Privacy Policy

Table of Contents

Introduction and Overview

We have prepared this Privacy Policy (Version 04/29/2025-322988387) to provide you with information in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, to explain what personal data (hereinafter “data”) we, as the data controller—and the data processors we engage (e.g., service providers)—process, will process in the future, and what legal options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is intended to explain the most important points to you as simply and transparently as possible. Where it promotes transparency, technical Terms Explained in an Easy-to-Understand Way, links to additional information are provided, and Graphs We use this to clearly and simply explain that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if one provides explanations that are as brief, unclear, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the links provided, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.

Scope of Application

This Privacy Policy applies to all personal data processed by our company and to all personal data processed by companies we have contracted (data processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:

  • All online platforms (websites, online stores) that we operate
  • Social Media Presence and Email Communication
  • Mobile apps for smartphones and other devices

In short: This Privacy Policy applies to all areas within the company where personal data is processed in a structured manner through the channels listed above. Should we enter into a legal relationship with you outside of these channels, we will notify you separately if necessary.

Legal Basis

In the following Privacy Policy, we provide you with transparent information about the legal principles and regulations—that is, the legal bases under the General Data Protection Regulation—that allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, access this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 read more.

We process your data only if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
  2. Contract (Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, when we enter into a purchase agreement with you, we need certain personal information in advance.
  3. Legal Obligation (Article 6(1)(c) of the GDPR): We process your data when we are subject to a legal obligation to do so. For example, we are legally required to retain invoices for accounting purposes. These invoices typically contain personal data.
  4. Legitimate Interests (Article 6(1)(f) of the GDPR): In cases where legitimate interests do not override your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.

Other conditions, such as the collection of data in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. However, should such a legal basis be applicable, it will be indicated in the appropriate section.

In addition to the EU regulation, national laws also apply:

  • In Austria This is the Federal Act on the Protection of Individuals with Regard to the Processing of Personal Data (Data Protection Act), in short DSG.
  • In Germany Does that apply? Federal Data Protection Act, in short BDSG.

If any additional regional or national laws apply, we will provide you with information about them in the following sections.

Contact Information for the Data Controller

If you have any questions regarding data protection or the processing of personal data, please find below the contact information for the data controller as specified in Article 4(7) of the EU General Data Protection Regulation (GDPR):
Bernd Morgenthaler
1 Moosbauerweg
82515 Wolfratshausen

Authorized Representative: Bernd Morgenthaler
Email: in**@******et.de
Phone: 0172 140 1969
Legal Notice: Bernd Morgenthaler, TouriNet GmbH, Moosbauerweg 1, 82515 Wolfratshausen

Contact Information for the Data Protection Officer

Below are the contact details for the Data Protection Officer:

Bernd Morgenthaler
1 Moosbauerweg
82515 Wolfratshausen

Email: be***@**********er.de
Phone: +49 4711 65416

Retention period

It is our general policy to store personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.

If you wish to have your data deleted or wish to revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.

We will provide you with information below regarding the specific duration of each data processing activity, provided we have further details on this matter.

Rights Under the General Data Protection Regulation

In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed in a fair and transparent manner:

  • Under Article 15 of the GDPR, you have the right to know whether we process any of your personal data. If we do, you have the right to receive a copy of that data and to obtain the following information:
    • the purpose for which we process the data;
    • the categories—that is, the types of data—that are processed;
    • who receives this data, and if the data is transferred to third countries, how security can be guaranteed;
    • how long the data is stored;
    • the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
    • that you can file a complaint with a supervisory authority (links to these authorities are provided below);
    • the source of the data, if we did not collect it from you;
    • whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
  • Under Article 16 of the GDPR, you have the right to have your data corrected, which means that we must correct any errors you find.
  • Under Article 17 of the GDPR, you have the right to erasure („right to be forgotten“), which specifically means that you may request the erasure of your data.
  • Under Article 18 of the GDPR, you have the right to restrict processing, which means that we may only store the data but may not use it further.
  • Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
  • Under Article 21 of the GDPR, you have the right to object, which, once exercised, will result in a change to how your data is processed.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then review as soon as possible whether we can legally comply with this objection.
    • If your data is used for direct marketing, you may object to this type of data processing at any time. After that, we may no longer use your data for direct marketing.
    • If data is used for profiling, you may object to this type of data processing at any time. After that, we may no longer use your data for profiling.
  • Under certain circumstances, pursuant to Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing (such as profiling).
  • Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may file a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights—don't hesitate to contact the responsible party listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you may file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/ find. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) contact. The following local data protection authority has jurisdiction over our company:

Bavarian Data Protection Authority

State Commissioner for Data Protection: Prof. Dr. Thomas Petri
Address: 18 Wagmüllerstr., 80538 Munich
Phone number: 089/21 26 72-0
Email address: po********@****************rn.de
Website: https://www.datenschutz-bayern.de/

Data Transfers to Third Countries

We transfer or process data to countries outside the scope of the GDPR (third countries) only if you consent to such processing or if there is another legal basis for doing so. This applies in particular when the processing is required by law or necessary to fulfill a contractual relationship, and in any case only to the extent that it is generally permitted. In most cases, your consent is the primary reason we have data processed in third countries. The processing of personal data in third countries such as the United States, where many software providers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.

We expressly note that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the U.S. currently exists only if a U.S. company, that processes personal data of EU citizens in the U.S. is an active participant in the EU-U.S. Data Privacy Framework. For more information, please visit: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en

Data processing by U.S. services that are not active participants in the EU-U.S. Data Privacy Framework may result in data being processed and stored without being anonymized, where applicable. Furthermore, U.S. government authorities may access specific data, where applicable. In addition, collected data may be linked to data from other services of the same provider, provided you have a corresponding user account. Whenever possible, we try to use server locations within the EU, if such options are available.
We provide more detailed information about data transfers to third countries—where applicable—in the relevant sections of this Privacy Policy.

Data Processing Security

To protect personal data, we have implemented both technical and organizational measures. Whenever possible, we encrypt or pseudonymize personal data. By doing so, we make it as difficult as possible—within the limits of our capabilities—for third parties to infer personal information from our data.

Article 25 of the GDPR refers to “data protection through technology design and privacy-friendly default settings,” meaning that security must always be considered—both in software (e.g., forms) and hardware (e.g., access to the server room)—and appropriate measures must be implemented. In the following, we will discuss specific measures as needed.

TLS Encryption with HTTPS

TLS, encryption, and HTTPS sound very technical—and they are. We use HTTPS (which stands for „Hypertext Transfer Protocol Secure“) to transmit data over the Internet in a way that prevents eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secure—no one can “eavesdrop.”.

We have thus introduced an additional layer of security and comply with data protection through design (Article 25(1) of the GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.
You can tell that this data transmission security measure is in use by the small padlock icon in the upper-left corner of the browser, to the left of the web address (e.g., examplepage.de) and the use of the "https" scheme (instead of "http") as part of our web address.
If you'd like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to additional information.

