directly via your browser and after just a few clicks you are in the middle of a video meeting. The tools also offer helpful additional features such as a chat and screen sharing function or the ability to share content between meeting participants.
What data is processed?
When you participate in our video conference or streaming, data from you is also processed and stored on the servers of the respective service provider.
Exactly which data is stored depends on the solution used. Each provider stores and processes different amounts of data. However, as a rule, most providers store your name, address, contact details such as your email address or phone number and your IP address. Furthermore, information about your device used, usage data such as which web pages you visit, when you visit a web page or which buttons you click may also be stored. Data shared within the video conference (photos, videos, texts) may also be stored.
Duration of Data Processing
We will inform you about the duration of data processing below in connection with the service used, if we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. The provider may store data from you according to its own standards, over which we then have no influence.
Right to Object
You always have the right to access, rectify and delete your personal data. If you have any questions, you can also contact the controller of the video conferencing or streaming tool used at any time. You can find contact details either in our specific privacy policy or on the website of the respective provider.
You can delete, deactivate or manage cookies that providers use for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
Legal Basis
If you have consented to data being processed and stored by the video or streaming solution, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). We can also offer a video conference as part of our services if this has been contractually agreed with you in advance (Art. 6(1)(b) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or other customers and business partners, however only insofar as you have at least consented. Most video or streaming solutions also set cookies in your browser to store data. We therefore recommend that you read our privacy text about cookies carefully and view the privacy policy or cookie policy of the respective service provider.
Information on specific video conferencing and streaming solutions can be found – if available – in the following sections.
Microsoft Teams Privacy Policy
We use Microsoft Teams on our website, a service for online meetings and video conferences. The service provider is the American company Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft also processes your data in the USA, among other places. Microsoft is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Microsoft uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Microsoft undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
More information about the Standard Contractual Clauses at Microsoft can be found at https://learn.microsoft.com/en-us/compliance/regulatory/offering-eu-model-clauses
You can learn more about the data processed through the use of Microsoft in the privacy policy at https://privacy.microsoft.com/de-de/privacystatement.
Review Platforms Introduction
| Review Platforms Summary 👥 Data subjects: Visitors to the website or a review platform 🤝 Purpose: Feedback on our products and/or services 📓 Data processed: Including IP address, email address, name. More details can be found below and with the respective review platforms used. 📅 Storage duration: Depending on the respective platform ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), |
What are review platforms?
On various review platforms you can rate our products or services. We are a participant in some of these platforms so that we can receive feedback from you and thus optimise our offering. If you rate us via a review platform, the privacy policy and general terms and conditions of the respective review service apply. Very often, you also have to register to submit a review. Review technologies (widgets) can also be integrated into our website. By using such an integrated tool, data is also transferred, processed and stored with the corresponding provider.
Many of these integrated programs work on a similar principle. After you have ordered a product from us or used a service, you are asked, by email or on the website, to submit a review. You are usually redirected via a link to a review page where you can create a review quickly and easily. Some review systems also offer an interface to various social media channels in order to make the feedback accessible to more people.
Why do we use review platforms?
Review platforms collect feedback and reviews about our offers. Through your reviews, we quickly receive corresponding feedback and can improve our products and/or services much more efficiently. The reviews therefore serve us on the one hand to optimise our offers and on the other hand they give you and all our future customers a good overview of the quality of our products and services.
Which data are processed?
With the help of your consent, we transmit information about you and the services you have used to the corresponding review platform. We do this to ensure that you have actually used one of our services. Only then can you give real feedback. The transmitted data is used solely for user identification. Which data is stored and processed exactly depends, of course, on the providers used. In most cases, personal data such as IP address, email address or your name are also made available to the review platforms. Even after you submit your review, order information such as the order number of a purchased item is forwarded to the respective platform. If your email address is transmitted, this is so that the review platform can send you an email after you have purchased a product. So that we can integrate your review into our website, we also give the providers the information that you have visited our page. Responsible for the personal data collected is the review platform used.
How long and where are the data stored?
You can find more details about the duration of data processing below in the corresponding privacy policy of the provider, provided we have further information about this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. Personal data that are mentioned in a review are generally anonymised by employees of the platform used and are therefore only visible to administrators of the company. The data collected are stored on the servers of the providers and deleted after the order has ended with most providers.
Right to object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third parties. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, deactivating or deleting cookies in your browser.