Communication

Communication Summary
👥 Who This Affects: Anyone who communicates with us by phone, email, or online form
📓 Processed data: e.g., phone number, name, email address, form data entered. You can find more details about this under the respective contact method.
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Retention period: Duration of the business transaction and as required by law
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(b) of the GDPR (contract), Art. 6(1)(f) of the GDPR (legitimate interests)

If you contact us and communicate with us by phone, email, or through an online form, we may process your personal data.

The data will be processed for the purpose of handling and addressing your inquiry and the related business transaction. The data will be stored for as long as necessary or as required by law.

Affected Individuals

All individuals who contact us through the communication channels we provide are affected by the events mentioned above.

Phone

When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business transaction has been completed and legal requirements permit it.

Email

When you communicate with us via email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and on the email server. The data will be deleted as soon as the business matter has been resolved and legal requirements permit it.

Online Forms

When you communicate with us via the online form, data is stored on our web server and, if necessary, forwarded to one of our email addresses. The data is deleted as soon as the business transaction is complete and legal requirements permit.

Legal Basis

The processing of data is based on the following legal grounds:

  • Art. 6(1)(a) of the GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
  • Art. 6(1)(b) of the GDPR (Contract): It is necessary for the performance of a contract with you or a processor, such as a telephone service provider, or we need to process the data for precontractual activities, such as preparing a quote;
  • Art. 6(1)(f) GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical systems—such as email programs, Exchange servers, and mobile network providers—are necessary to ensure efficient communication.

Cookies

Cookies Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Depends on the specific cookie. For more details, see below or contact the software provider that sets the cookie.
📓 Data Processed: Depends on the specific cookie used. For more details, see below or contact the software provider that sets the cookie.
📅 Storage duration: depends on the specific cookie; can range from hours to years
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.

Whenever you browse the Internet, you use a browser. Some well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing cannot be denied: Cookies are really useful little helpers. Almost all websites use cookies. To be more precise, they are HTTP cookies, since there are also other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder—essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this „user-specific“ information back to our site. Thanks to cookies, our website recognizes you and provides you with the settings you’re accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following diagram illustrates a possible interaction between a web browser—such as Chrome—and a web server. In this scenario, the web browser requests a website and receives a cookie from the server, which the browser then uses again the next time a different page is requested.

HTTP Cookie Interaction Between the Browser and the Web Server

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other „malware.“ Cookies also cannot access information on your computer.

Here's an example of what cookie data might look like:

Name: _ga
Value: GA1.2.1326744211.152322988387-9
Purpose: Distinguishing Between Website Visitors
Expiration Date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4,096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3,000 cookies in total

What types of cookies are there?

The specific cookies we use depend on the services we employ and are explained in the following sections of this Privacy Policy. At this point, we would like to briefly discuss the different types of HTTP cookies.

There are four types of cookies:

Essential Cookies
These cookies are necessary to ensure the website's basic functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues browsing other pages, and only proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.

Essential Cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the website's loading time and performance across different browsers.

Targeted Cookies
These cookies improve the user experience. For example, they save locations you've entered, font sizes, or form data.

Advertising Cookies
These cookies are also called targeting cookies. They are used to deliver personalized ads to users. This can be very convenient, but it can also be very annoying.

Usually, when you visit a website for the first time, you'll be asked which of these types of cookies you want to allow. And, of course, this decision is also stored in a cookie.

If you'd like to learn more about cookies and don't mind reading technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”.

Purpose of Processing via Cookies

The purpose ultimately depends on the specific cookie. You can find more details below or by contacting the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are small tools that help with a wide variety of tasks. Unfortunately, it is not possible to generalize about what data is stored in cookies, but we will inform you about the data that is processed or stored in this Privacy Policy.

Cookie Retention Periods

The storage period depends on the specific cookie and is explained in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.

You also have control over how long cookies are stored. You can manually delete all cookies at any time through your browser (see also “Right to Object” below). Furthermore, cookies that are based on your consent will be deleted no later than when you revoke your consent, although the lawfulness of their storage up to that point remains unaffected.

Right to Object – How Can I Delete Cookies?

You decide for yourself whether and how you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only some cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to see which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find these options in your browser settings:

Chrome: Delete, Enable, and Manage Cookies in Chrome

Safari: Managing Cookies and Website Data with Safari

Firefox: Clear cookies to remove data that websites have stored on your computer

Internet Explorer: Deleting and Managing Cookies

Microsoft Edge: Deleting and Managing Cookies

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. The best approach is to search for instructions on Google using the search terms “delete cookies in Chrome” or “disable cookies in Chrome” if you’re using the Chrome browser.

Legal Basis

The so-called „Cookie Directive“ has been in effect since 2009. It stipulates that the storage of cookies is a Consent (Article 6(1)(a) of the GDPR) requires you to do so. However, there are still very different approaches to these guidelines among EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the cookie guidelines were not transposed into national law. Instead, this directive was largely implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.

For strictly necessary cookies, even in the absence of consent, the following apply: legitimate interests (Article 6(1)(f) of the GDPR), which are, in most cases, of a business nature. We want to provide website visitors with a pleasant user experience, and certain cookies are often absolutely necessary to achieve this.

Unless strictly necessary cookies are used, this will only occur with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.

The following sections provide more detailed information about the use of cookies, to the extent that the software used employs cookies.

Customer Data

Customer Data Summary
👥 Affected parties: Customers, business partners, and contractual partners
🤝 Purpose: Provision of services agreed upon in a contract or a pre-contractual agreement, including related communication
📓 Data Processed: Name, address, contact information, email address, phone number, payment information (such as invoices and bank details), contract details (such as the term and subject matter of the contract), IP address, order details
📅 Retention period: The data will be deleted as soon as it is no longer necessary for our business purposes and there is no legal obligation to retain it.
⚖️ Legal basis: Legitimate interest (Art. 6(1)(f) of the GDPR), Contract (Art. 6(1)(b) of the GDPR)

What is customer data?

In order to provide our services and fulfill our contractual obligations, we also process data from our customers and business partners. This data always includes personal information. Customer data refers to all information processed on the basis of a contractual or pre-contractual relationship in order to provide the services we offer. Customer data, therefore, refers to all the information we collect and process about our customers.

Why do we process customer data?

There are many reasons why we collect and process customer data. The most important one is that we simply need various types of data to provide our services. Sometimes your email address is all we need, but if you purchase a product or service, for example, we also need information such as your name, address, bank details, or contract information. We also use this data for marketing and sales optimization so that we can improve our overall service for our customers. Another important aspect is our customer service, which is always very important to us. We want you to be able to contact us at any time with questions about our offerings, and for that, we need at least your email address.

What data is processed?

At this point, we can only describe the specific data we store in terms of categories. This is because it always depends on the services you receive from us. In some cases, you simply provide us with your email address so that we can, for example, contact you or answer your questions. In other cases, you purchase a product or service from us, and for that we need significantly more information, such as your contact information, payment details, and contract information.

Here is a list of the types of data we may receive from you and process:

  • Name
  • Contact Information
  • Email address
  • Phone number
  • Date of Birth
  • Payment information (invoices, bank information, payment history, etc.)
  • Contract Details (Term, Content)
  • Usage data (websites visited, access data, etc.)
  • Metadata (IP address, device information)

How long is the data stored?