Legal Basis
If you have consented to a review platform being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by a review portal.
On our part, there is also a legitimate interest in using a review platform to optimise our online service. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use a review platform insofar as you have given your consent.
We hope we have been able to provide you with the most important general information about the data processing of review platforms. You can find more detailed information below in the privacy texts or in the linked privacy policies of the respective company.
Google Customer Reviews Privacy Policy
On our website, we also use the review platform Google Customer Reviews. The service provider is the American company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.
Google also processes data about you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Controller-Controller Data Protection Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/
You can learn more about the data processed through the use of Google in the privacy policy at https://policies.google.com/privacy?hl=de.
Web Design Introduction
| Web Design Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Improving user experience 📓Data processed: Which data is processed depends heavily on the services used. Usually this involves IP address, technical data, language settings, browser version, screen resolution and browser name. More details can be found in the respective web design tools used. 📅 Storage duration: Depending on the tools used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is web design?
We use various tools on our website that serve our web design. Web design is not just about making our website look pretty, as is often assumed, but also about functionality and performance. But of course, the appropriate look of a website is also one of the major goals of professional web design. Web design is a sub-area of media design and deals with both the visual and structural and functional design of a website. The goal is to improve your experience on our website with the help of web design. In web design jargon, this is referred to as user experience (UX) and usability. User experience means all the impressions and experiences the website visitor has on a website. A sub-item of user experience is usability. This is about the user-friendliness of a website. The focus here is primarily on making content, sub-pages or products clearly structured so that you can easily and quickly find what you are looking for. To offer you the best possible experience on our website, we also use so-called web design tools from third-party providers. In this privacy policy, the category "web design" therefore includes all services that improve our website in terms of design. This can be, for example, fonts, various plugins or other embedded web design functions.
Why do we use web design tools?
How you take in information on a website depends very much on the structure, the functionality and the visual perception of the website. Therefore, good and professional web design has also become increasingly important for us. We are constantly working on improving our website and also see this as an extended service for you as a website visitor. Furthermore, a beautiful and functioning website also has economic advantages for us. After all, you will only visit us and make use of our offers if you feel completely comfortable.
Which data are stored by web design tools?
When you visit our website, web design elements can be integrated into our pages that can also process data. What data exactly is involved depends, of course, heavily on the tools used. Below you can see exactly which tools we use for our website. For more information on data processing, we also recommend reading the respective privacy policy of the tools used. There you will usually find out which data are processed, whether cookies are used and how long the data are retained. Through fonts such as Google Fonts, for example, information such as language settings, IP address, browser version, browser screen resolution and browser name is automatically transferred to the Google servers.
Duration of data processing
How long data are processed is very individual and depends on the web design elements used. If cookies are used, for example, the retention period can be only a minute, but it can also last a few years. Please inform yourself about this. We recommend, on the one hand, our general text section on cookies as well as the privacy policies of the tools used. There you will usually find out which cookies exactly are used, and what information is stored in them. Google font files, for example, are stored for one year. This is intended to improve the loading time of a website. In principle, data are only stored for as long as is necessary for the provision of the service. In the case of legal requirements, data can also be stored for longer.
Right to object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third parties. This works either via our cookie management tool or via other opt-out functions. You can also prevent data collection via cookies by managing, deactivating or deleting cookies in your browser. However, with web design elements (usually with fonts), there are also data that cannot be so easily deleted. This is the case when data is automatically collected directly when a page is called up and transmitted to a third-party provider (such as Google). In that case, please contact the support of the corresponding provider. In the case of Google, you can reach support at https://support.google.com/?hl=de.
Legal Basis
If you have consented to web design tools being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by web design tools. On our part, there is also a legitimate interest in improving web design on our website. After all, we can only offer you a nice and professional web offering this way. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use web design tools insofar as you have given your consent. We definitely want to emphasise this once more here.
Information on specific web design tools can be found – if available – in the following sections.
Google Fonts Privacy Policy
| Google Fonts Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as IP address and CSS and font requests More details can be found further below in this privacy policy. 📅 Storage duration: Font files are stored at Google for one year ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are Google Fonts?
On our website we use Google Fonts. These are the “Google fonts”from Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.
To use Google fonts, you do not need to log in or provide a password. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, the requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you don’t have to worry about your Google account data being transferred to Google while using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will look at exactly how data storage works in more detail.
Google Fonts (formerly Google Web Fonts) is a directory of over 800 fonts that Google provides to its users free of charge.
Many of these fonts are published under the SIL Open Font License, while others are published under the Apache License. Both are free software licences.
Why do we use Google Fonts on our website?
With Google Fonts we can use fonts on our own website without having to upload them to our own server. Google Fonts is an important component for keeping the quality of our website high. All Google fonts are automatically optimised for the web and this saves data volume, which is a big advantage especially for use on mobile devices. When you visit our site, the low file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors. Such errors can sometimes visually distort texts or entire websites. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform problems with Google Fonts. Google Fonts supports all common browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). So we use Google Fonts so that we can present our entire online service as nicely and uniformly as possible.
Which data are stored by Google?
When you visit our website, the fonts are reloaded via a Google server. Through this external call, data is transmitted to the Google servers. This way, Google also recognises that you or your IP address have visited our website. The Google Fonts API has been developed to reduce the use, storage and collection of end-user data to what is necessary for the proper provision of fonts. API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.
Google Fonts stores CSS and font requests securely at Google and is therefore protected. Through the collected usage numbers, Google can determine how well the individual fonts are received. Google publishes the results on internal analysis pages, such as Google Analytics. In addition, Google also uses data from its own web crawler to determine which websites use Google fonts. This data is published in the BigQuery database of Google Fonts. Entrepreneurs and developers use the Google web service BigQuery to examine and move large amounts of data.
However, it should be noted that with each Google Font request, information such as language settings, IP address, browser version, browser screen resolution and browser name is automatically transmitted to the Google servers. Whether this data is also stored cannot be clearly determined or is not clearly communicated by Google.
How long and where are the data stored?
Google stores requests for CSS assets for one day on its servers, which are mainly located outside the EU. This enables us to use the fonts with the help of a Google style sheet. A style sheet is a format template that can be used to quickly and easily change, for example, the design or font of a website.
The font files are stored at Google for one year. Google’s aim is to fundamentally improve the loading time of websites. If millions of websites refer to the same fonts, they are cached after the first visit and reappear immediately on all other websites visited later. Sometimes Google updates font files to reduce file size, increase language coverage and improve design.
How can I delete my data or prevent data storage?
Those data that Google stores for one day or one year cannot simply be deleted. The data is automatically transmitted to Google when the page is accessed. In order to delete this data prematurely, you must contact Google support at https://support.google.com/?hl=de&tid=112749124 . In this case, you only prevent data storage by not visiting our site.
Unlike other web fonts, Google gives us unrestricted access to all fonts. So we can access an unlimited sea of fonts and get the most out of our website. You can find more about Google Fonts and further questions at https://developers.google.com/fonts/faq?tid=112749124. Although Google addresses data protection-relevant matters there, really detailed information about data storage is not included. It is relatively difficult to get really precise information from Google about stored data.
Legal Basis
If you have consented to Google Fonts being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by Google Fonts.
On our part, there is also a legitimate interest in using Google Fonts to optimise our online service. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Google Fonts insofar as you have given your consent.
Google also processes data about you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
You can also read about which data is generally collected by Google and what this data is used for at https://www.google.com/intl/de/policies/privacy/ .
Google Fonts Local Privacy Policy
On our website, we use Google Fonts from Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible. We have embedded the Google fonts locally, i.e. on our web server – not on Google's servers. As a result, there is no connection to Google servers and therefore no data transfer or storage.
What are Google Fonts?
Google Fonts used to be called Google Web Fonts. It is an interactive directory of over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, to prevent any information transfer to Google servers, we have downloaded the fonts to our server. In this way, we act in compliance with data protection and do not send any data to Google Fonts.
Online Map Services Introduction
| Online Map Services Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Improving user experience 📓 Data processed: Which data is processed depends heavily on the services used. Usually this involves IP address, location data, search items and/or technical data. More details can be found in the respective tools used. 📅 Storage duration: Depending on the tools used ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are online map services?
We use online map services for our website as an extended service. Google Maps is probably the service most familiar to you, but there are also other providers that specialise in creating digital maps. Such services make it possible to display locations, route plans or other geographic information directly via our website. Through an integrated map service, you no longer have to leave our website to view, for example, the route to a location. So that the online map works on our website, map sections are embedded using HTML code. The services can then display street maps, the earth's surface or aerial or satellite images. If you use the built-in map offering, data is also transferred to the tool used and stored there. This data may also include personal data.