As soon as we no longer need the customer data to fulfill our contractual obligations and for our purposes, and the data is also no longer required for any potential warranty or liability obligations, we delete the relevant customer data. This is the case, for example, when a business contract ends. After that, the statute of limitations is generally 3 years, although longer periods are possible in individual cases. Of course, we also comply with statutory retention requirements. Your customer data will certainly not be disclosed to third parties unless you have explicitly given your consent.

Legal Basis

The legal bases for the processing of your data are Article 6(1)(a) of the GDPR (consent), Article 6(1)(b) of the GDPR (contract or precontractual measures), Article 6(1)(f) of the GDPR (legitimate interests), and in specific cases (e.g., medical services), Article 9(2)(a) of the GDPR (processing of special categories of data).

In cases involving the protection of vital interests, data processing is carried out in accordance with Article 9(2)(c) of the GDPR. For the purposes of healthcare, occupational medicine, medical diagnostics, care or treatment in the health or social services sector, or the administration of systems and services in the health or social services sector, the processing of personal data is carried out in accordance with Article 9(2)(h) of the GDPR. If you voluntarily provide special categories of personal data, the processing is based on Article 9(2)(a) of the GDPR.

Web Hosting Introduction

Web Hosting Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Professional website hosting and ensuring smooth operation
📓 Data processed: IP address, time of the website visit, browser used, and other data. You can find more details below or from the respective web hosting provider.
📅 Retention period: depends on the provider, but is generally 2 weeks
⚖️ Legal basis: Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is web hosting?

When you visit websites these days, certain information—including personal data—is automatically generated and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only for valid reasons. By the way, when we say “website,” we mean the entirety of all web pages on a domain—that is, everything from the home page to the very last subpage (like this one). By “domain,” we mean, for example, example.de or sampleexample.com.

If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You’re probably familiar with the names of some web browsers: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as browsers or web browsers.

To display a website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why it’s usually handled by professional providers. They offer web hosting and ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!

When your browser establishes a connection on your computer (desktop, laptop, tablet, or smartphone) and during the transmission of data to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.

A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the Internet, and the hosting provider.

Browsers and Web Servers

Why do we process personal data?

The purposes of data processing are:

  1. Professional website hosting and ensuring smooth operation
  2. to maintain operational and IT security
  3. Anonymous analysis of user behavior to improve our services and, if necessary, for law enforcement or to pursue claims

What data is processed?

Even as you are visiting our website right now, our web server—the computer on which this website is hosted—typically automatically stores data such as

  • the complete web address (URL) of the webpage that was accessed
  • Browser and browser version (e.g., Chrome 87)
  • the operating system used (e.g., Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g.,. https://www.beispielquellsite.de/vondabinichgekommen/)
  • the hostname and IP address of the device from which the request is being made (e.g., COMPUTERNAME and 194.23.43.121)
  • Date and Time
  • in files known as web server log files

How long is data stored?

As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that government authorities may access this data in the event of unlawful conduct.

In short: Your visit is logged by our provider (the company that hosts our website on special computers [servers]), but we will not share your information without your consent!

Legal Basis

The lawfulness of processing personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests), as the use of professional hosting services from a provider is necessary to present the company on the Internet in a secure and user-friendly manner and, if necessary, to investigate any attacks or claims arising therefrom.

We generally have a contract with the hosting provider regarding data processing in accordance with Article 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.

HostEurope Privacy Policy

We use HostEurope, a web hosting provider, for our website. The service provider is the German company Host Europe GmbH, Hansestrasse 111, 51149 Cologne, Germany.

You can learn more about the data processed when using HostEurope in the Privacy Policy at https://www.hosteurope.de/AGB/Datenschutzerklaerung/.

Data Processing Agreement (DPA) HostEurope

In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with HostEurope. You can read more about what exactly a DPA is and, most importantly, what must be included in a DPA in our general section titled „Data Processing Agreement (DPA).“.

This agreement is required by law because HostEurope processes personal data on our behalf. It specifies that HostEurope may process data it receives from us only in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://www.hosteurope.de/Dokumente/.

Introduction to Website Builder Systems

Website Builder Systems: Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as technical usage information (e.g., browser activity, clickstream activity, session heatmaps), as well as contact information, IP address, or your geographic location. You can find more details below in this Privacy Policy and in the providers’ privacy policies.
📅 Retention period: depends on the provider
⚖️ Legal basis: Art. 6(1)(f) of the GDPR (legitimate interests), Art. 6(1)(a) of the GDPR (consent)

What are website builders?

We use a website builder for our website. Website builders are a specific type of content management system (CMS). With a website builder, website operators can create a website very easily and without any programming knowledge. In many cases, web hosting providers also offer website builders. When using a website builder, your personal data may be collected, stored, and processed. In this privacy notice, we provide you with general information about data processing by website builders. For more detailed information, please refer to the provider’s privacy policy.

Why do we use website builders for our website?

The biggest advantage of a modular system is its ease of use. We want to offer you a clear, simple, and well-organized website that we can easily operate and maintain ourselves—without external assistance. Modular systems now offer many helpful features that we can use even without any programming knowledge. This allows us to design our website according to our preferences and provide you with an informative and enjoyable experience on our site.

What data is stored by a modular system?

Exactly what data is stored depends, of course, on the website builder system used. Each provider processes and collects different types of data from website visitors. However, technical usage information—such as operating system, browser, screen resolution, language and keyboard settings, hosting provider, and the date of your visit—is typically collected. In addition, tracking data (e.g., browser activity, clickstream activity, session heatmaps, etc.) may also be processed. In addition, personal data may also be collected and stored. This usually includes contact information such as your email address, phone number (if you provided it), IP address, and geographic location data. You can find details on exactly which data is stored in the provider’s privacy policy.

How long and where is the data stored?

We provide information below regarding the duration of data processing in connection with the website builder system used, to the extent that we have further details on this matter. You can find detailed information about this in the provider’s privacy policy. In general, we process personal data only for as long as is strictly necessary to provide our services and products. The provider may store your data according to its own policies, over which we have no control.

Right to Object

You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the administrators of the website builder system used at any time. You can find their contact information either in our Privacy Policy or on the provider’s website.

You can delete, disable, or manage cookies that providers use for their features in your browser. The process varies depending on which browser you use. Please note, however, that this may prevent some features from working as usual.

Legal Basis

We have a legitimate interest in using a website builder system to optimize our online service and present it to you in an efficient and user-friendly manner. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we will only use the website builder if you have given your consent.

To the extent that the processing of data is not strictly necessary for the operation of the website, the data will be processed only on the basis of your consent. This applies in particular to tracking activities. The legal basis for this is Article 6(1)(a) of the GDPR.

In this Privacy Policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information on this topic, you can find additional details—if available—in the following section or in the provider’s privacy policy.

WordPress.com Privacy Policy

WordPress.com Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as technical usage information (e.g., browser activity, clickstream activity, session heatmaps), as well as contact information, IP address, or your geographic location. You can find more details below in this Privacy Policy.
📅 Retention period: It depends primarily on the type of data stored and the specific settings.
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is WordPress?