Why do we use online map services on our website?
Generally speaking, it is our concern to offer you a pleasant time on our website. And of course your time is only pleasant if you can easily find your way around our website and find all the information you need quickly and easily. Therefore, we thought that an online map system could be a significant optimisation of our service on the website. Without leaving our website, you can use the map system to easily view route descriptions, locations or even points of interest. It is of course also super-practical that you can see at a glance where our company is located so that you can find your way to us quickly and safely. You see, there are simply many advantages and we clearly regard online map services on our website as part of our customer service.
Which data are stored by online map services?
When you open a page on our website that has an online map function built in, personal data can be transmitted to the respective service and stored there. Usually this is your IP address, which can also be used to determine your approximate location. In addition to the IP address, data such as entered search terms as well as longitude and latitude coordinates are also stored. If, for example, you enter an address for route planning, this data is also stored. The data is not stored with us, but on the servers of the integrated tools. You can imagine it roughly like this: You are on our website, but when you interact with a map service, this interaction actually takes place on their website. In order for the service to work properly, at least one cookie is usually set in your browser. Google Maps, for example, also uses cookies to record user behaviour and thus optimise its own service and display personalised advertising. You can find more information about cookies in our “Cookies” section.
How long and where are the data stored?
Each online map service processes different user data. Provided we have further information, we will inform you about the duration of data processing below in the corresponding sections on the individual tools. In general, personal data are only retained for as long as is necessary for the provision of the service. Google Maps, for example, stores certain data for a defined period, other data you have to delete yourself. With Mapbox, for example, the IP address is kept for 30 days and then deleted. As you can see, each tool stores data for different lengths of time. Therefore, we recommend that you take a close look at the privacy policies of the tools used.
The providers also use cookies to store data on your user behaviour with the map service. You can find more general information about cookies in our “Cookies” section, but the privacy texts of the individual providers also tell you which cookies may be used. However, this is usually only an exemplary list and is not exhaustive.
Right to object
You always have the option and the right to access your personal data and also to object to their use and processing. You can also withdraw your consent, which you have given us, at any time. As a rule, this works most easily via the cookie consent tool. There are also other opt-out tools that you can use. Possible cookies that are set by the providers used can also be managed, deleted or deactivated by yourself with a few mouse clicks. However, some functions of the service may then no longer work as usual. How you manage the cookies in your browser also depends on the browser you use. In the “Cookies” section you will also find links to the instructions of the most important browsers.
Legal Basis
If you have consented to an online map service being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by an online map service.
We also have a legitimate interest in using an online map service to optimise our service on our website. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use an online map service if you have given your consent. We definitely want to state this once more here.
Information on specific online map services can be found – if available – in the following sections.
Google Maps Privacy Policy
| Google Maps Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as entered search terms, your IP address and also the latitude or longitude coordinates. More details can be found further below in this privacy policy. 📅 Storage duration: Depending on the data stored ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Google Maps?
We use Google Maps from Google Inc. on our website. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Maps, we can show you locations better and thus adapt our service to your needs. By using Google Maps, data is transferred to Google and stored on Google servers. Here we want to go into more detail about what Google Maps is, why we use this Google service, what data is stored and how you can prevent this.
Google Maps is an internet map service from Google. With Google Maps you can search online via a PC, tablet or app for exact locations of cities, sights, accommodations or businesses. If companies are represented on Google My Business, further information about the company is displayed in addition to the location. To show directions, map sections of a location can be embedded in a website using HTML code. Google Maps displays the earth’s surface as a street map or as an aerial or satellite image. Thanks to the Street View images and the high-quality satellite images, very precise representations are possible.
Why do we use Google Maps on our website?
All our efforts on this site are aimed at providing you with a useful and meaningful time on our website. By integrating Google Maps, we can provide you with the most important information about various locations. You can see at a glance where our company is located. The directions always show you the best or fastest way to us. You can retrieve directions for routes by car, public transport, on foot or by bike. For us, providing Google Maps is part of our customer service.
Which data are stored by Google Maps?
In order for Google Maps to offer its service fully, the company has to record and store data about you. This includes, among other things, the entered search terms, your IP address and also the latitude and longitude coordinates. If you use the route planner function, the entered starting address is also stored. However, this data storage takes place on the Google Maps websites. We can only inform you about this, but cannot influence it. Since we have integrated Google Maps into our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behaviour. Google uses this data primarily to optimise its own services and to provide you with individual, personalised advertising.