We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

The company was founded in 2003 and, in a relatively short time, grew to become one of the world’s best-known content management systems (CMS). A CMS is software that helps us design our website and present content in an attractive and organized manner. This content can include text, audio, and video.
Through the use of WordPress, personal data about you may also be collected, stored, and processed. Generally, the data stored consists mainly of technical information such as operating system, browser, screen resolution, or hosting provider. However, personal data such as IP address, geographic data, or contact information may also be processed.

Why do we use WordPress on our website?

We have many strengths, but actual programming isn't one of our core competencies.

Nevertheless, we want a high-performance, visually appealing website that we can manage and maintain ourselves. A website builder or content management system like WordPress makes exactly that possible. With WordPress, we don’t have to be programming experts to provide you with a beautiful website. Thanks to WordPress, we can manage our website quickly and easily, even without any prior technical knowledge. If technical issues ever arise or we have specific requests for our website, we still have our experts on hand who are well-versed in HTML, PHP, CSS, and more.

Thanks to WordPress's ease of use and comprehensive features, we can design our website exactly as we want and provide you with a great user experience.

What data does WordPress process?

Non-personal data includes, for example, technical usage information such as browser activity, clickstream activity, session heat maps, and data about your computer, operating system, browser, screen resolution, language and keyboard settings, Internet service provider, and the date of your visit to the site.

In addition, personal data is also collected. This primarily includes contact information (email address or phone number, if you provide it), your IP address, or your geographic location.

WordPress may also use cookies to collect data. These cookies often track information about your behavior on our website. For example, it may track which subpages you particularly like to view, how long you stay on individual pages, when you leave a page (bounce rate), or which preferences (e.g., language selection) you have set. Based on this data, WordPress can also better tailor its own marketing efforts to your interests and user behavior. Consequently, the next time you visit our website, it will be displayed exactly as you previously configured it.

WordPress may also use technologies such as pixel tags (web beacons) to, for example, clearly identify you as a user and potentially serve you interest-based ads.

How long and where is the data stored?

How long the data is stored depends on various factors. Specifically, it depends primarily on the type of data stored and the website’s specific settings. Generally, WordPress deletes the data once it is no longer needed for its own purposes. There are, of course, exceptions, especially when legal obligations require the data to be retained for a longer period. Web server logs containing your IP address and technical data are deleted by WordPress or Automattic after 30 days. Until then, Automattic uses the data to analyze traffic on its own websites (such as all WordPress sites) and to resolve any potential issues. Deleted content on WordPress websites is also retained in the trash for 30 days to allow for restoration; after that, it may remain in backups and caches until they are deleted. The data is stored on Automattic’s servers in the United States.

How can I delete my data or prevent it from being stored?

You have the right and the ability at any time to access your personal data and to object to its use and processing. You may also file a complaint with a government regulatory authority at any time.

In your browser, you also have the option to manage, delete, or disable cookies individually. Please note, however, that disabling or deleting cookies may have a negative impact on the functionality of our WordPress site. Depending on which browser you use, the process for managing cookies works slightly differently. Under the „Cookies“ section, you’ll find links to the relevant instructions for the most popular browsers.

Legal Basis

If you have consented to the use of WordPress, this consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur when data is collected by WordPress.

We also have a legitimate interest in using WordPress to optimize our online service and present it in an appealing way to you. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use WordPress to the extent that you have given your consent.

WordPress and Automattic process your data in the U.S., among other places. Automattic is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Automattic commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more details about the privacy policy and what data is processed by WordPress and how, please visit https://automattic.com/privacy/.

WordPress.com Data Processing Agreement (DPA)

In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with WordPress.com. You can read more about what a DPA is exactly—and, most importantly, what it must contain—in our general section titled „Data Processing Agreement (DPA).“.

This agreement is required by law because WordPress.com processes personal data on our behalf. It clarifies that WordPress.com may only process data it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://wordpress.com/support/data-processing-agreements/.

Social Media Introduction

Social Media Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To present and optimize our services, communicate with visitors, prospective customers, and others, and for advertising purposes
📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.
You can find more details about this on the respective social media platform.
📅 Retention period: depends on the social media platforms used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is social media?

In addition to our website, we are also active on various social media platforms. In this context, user data may be processed so that we can specifically target users who are interested in us through social networks. Furthermore, elements of a social media platform may be embedded directly into our website. This is the case, for example, when you click on a so-called social button on our website and are redirected directly to our social media presence. “Social media” refers to websites and apps through which registered members can create content, share content publicly or within specific groups, and connect with other members.

Why do we use social media?

For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to potential customers. The social media elements integrated into our website help you quickly and easily access our social media content.

The data stored and processed as a result of your use of a social media channel is primarily intended to enable web analytics. The goal of these analyses is to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, the analyzed data can be used to draw conclusions about your interests and create so-called user profiles. This also enables the platforms to present you with customized advertisements. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.

We generally assume that we remain the data controller under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be a joint controller with us within the meaning of Article 26 of the GDPR. Where this is the case, we will make a separate note of it and operate on the basis of a relevant agreement. The key provisions of the agreement are then set forth below for the respective platform.

Please note that when you use social media platforms or our embedded features, your data may also be processed outside the European Union, as many social media channels—such as Facebook or Twitter—are U.S. companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.

What data is processed?

Exactly which data is stored and processed depends on the specific social media platform provider. But typically, this includes data such as phone numbers, email addresses, information you enter into a contact form, user data—for example, which buttons you click, who you like or follow, when you visited which pages—as well as information about your device and your IP address. Most of this data is stored in cookies. Especially if you have a profile on the social media platform you’re visiting and are logged in, data can be linked to your profile.

All data collected through a social media platform is also stored on the providers' servers. Consequently, only the providers have access to the data and can provide you with the relevant information or make changes.

If you want to know exactly what data social media providers store and process, and how you can object to that data processing, you should carefully read the company’s privacy policy. If you have any questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the provider directly.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details. For example, the social media platform Facebook stores data until it is no longer needed for its own purposes. However, customer data that is matched with a user’s own data is deleted within two days. In general, we process personal data only for as long as is absolutely necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be extended.

Right to Object

You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers, such as embedded social media elements. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since social media tools may use cookies, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for the data processing. (Art. 6(1)(a) of the GDPR). In general, if consent has been provided, your data will also be processed based on our legitimate interest (Art. 6(1)(f) of the GDPR) stored and processed for the purpose of fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.

You can find information about specific social media platforms—if available—in the following sections.

Facebook Privacy Policy

Facebook Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Processed Data: Data such as customer data, user behavior data, information about your device, and your IP address.
You can find more details on this further down in the Privacy Policy.
📅 Retention period: until the data is no longer useful for Facebook's purposes
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What are Facebook tools?

We use select Facebook tools on our website. Facebook is a social media network operated by Meta Platforms Inc. or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland. These tools enable us to provide you and others interested in our products and services with the best possible experience.