The following cookie is set in your browser due to the integration of Google Maps:
Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ112749124-5
Purpose: NID is used by Google to adapt advertisements to your Google search. With the help of the cookie, Google “remembers” your most frequently entered search queries or your previous interaction with advertisements. So you always get tailor-made advertisements. The cookie contains a unique ID that Google uses to collect your personal settings for advertising purposes.
Expiry date: after 6 months
Note: We cannot guarantee completeness in the information on the stored data. Especially when using cookies, changes can never be ruled out. In order to identify the cookie NID, a separate test page was created where only Google Maps was integrated.
How long and where are the data stored?
Google’s servers are located in data centres around the world. However, most of the servers are located in America. For this reason, your data is also increasingly stored in the USA. Here you can read exactly where Google’s data centres are located: https://datacenters.google/
Google distributes the data across various storage media. This makes the data quicker to retrieve and better protected against any attempts at manipulation. Every data centre also has special emergency programmes. If, for example, there are problems with Google hardware or a natural disaster paralyses the servers, the data remains fairly safely protected.
Google stores some data for a defined period of time. For other data, Google only offers the option of deleting it manually. Furthermore, the company also anonymises information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months.
How can I delete my data or prevent data storage?
With the automatic delete function for location and activity data introduced in 2019, information on location determination and web/app activity is – depending on your decision – stored for either 3 or 18 months and then deleted. In addition, you can manually delete this data from your history at any time via your Google account. If you want to completely prevent location tracking, you have to pause the “Web & App Activity” section in your Google account. Click on “Data & Personalisation” and then on the “Activity Setting” option. Here you can switch activities on or off.
In your browser you can also deactivate, delete or manage individual cookies. Depending on which browser you use, this always works a little differently. Under the “Cookies” section you will find the corresponding links to the respective instructions of the best-known browsers.
If you do not want cookies at all, you can set up your browser so that it always informs you when a cookie is to be set. In this way, you can decide for each individual cookie whether you allow it or not.
Legal Basis
If you have consented to Google Maps being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by Google Maps.
On our part, there is also a legitimate interest in using Google Maps to optimise our online service. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Google Maps insofar as you have given your consent.
Google also processes data about you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
If you want to learn more about Google’s data processing, we recommend the company’s own privacy policy at https://policies.google.com/privacy?hl=de.
Mapbox API Privacy Policy
| Mapbox API Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as IP address, browser information, your operating system, content of the request, restricted location and usage data More details can be found further below in this privacy policy. 📅 Storage duration: the IP address is deleted after 30 days, ID data after 36 months ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is Mapbox API?
On our website we use the Mapbox API from the American software company Mapbox Inc., 740 15th Street NW, 5th Floor, District of Columbia 20005, USA. Mapbox is an online map tool (open-source mapping) that is accessed via an interface (API). By using this tool, your IP address, among other things, is forwarded to Mapbox and stored. In this privacy policy you will learn more about the functions of the tool, why we use it and above all what data is stored and how you can prevent this.
Mapbox is an American software company that offers custom online maps for websites. With Mapbox, content can be illustrated on our website or, for example, directions can be displayed graphically. The maps can be easily integrated into our website with small code snippets (JavaScript code). Mapbox offers, among other things, a mobile-friendly environment, route information is provided in real time and data is presented visually.
Why do we use Mapbox API on our website?
We also want to offer you a comprehensive service on our website and this should not simply end with our services or products. No, all our content should also be of use to you. And this includes, for example, directions maps that show you the way to our company.
Which data are stored by Mapbox API?
When you visit one of our sub-pages that has an online map from Mapbox integrated, data about your user behaviour can be collected and stored. This is necessary so that the integrated online maps work properly. It may also be that data collected by Mapbox is passed on to third parties, but not personal data. This happens either when it is necessary for legal reasons or when Mapbox explicitly commissions another company. The map contents are transmitted directly to your browser and embedded in our website.
Mapbox automatically collects certain technical information when requests are made to the APIs. This includes, in addition to your IP address, browser information, your operating system, content of the request, restricted location and usage data, the URL of the visited website and the date and time of the website visit. According to Mapbox, the data is only used to improve its own products. In addition, Mapbox also collects randomly generated IDs to analyse user behaviour and determine the number of active users.
When you use one of our sub-pages and interact with an online map, Mapbox sets the following cookie in your browser:
Name: ppcbb-enable-content-mapbox_js
Value: 1605795587112749124-4
Purpose: More detailed information about the purpose of the cookie is not yet known to us.
Expiry date: after one year
Note: During our tests we did not find a cookie in the Chrome browser, but we did in other browsers.
How long and where are the data stored?
The collected data is stored and processed on American servers of the company Mapbox. Your IP address is retained for 30 days for security reasons and then deleted. Randomly generated IDs (not personal data) that analyse the use of the APIs are deleted after 36 months.
How can I delete my data or prevent data storage?
If you do not want Mapbox to process data about you or your user behaviour, you can deactivate JavaScript in your browser settings. Of course, you will then no longer be able to use the corresponding functions to their full extent.
You have the right at any time to access your personal data and to object to their use and processing. Cookies that may be set by Mapbox API can be managed, deleted or deactivated in your browser at any time. However, the service may then no longer function fully. The management, deletion or deactivation of cookies works a little differently with each browser. Under the “Cookies”section you will find the corresponding links to the respective instructions of the best-known browsers.
Legal Basis
If you have consented to Mapbox API being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by Mapbox API.
On our part, there is also a legitimate interest in using Mapbox API to optimise our online service. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use Mapbox API insofar as you have given your consent.
Mapbox also processes data about you in the USA, among other places. Mapbox is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Mapbox uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template clauses provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Mapbox undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
You can learn more about the data and Standard Contractual Clauses processed through the use of Mapbox API in the privacy policy at https://www.mapbox.com/legal/privacy.
OpenStreetMap Privacy Policy
| OpenStreetMap Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimisation of our service 📓 Data processed: Data such as IP address, browser information, your operating system, content of the request, restricted location and usage data More details can be found further below in this privacy policy. 📅 Storage duration: the IP address is deleted after 180 days ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What is OpenStreetMap?
On our website we have integrated map sections of the online map tool “OpenStreetMap”. This is a so-called open-source mapping that we can access via an API (interface). This function is offered by OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. By using this map function, your IP address is forwarded to OpenStreetMap. In this privacy policy you will learn why we use the functions of the OpenStreetMap tool, where which data are stored and how you can prevent this data storage.
The OpenStreetMap project was launched in 2004. The goal of the project is and was to create a free world map. Users collect data worldwide about buildings, forests, rivers and streets, for example. In this way, over the years, an extensive user-created digital world map has been created. Of course, the map is not complete, but it is equipped with a great deal of data in most regions.
Why do we use OpenStreetMap on our website?
Our website should primarily be helpful to you. And from our point of view, it is always helpful when information can be found quickly and easily. On the one hand, this is about our services and products; on the other hand, other helpful information should also be available to you. That is why we also use the OpenStreetMap map service. Because this way we can show you exactly how to find our company, for example. The map shows you the best way to us and your journey becomes child’s play.
Which data are stored by OpenStreetMap?
When you visit one of our websites that offers OpenStreetMap, user data is transmitted to the service and stored there. OpenStreetMap collects, for example, information about your interactions with the digital map, your IP address, data about your browser, device type, operating system and on which day and at what time you used the service. Tracking software is also used for this to record user interactions. The company states in its own privacy policy the analysis tool “Piwik”.
The data collected is subsequently accessible to the corresponding working groups of the OpenStreetMap Foundation. According to the company, personal data is not passed on to other persons or companies unless this is legally necessary. The third-party provider Piwik stores your IP address, but in shortened form.
The following cookie can be set in your browser when you interact with OpenStreetMap on our website:
Name: _osm_location
Value: 9.63312%7C52.41500%7C17%7CM
Purpose: The cookie is needed to unlock the contents of OpenStreetMap.
Expiry date: after 10 years
If you want to view the full-screen map, you will be linked to the OpenStreetMap website. There, among other things, the following cookies can be stored in your browser:
Name: _osm_totp_token
Value: 148253112749124-2
Purpose: This cookie is used to ensure the operation of the map section.
Expiry date: after one hour
Name: _osm_session
Value: 1d9bfa122e0259d5f6db4cb8ef653a1c
Purpose: With the help of the cookie, session information (i.e. user behaviour) can be stored.