If data about you is collected and transmitted through our embedded Facebook elements or through our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook bears sole responsibility for the further processing of this data. Our joint obligations are also set forth in a publicly available agreement at https://www.facebook.com/legal/controller_addendum enshrined. Among other things, it stipulates that we must clearly inform you about the use of Facebook tools on our site. Furthermore, we are also responsible for ensuring that the tools are integrated into our website in a manner that complies with data protection laws. Facebook, on the other hand, is responsible for the data security of Facebook products. If you have any questions regarding data collection and processing by Facebook, you can contact the company directly. If you direct your question to us, we are obligated to forward it to Facebook.

Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete that data.

In addition to many other products, Facebook also offers what are known as “Facebook Business Tools.” That is Facebook’s official name for them. However, since the term is not widely known, we have decided to simply refer to them as Facebook Tools. These include, among others:

  • Facebook Pixel
  • social plug-ins (such as the „Like“ or „Share“ button)
  • Facebook Login
  • Account Kit
  • APIs (Application Programming Interfaces)
  • SDKs (Software Development Kits)
  • Platform Integrations
  • Plugins
  • Codes
  • Specifications
  • Documentation
  • Technologies and Services

Through these tools, Facebook expands its services and is able to obtain information about user activity outside of Facebook.

Why do we use Facebook tools on our website?

We want to show our services and products only to people who are genuinely interested in them. With the help of ads (Facebook Ads), we can reach exactly those people. However, in order to show users relevant ads, Facebook needs information about people’s preferences and needs. As a result, information about user behavior (and contact information) on our website is made available to the company. This allows Facebook to collect more accurate user data and display relevant ads about our products and services to interested people. These tools thus enable tailored advertising campaigns on Facebook.

Facebook refers to data about your behavior on our website as „event data.“ This data is also used for measurement and analytics services. This allows Facebook to create „campaign reports“ on our behalf regarding the effectiveness of our advertising campaigns. Furthermore, analytics provide us with better insight into how you use our services, website, or products. We use some of these tools to optimize your user experience on our website. For example, you can use the social plugins to share content from our site directly on Facebook.

What data is stored by Facebook tools?

Using certain Facebook tools may result in personal data (customer data) being sent to Facebook. Depending on the tools used, customer data such as name, address, phone number, and IP address may be transmitted.

Facebook uses this information to match the data with the data it has about you (if you are a Facebook member). Before customer data is transmitted to Facebook, a process known as „hashing“ takes place. This means that a data set of any size is converted into a string of characters. This also serves to encrypt the data.

In addition to contact information, „event data“ is also transmitted. „Event data“ refers to the information we collect about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information it collects with third parties (such as advertisers) unless the company has explicit permission or is legally required to do so. „Event data“ can also be linked to contact information. This allows Facebook to offer more personalized advertising. After the aforementioned matching process, Facebook deletes the contact information.

In order to deliver optimized ads, Facebook uses event data only if it has been aggregated with other data (collected by Facebook through other means). Facebook also uses this event data for security, protection, development, and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, a varying number of cookies are stored in your browser. We provide more detailed information about individual Facebook cookies in the descriptions of the various Facebook tools. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.

How long and where is the data stored?

In general, Facebook stores data until it is no longer needed for its own services and Facebook products. Facebook has servers located all over the world where its data is stored. However, customer data is deleted within 48 hours after it has been matched with the user’s own data.

How can I delete my data or prevent it from being stored?

In accordance with the General Data Protection Regulation, you have the right to access, correct, transfer, and delete your data.

Your data will only be completely deleted if you permanently delete your Facebook account. Here's how to delete your Facebook account:

1) Click "Settings" on the right side of Facebook.

2) Next, click „Your Facebook Information“ in the left column.

3) Now click “Deactivate and Delete.”.

4) Now select „Delete Account“ and then click „Continue and Delete Account“

5) Now enter your password, click „Next,“ and then click „Delete Account.“

The data that Facebook receives through our site is stored, among other things, via cookies (e.g., through social plugins). In your browser, you can disable, delete, or manage individual cookies or all cookies. Depending on which browser you use, this works in different ways. In the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide whether to allow each individual cookie or not.

Legal Basis

If you have consented to the processing and storage of your data by integrated Facebook tools, this consent serves as the legal basis for the data processing. (Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest (Art. 6(1)(f) of the GDPR) stored and processed to facilitate fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review Facebook’s privacy policy or cookie guidelines.

Facebook processes your data in the U.S., among other places. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Facebook uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/legal/terms/dataprocessing.

We hope we've helped you better understand the most important information about the use and processing of data by Facebook tools. If you'd like to learn more about how Facebook uses your data, we recommend reviewing the privacy policy at https://www.facebook.com/privacy/policy/.

Introduction to Online Marketing

Online Marketing Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To analyze visitor data in order to optimize the website.
📓 Data Processed: Access statistics, which include data such as access locations, device information, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed. You can find more details about this in the documentation for the respective online marketing tool.
📅 Retention period: depends on the online marketing tools used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What is online marketing?

Online marketing refers to all activities carried out online to achieve marketing goals, such as increasing brand awareness or closing a sale. Furthermore, our online marketing efforts are aimed at drawing people’s attention to our website. To showcase our offerings to as many interested people as possible, we engage in online marketing. This typically involves online advertising, content marketing, or search engine optimization. To ensure we can use online marketing efficiently and effectively, we also collect and process personal data. On the one hand, this data helps us ensure that our content is shown only to those who are genuinely interested in it; on the other hand, it allows us to measure the advertising success of our online marketing efforts.

Why do we use online marketing tools?

We want to show our website to everyone who is interested in what we have to offer. We realize that this isn’t possible without taking deliberate action. That’s why we do online marketing. There are various tools that make it easier for us to carry out our online marketing efforts and that also use data to continuously provide suggestions for improvement. This allows us to tailor our campaigns more precisely to our target audience. Ultimately, the purpose of these online marketing tools is to optimize our offerings.

What data is processed?

To ensure that our online marketing is effective and that we can measure the success of our efforts, we create user profiles and store data, for example, in cookies (which are small text files). With the help of this data, we can not only display ads in the traditional sense but also present our content on our website in a way that best suits your preferences. There are various third-party tools that offer these functions and, accordingly, collect and store data from you. For example, the cookies mentioned store information about which pages you visited on our website, how long you viewed those pages, which links or buttons you clicked, and which website referred you to us. In addition, technical information may also be stored, such as your IP address, the browser you use, the device from which you visit our website, and the time you accessed our website and when you left it. If you have consented to allow us to determine your location, we may also store and process this information.

Your IP address is stored in pseudonymized form (i.e., truncated). Unique data that directly identifies you as an individual—such as your name, address, or email address—is also stored only in pseudonymized form as part of our advertising and online marketing processes. Therefore, we cannot identify you as an individual; rather, we only have the pseudonymized information stored in the user profiles.

Under certain circumstances, these cookies may also be placed, analyzed, and used for advertising purposes on other websites that use the same advertising tools. The data may then also be stored on the servers of the advertising tool providers.

In exceptional cases, personally identifiable information (names, email addresses, etc.) may also be stored in user profiles. This occurs, for example, if you are a member of a social media platform that we use for our online marketing activities and the platform links previously collected data to your user profile.