Expiry date: after end of session
Name: _pk_id.1.cf09
Value: 4a5.1593684142.2.1593688396.1593688396112749124-9
Purpose: This cookie is set by Piwik to store or measure user data such as click behaviour.
Expiry date: after one year
How long and where are the data stored?
The API servers, the databases and the servers of auxiliary services are currently located in the United Kingdom (Great Britain and Northern Ireland) and in the Netherlands. Your IP address and user information, which are stored in shortened form by the web analysis tool Piwik, are deleted after 180 days.
How can I delete my data or prevent data storage?
You have the right at any time to access your personal data and to object to their use and processing. Cookies that may be set by OpenStreetMap can be managed, deleted or deactivated in your browser at any time. However, this will mean that the service no longer functions to its full extent. The management, deletion or deactivation of cookies works a little differently with each browser. Under the “Cookies” section you will find the corresponding links to the respective instructions of the best-known browsers.
Legal Basis
If you have consented to OpenStreetMap being used, the legal basis for the corresponding data processing is this consent. This consent constitutes, according to Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data, as may occur when captured by OpenStreetMap.
On our part, there is also a legitimate interest in using OpenStreetMap to optimise our online service. The corresponding legal basis is Art. 6(1)(f) GDPR (legitimate interests). However, we only use OpenStreetMap insofar as you have given your consent.
If you want to learn more about data processing by OpenStreetMap, we recommend the company’s privacy policy at https://wiki.osmfoundation.org/wiki/Privacy_Policy.
OpenWeather Privacy Policy
For our website, we use OpenWeather, an online service for weather data. The service provider is the British company Openweather Ltd, 17th floor, 1 Ropemaker Street, City Point, London, EC2Y 9ST, United Kingdom.
You can learn more about the data processed through the use of OpenWeather in the Privacy Policy at https://openweather.co.uk/privacy-policy.
Explanation of Terms Used
We always strive to write our privacy policy as clearly and comprehensibly as possible. However, this is not always easy, especially with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). However, we do not want to use these without an explanation. Below you will find an alphabetical list of important terms used that we may not have adequately addressed in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also cite the GDPR texts here and add our own explanations where appropriate.
Supervisory Authority
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“supervisory authority” means an independent public authority which is established by a Member State pursuant to Article 51;
Explanation: “Supervisory authorities” are always state, independent institutions that also have the power to issue directives in certain cases. They serve to carry out so-called state supervision and are located in ministries, special departments or other authorities. For data protection in Austria, there is an Austrian Data Protection Authority; for Germany, there is a separate data protection authority for each federal state.
Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to controllers, there can also be so-called processors. This includes any company or person that processes personal data on our behalf. Processors can therefore include, in addition to service providers such as tax advisors, hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Filing System
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“filing system” means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;
Explanation: Any organised storage of data on a data carrier of a computer is referred to as a “filing system”. If, for example, we store your name and email address on a server for our newsletter, then this data is located in a so-called “filing system”. The most important tasks of a “filing system” include the quick searching and finding of specific data and of course the secure storage of the data.
Information Society Service
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“information society service” means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council (19);
Explanation: Generally, the term “information society” refers to a society that is based on information and communication technologies. Especially as a website visitor, you are familiar with the most diverse kinds of online services, and most online services are considered“information society services”. A classic example of this is an online transaction, such as the purchase of goods over the internet.
Third Party
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
Explanation: The GDPR here basically only explains what a “third party” is not. In practice, any “third party” is someone who also has an interest in the personal data, but does not belong to the above-mentioned persons, authorities or institutions. For example, a parent company can act as a “third party”. In this case, the subsidiary is the controller and the parent company is the “third party”. However, this does not mean that the parent company is automatically allowed to view, collect or store the personal data of the subsidiary.
Restriction of Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“restriction of processing” means the marking of stored personal data with the aim of limiting their processing in the future;
Explanation: It is one of your rights to be able to demand at any time that processors restrict your personal data for further processing operations. For this purpose, specific personal data such as your name, your date of birth or your address are marked in such a way that full further processing is no longer possible. For example, you could restrict the processing to the effect that your data may no longer be used for personalised advertising.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
Explanation: For websites, such consent is usually given via a cookie consent tool. You certainly know this. Whenever you first visit a website, you are usually asked via a banner whether you agree or consent to data processing. Usually, you can also make individual settings and thus decide for yourself which data processing you allow and which not. If you do not consent, no personal data about you may be processed. In principle, consent can also be given in writing, i.e. not via a tool.