For all the advertising tools we use that store your data on their servers, we only ever receive aggregated information and never data that identifies you as an individual. The data simply shows how well specific advertising campaigns performed. For example, we can see which campaigns prompted you or other users to visit our website and purchase a service or product there. Based on these analyses, we can improve our advertising offerings in the future and tailor them even more precisely to the needs and preferences of interested individuals.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. You can usually find detailed information about the specific cookies used by each provider in their respective privacy policies.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. The lawfulness of the processing up until the time of revocation remains unaffected.

Since online marketing tools typically use cookies, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

If you have consented to the use of third-party providers, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by online marketing tools.

We also have a legitimate interest in measuring online marketing activities in an anonymized form in order to use the data collected to optimize our offerings and initiatives. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools to the extent that you have given your consent.

Information on specific online marketing tools—if available—can be found in the following sections.

Google AdSense Privacy Policy

Google AdSense Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: business success and the optimization of our services.
📓 Processed data: Access statistics, which include data such as access locations, device information, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
📅 Retention period: depends on the cookies used and the data stored
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What is Google AdSense?

We use Google AdSense on this website. This is an advertising program provided by Google Inc. In Europe, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google AdSense allows us to display ads on this website that are relevant to our content. This allows us to offer you ads that, ideally, provide real added value for you. In this privacy notice regarding Google AdSense, we explain why we use Google AdSense on our website, which of your data is processed and stored, and how you can prevent this data from being stored.

The Google AdSense advertising program has been around since 2003. Unlike Google Ads (formerly Google AdWords), you can’t place ads yourself through this service. Google AdSense displays ads on websites, such as ours. The biggest advantage of this advertising service compared to many others is that Google AdSense only shows you ads that are relevant to our content. Google uses its own algorithm to determine which ads you see. Of course, we only want to show you ads that interest you and offer added value. Google uses your interests and user behavior, along with the content we provide, to determine which ads are suitable for our website and our users. We’d also like to mention here that we are not responsible for the selection of these ads. We simply provide the advertising space on our website. Google is responsible for selecting the ads that are displayed. Since August 2013, the ads have also been adapted to the respective user interface. This means that whether you visit our website from your smartphone, PC, or laptop, the ads will adapt to your device.

Why do we use Google AdSense on our website?

Running a high-quality website requires a lot of dedication and hard work. Basically, we’re never done working on our website. We always strive to maintain our site and keep it as up-to-date as possible. Of course, we also want this work to be financially successful. That’s why we’ve chosen advertising as a source of revenue. The most important thing for us, however, is to ensure that these ads do not disrupt your visit to our website. With the help of Google AdSense, you’ll only see ads that are relevant to our topics and your interests.

Similar to how Google indexes a website, a bot analyzes the relevant content and offerings on the page. The ads are then customized based on that content and displayed. In addition to content overlaps between the ad and the website’s offerings, AdSense also supports interest-based targeting. This means that Google also uses your data to provide ads tailored to you. This way, you receive ads that, ideally, offer you real added value, and we have a better chance of earning a little something.

What data does Google AdSense store?

Google AdSense uses cookies, among other things, to display ads that are tailored to your interests. Cookies are small text files that store certain information on your computer.

In AdSense, cookies are used to deliver more relevant ads. The cookies do not contain any personally identifiable information. However, it is important to note that Google considers data such as “pseudonymous cookie IDs” (where a name or other identifying characteristic is replaced by a pseudonym) or IP addresses to be non-personally identifiable information. Under the GDPR, however, this data may be considered personal data. Google AdSense sends a cookie to the browser after every impression (which occurs whenever you see an ad), every click, and every other activity that results in a request to the Google AdSense servers. If the browser accepts the cookie, it is stored there.

Under certain circumstances, third-party providers may, as part of AdSense, place and read cookies in your browser or use web beacons to store data they receive through the display of ads on the website. Web beacons are small graphics that analyze and record log files. This analysis enables statistical evaluation for online marketing purposes.

Google can use these cookies to collect certain information about your user behavior on our website. This includes:

  • Information on how to interact with an ad (clicks, impressions, mouse movements)
  • Information about whether an ad has already appeared in your browser at an earlier time. This data helps ensure that you do not see the same ad more than once.

In doing so, Google analyzes and evaluates the data regarding the displayed advertisements and your IP address. Google uses this data primarily to measure the effectiveness of an ad and to improve its advertising offerings. This data is not linked to any personal information that Google may have about you from other Google services.

Below, we’ll introduce you to the cookies that Google AdSense uses for tracking purposes. We’ll be referring to a test website that has only Google AdSense installed: 

Name: uid
Value: 891269189322988387-8
Purpose: The cookie is stored under the domain adform.net. It provides a uniquely assigned, machine-generated user ID and collects data about activity on our website.
Expiration Date: after 2 months

Name: C
Value: 1
Purpose: This cookie determines whether your browser accepts cookies. The cookie is stored under the domain track.adform.net.
Expiration Date: after 1 month

Name: cid
Value: 8912691894970695056,0,0,0,0
Purpose: This cookie is stored under the domain track.adform.net, represents a client ID, and is used to improve the ads you see. It can deliver more relevant ads to visitors and helps improve campaign performance reports.
Expiration Date: after 2 months

Name: IDE
Value: zOtj4TWxwbFDjaATZ2TzNaQmxrU322988387-1
Purpose: The cookie is stored under the domain doubleclick.net. It is used to track your actions after an ad is displayed or after you click on it. This allows us to measure how well an ad is received by our visitors.
Expiration Date: after 1 month

Name: test_cookie
Value: Not specified
Purpose: You can use the „test_cookies“ cookie to check whether your browser supports cookies at all. The cookie is stored under the domain doubleclick.net.
Expiration Date: after 1 month

Name: CT592996
Value:733366
Purpose: Stored under the domain adform.net. The cookie is set as soon as you click on an advertisement. We were unable to find more detailed information about the use of this cookie.
Expiration Date: after an hour

Note: This list is by no means exhaustive, as experience has shown that Google frequently changes the cookies it uses.

How long and where is the data stored?

Google collects your IP address and various activities you perform on the website. Cookies store this information about your interactions on our website. According to Google, the company collects and stores the specified information securely on its own servers in the United States.

If you do not have a Google Account or are not signed in, Google typically stores the collected data with a unique identifier (ID) in your browser. The unique IDs stored in cookies are used, for example, to deliver personalized ads. If you’re signed in to a Google Account, Google may also collect personal data.

You can delete some of the data that Google stores at any time (see the next section). Much of the information stored in cookies is automatically deleted after a certain period of time. However, there is also data that Google stores for a longer period of time. This is the case when Google must store certain data for an indefinite, extended period due to business or legal requirements.

How can I delete my data or prevent it from being stored?

You can always delete or disable cookies stored on your computer. How exactly you do this depends on your browser. In the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. By downloading and installing this browser plug-in at https://support.google.com/ads/answer/7395996 All „advertising cookies“ will also be disabled. Please note that disabling these cookies does not prevent ads from appearing; it only prevents personalized advertising.

If you have a Google account, you can access the website https://adssettings.google.com/authenticated Disable personalized ads. You will still see ads, but they will no longer be tailored to your interests. However, the ads will still be displayed based on a few factors, such as your location, browser type, and search terms.

Legal Basis

If you have consented to the use of Google AdSense, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by Google AdSense.

We also have a legitimate interest in using Google AdSense to optimize our online services and marketing efforts. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google AdSense if you have given your consent.

Google processes your data in the United States, among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/

You can find out what data Google generally collects and how it uses that data at https://policies.google.com/privacy?hl=de read more.

Affiliate Programs: Introduction

Affiliate Programs Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: business success and the optimization of our services.
📓 Processed data: Access statistics, which include data such as access locations, device information, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
📅 Retention period: Personal data is typically stored by affiliate programs until it is no longer needed
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What are affiliate programs?

We use affiliate programs from various providers on our website. When you use an affiliate program, your data may be transferred to, stored by, and processed by the respective affiliate program provider. In this privacy policy, we provide you with a general overview of data processing through affiliate programs and explain how you can prevent or revoke such data transfers. Every affiliate program is based on the principle of referral commissions. A link or an advertisement containing a link is placed on our website; if you are interested in it, click on it, and purchase a product or service through that link, we receive a commission (advertising reimbursement).

Why do we use affiliate programs on our website?

Our goal is to provide you with an enjoyable experience and plenty of helpful content. To that end, we put a great deal of work and time into developing our website. Through affiliate programs, we’re able to earn a small compensation for our work. Of course, every affiliate link is always related to our topic and features offers that might interest you.

What data is processed?

In order to track whether you clicked on a link we provided, the affiliate program provider needs to know that it was you who followed the link via our website. Therefore, the affiliate program links used must be correctly matched to the subsequent actions (business transaction, purchase, conversion, impression, etc.). Only then can commission payments be processed correctly.

To make this tracking work, a value can be appended to a link (in the URL), or information can be stored in cookies. This information includes, for example, the page you came from (referrer), when you clicked the link, an identifier for our website, details about the offer in question, and a user ID.

This means that as soon as you interact with the products and services of an affiliate program, that provider also collects data from you. Exactly what data is stored depends on the individual providers. For example, the Amazon Associates Program distinguishes between active and automatic information. Active information includes your name, email address, phone number, age, payment information, and location information. In this case, automatically collected information includes user behavior, IP address, device information, and the URL.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details. In general, personal data is processed only for as long as necessary to provide the services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website; others may remain stored in your browser for several years unless you actively delete them. The exact duration of data processing depends on the provider used; in most cases, you should expect a storage period of several years. You can usually find detailed information about the duration of data processing in the respective privacy policies of the individual providers.

Right to Object

You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the data controller of the affiliate program provider you are using at any time. You can find contact information either in our specific privacy policy or on the provider’s website.

You can delete, disable, or manage cookies that providers use for their features in your browser. The process varies depending on which browser you use.

Legal Basis

If you have consented to the use of affiliate programs, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected through a partner program.

We also have a legitimate interest in using an affiliate program to optimize our online services and marketing efforts. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we will only use the affiliate program if you have given your consent.

Information on specific partner programs—if available—can be found in the following sections.

Amazon Associates Program Privacy Policy

Amazon Associates Program Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: business success and the optimization of our services.
📓 Processed data: Access statistics, which include data such as access locations, device information, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
📅 Retention period: Personal data is stored by Amazon until it is no longer needed
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What is the Amazon Associates Program?

We use the Amazon Associates Program operated by Amazon.com, Inc. on our website. The entities responsible within the meaning of the Privacy Policy are Amazon Europe Core S.à.r.l., Amazon EU S.à.r.l., Amazon Services Europe S.à.r.l., and Amazon Media EU S.à.r.l., all four located at 5, Rue Plaetis, L-2338 Luxembourg, as well as Amazon Instant Video Germany GmbH, Domagkstr. 28, 80807 Munich. Amazon Deutschland Services GmbH, Marcel-Breuer-Str. 12, 80807 Munich, acts as the data processor. By using this Amazon Associates Program, your data may be transmitted to, stored by, and processed by Amazon.

In this privacy policy, we explain what data is involved, why we use the program, and how you can manage or prevent the transfer of data.

The Amazon Associates Program is an affiliate marketing program run by the online retailer Amazon.de. Like any affiliate program, the Amazon Associates Program is based on the principle of referral commissions. Amazon—or rather, we—place advertisements or affiliate links on our website, and if you click on them and purchase a product through Amazon, we receive a commission.

Why do we use the Amazon Associates Program on our website?

Our goal is to provide you with an enjoyable experience and plenty of helpful content. To that end, we put a great deal of work and energy into developing our website. Through the Amazon Associates Program, we have the opportunity to earn a small commission for our work. Of course, every affiliate link to Amazon is always related to our topic and showcases offers that might interest you.

What data is stored by the Amazon Associates Program?

As soon as you interact with Amazon’s products and services, Amazon collects data from you. Amazon distinguishes between information that you actively provide to the company and information that is automatically collected and stored. “Active information” includes, for example, your name, email address, phone number, age, payment information, or location information. So-called „automatic information“ is primarily stored via cookies. This includes information on user behavior, IP address, device information (browser type, location, operating systems), and the URL. Amazon also stores the clickstream—that is, the path (sequence of pages) you take as a user to reach a product. Amazon also stores cookies in your browser to track the origin of an order. This allows the company to recognize that you clicked on an Amazon ad or an affiliate link via our website.

If you have an Amazon account and are logged in while browsing our website, the data collected may be associated with your account. You can prevent this by logging out of Amazon before browsing our website.

Here are some examples of cookies that are set in your browser when you click on an Amazon link on our website.

Name: uid
Value: 3230928052675285215322988387-9
Purpose: This cookie stores a unique user ID and collects information about your website activity.
Expiration Date: after 2 months

Name: ad-id
Value: AyDaInRV1k-Lk59xSnp7h5o
Purpose: This cookie is provided by amazon-adsystem.com and is used by the company for various advertising purposes.
Expiration Date: after 8 months

Name: uuid2
Value: 8965834524520213028322988387-2
Purpose: This cookie enables targeted and interest-based advertising through the AppNexus platform. For example, the cookie collects and stores anonymous data—via your IP address—about which ads you clicked on and which pages you visited.
Expiration Date: after 3 months

Name: session-id
Value: 262-0272718-2582202322988387-1
Purpose: This cookie stores a unique user ID that the server assigns to you for the duration of your visit to the website (session). If you visit the same page again, the information stored in it will be retrieved.
Expiration Date: after 15 years

Name: APID
Value: UP9801199c-4bee-11ea-931d-02e8e13f0574
Purpose: This cookie stores information about how you use a website and what advertisements you viewed before visiting the website.
Expiration Date: after a year

Name: session-id-time
Value: tb:s-STNY7ZS65H5335FZEVPE|1581329862486&t:1581329864300&adb:adblk_no
Purpose: This cookie tracks the time you spend on a website using a unique cookie ID.
Expiration Date: after 2 years

Name: csm-hit
Value: 2082754801l
Purpose: We were unable to obtain any specific information about this cookie.
Expiration Date: after 15 years

Note: Please note that this list provides only examples of cookies and is not intended to be exhaustive.