Recipient
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
Explanation: Every person and every company that receives personal data is considered a recipient. Thus, we and our processors are also so-called recipients. Only authorities that have an investigation mandate are not considered recipients.
Cross-border Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“cross-border processing” means either
(a)
processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or
(b)
processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State;
Explanation: If, for example, a company or other organisation has establishments in Spain and Croatia and personal data is processed in connection with the activities of the establishments, this is a“cross-border processing” of personal data. Even if the data is only processed in one country (as in this example in Spain), but the effects on the affected person are also noticeable in another country, this is also referred to as “cross-border processing”.
Main Establishment
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“main establishment”
(a)
as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment;
(b)
as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation;
Explanation: For example, the company Google is an American company that also processes data in the USA, but the European main establishment is located in Ireland (Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland). Thus, from a legal point of view, Google Ireland Limited is an independent company and is responsible for all Google products offered in the European Economic Area. In contrast to a main establishment, there are also branch offices, but these do not function as legally independent establishments and are therefore also to be distinguished from subsidiaries. A main establishment is therefore always the place where a company (trading company) has its operational centre.
Personal Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data is therefore all data that can identify you as a person. This is typically data such as:
- Name
- Address
- Email address
- Postal address
- Phone number
- Date of birth
- Identification numbers such as social security number, tax identification number, identity card number or matriculation number
- Bank details such as account number, credit information, account balances, etc.
According to the European Court of Justice (ECJ), your IP address also counts as personal data. IT experts can determine at least the approximate location of your device and subsequently you as the connection holder based on your IP address. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that are particularly worthy of protection. These include:
- racial and ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data such as data taken from blood or saliva samples
- biometric data (this is information about psychological, physical or behavioural characteristics that can identify a person).
Health data - data concerning sexual orientation or sex life
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
Explanation: In profiling, various pieces of information about a person are compiled to learn more about that person. In the web area, profiling is frequently used for advertising purposes or credit checks. Web or advertising analysis programs collect data about your behaviour and interests on a website, for example. This results in a special user profile that can be used to target advertising at a specific audience.
Pseudonymisation
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
Explanation: In our privacy policy, pseudonymised data is mentioned more often. With pseudonymised data, you can no longer be identified as a person unless additional information is added. However, you should not confuse pseudonymisation with anonymisation. With anonymisation, any reference to a person is eliminated, so that it can really only be reconstructed through disproportionately great technical effort.
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and therefore the “controller”. If we pass on collected data to other service providers for processing, they are “processors”. For this, a“data processing agreement (DPA)” must be signed.
Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Note: When we speak of processing in our privacy policy, we mean any type of data processing. This includes, as mentioned above in the original GDPR definition, not only the collection but also the storage and processing of data.
Personal Data Breach
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
Explanation: For example, a “personal data breach” can occur in the case of a data leak, i.e. a technical problem or a cyber attack. If the breach results in a risk to the rights and freedoms of natural persons, the controller must immediately notify the competent supervisory authority of the incident. In addition, the affected persons must also be informed if the breach poses a high risk to the rights and freedoms of natural persons.
Representative
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“representative” means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation;
Explanation: A“representative” can therefore be any person who has been designated in writing by us (controller) or by one of our service providers (processor). Companies outside the EU that process data of EU citizens must designate a representative within the EU. For example, if a web analytics provider has its main establishment in the USA, it must appoint a “representative” within the European Union to represent the obligations relating to data processing.
Closing Remarks
Congratulations! If you are reading these lines, you have really "fought" your way through our entire privacy policy or at least scrolled this far. As you can see from the scope of our privacy policy, we take the protection of your personal data anything but lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we do not just want to tell you which data is processed, but also to bring you closer to the reasons for using various software programs. As a rule, privacy policies sound very technical and legalistic. Since most of you are neither web developers nor lawyers, we also wanted to take a different linguistic approach and explain the facts in simple and clear language. Of course, this is not always possible due to the subject matter. The most important terms are therefore explained in more detail at the end of the privacy policy.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible body. We wish you a pleasant time and hope to welcome you back to our website soon.
All texts are protected by copyright.
Source: Created with the Privacy Policy Generator Austria by AdSimple