Amazon uses this information to tailor advertisements more closely to users' interests.

How long and where is the data stored?

Amazon stores personal data for as long as is necessary for Amazon's business services or as required by law. Since Amazon is headquartered in the United States, the data collected is also stored on U.S. servers.

How can I delete my data or prevent it from being stored?

You have the right to access and delete your personal data at any time. If you have an Amazon account, you can manage or delete much of the data collected in your account.

Your browser offers another option for managing how Amazon processes and stores your data according to your preferences. There, you can manage, disable, or delete cookies. This works a little differently in each browser. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.

Legal Basis

If you have consented to the use of the Amazon Associates Program, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected through the Amazon Associates Program.

We also have a legitimate interest in using the Amazon Associates Program to optimize our online services and marketing efforts. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use the Amazon Associates Program if you have given your consent.

Amazon processes your data in the United States, among other places. Amazon is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Amazon uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Amazon commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Amazon Data Processing Terms (AWS GDPR DATA PROCESSING), which are consistent with the Standard Contractual Clauses, can be found at https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf.

We hope we've helped you understand the key information about data transmission through the Amazon Associates Program. For more information, please visit https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.

Booking.com Affiliate Program Privacy Policy

We use the Booking.com affiliate program for our website. The service provider is the Dutch company Booking.com B.V., Herengracht 597, 1017 CE Amsterdam, Netherlands. You can learn more about the data processed through the use of Booking.com in the privacy policy at https://www.booking.com/content/privacy.de.html.

Content Delivery Networks: Introduction

Content Delivery Networks Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our service (so the website loads faster)
📓 Data Processed: Data such as your IP address
You can find more details below and in the individual privacy policies.
📅 Retention period: In most cases, the data is retained until it is no longer needed to provide the service.
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is a content delivery network?

We use what is known as a content delivery network on our website. Such a network is usually referred to simply as a CDN. A CDN helps us load our website quickly and smoothly, regardless of your location. In the process, your personal data is also stored, managed, and processed on the servers of the CDN provider we use. Below, we provide a general overview of the service and its data processing practices. Detailed information about how your data is handled can be found in the provider’s respective privacy policy.

Every Content Delivery Network (CDN) is a network of geographically distributed servers, all of which are connected to each other via the Internet. Through this network, website content (especially very large files) can be delivered quickly and smoothly, even during periods of high traffic. To achieve this, the CDN stores a copy of our website on its servers. Since these servers are distributed worldwide, the website can be delivered quickly. As a result, the CDN significantly reduces the time it takes for data to be transferred to your browser.

Why do we use a content delivery network for our website?

A fast-loading website is part of our service. We know, of course, how frustrating it is when a website loads at a snail’s pace. Most of the time, you even lose patience and leave the site before it’s fully loaded. We want to avoid that, of course. That’s why a fast-loading website is a natural part of our website offerings. With a Content Delivery Network (CDN), our website loads significantly faster in your browser. Using a CDN is especially helpful when you’re abroad, because the website is delivered from a server near you.

What data is processed?

When you request a website or its content and that content is cached in a CDN, the CDN forwards the request to the server closest to you, and that server delivers the content. Content Delivery Networks are designed so that JavaScript libraries can be downloaded and hosted on npm and GitHub servers. Alternatively, most CDNs also allow WordPress plugins to be loaded if they are hosted on WordPress.org be hosted. Your browser may send personal data to the Content Delivery Network (CDN) we use. This data includes, for example, your IP address, browser type, browser version, the website being loaded, and the date and time of your visit. This data is collected and stored by the CDN. Whether cookies are used for data storage depends on the network in question. Please review the privacy policies of the respective service for more information.

Right to Object

If you want to completely prevent this data transfer, you can use a JavaScript blocker (see, for example, https://noscript.net/) on your PC. Of course, our website will then no longer be able to provide the usual services (such as fast loading speeds).

Legal Basis

If you have consented to the use of a content delivery network, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by a content delivery network.

We also have a legitimate interest in using a content delivery network to optimize our online service and make it more secure. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we will only use this tool if you have given your consent.

Information about specific content delivery networks—if available—can be found in the following sections.

Cloudflare Privacy Policy

Cloudflare Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our service (so the website loads faster)
📓 Processed Data: Data such as IP addresses, contact and log information, security fingerprints, and website performance data
You can find more details on this further down in this privacy policy.
📅 Retention period: In most cases, the data is stored for less than 24 hours
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is Cloudflare?

On this website, we use Cloudflare, provided by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA), to make our website faster and more secure. In doing so, Cloudflare uses cookies and processes user data. Cloudflare, Inc. is an American company that offers a content delivery network and various security services. These services are located between the user and our hosting provider. We’ll try to explain exactly what this all means in more detail below.

A Content Delivery Network (CDN), such as the one provided by Cloudflare, is simply a network of interconnected servers. Cloudflare has distributed these servers around the world to deliver websites to your screen more quickly. Simply put, Cloudflare creates copies of our website and stores them on its own servers. When you visit our website, a load-balancing system ensures that the largest portions of our website are delivered from the server that can display our website to you the fastest. A CDN significantly shortens the distance data must travel to reach your browser. As a result, Cloudflare delivers our website’s content to you not only from our hosting server but also from servers all over the world. Using Cloudflare is particularly helpful for users abroad, as the site can be served from a nearby server. In addition to fast website delivery, Cloudflare also offers various security services, such as DDoS protection and a web application firewall.

Why do we use Cloudflare on our website?

Of course, we want to provide you with the best possible service through our website. Cloudflare helps us make our website faster and more secure. Cloudflare offers us both web optimization and security services, such as DDoS protection and a web firewall. This also includes a Reverse Proxy and the content delivery network (CDN). Cloudflare blocks threats and limits abusive bots and crawlers that waste our bandwidth and server resources. By caching our website in local data centers and blocking spam software, Cloudflare enables us to reduce our bandwidth usage by about 60%. Delivering content via a data center near you and implementing certain web optimizations there reduces the average page load time by about half. According to Cloudflare, the „I’m Under Attack Mode“ setting can further mitigate attacks by displaying a JavaScript puzzle that must be solved before a user can access a webpage. Overall, this makes our website significantly more robust and less vulnerable to spam or other attacks.

What data does Cloudflare process?

Cloudflare generally only forwards data that is controlled by website operators. This means that the content is not determined by Cloudflare, but always by the website operator itself. In addition, Cloudflare may collect certain information regarding the use of our website and process data that we send or for which Cloudflare has received specific instructions. In most cases, Cloudflare receives data such as IP addresses, contact and log information, security fingerprints, and website performance data. Log data, for example, helps Cloudflare detect new threats. This enables Cloudflare to ensure a high level of security for our website. Cloudflare processes this data as part of its services in compliance with applicable laws. This naturally includes the General Data Protection Regulation (GDPR). Cloudflare also works with third-party providers. These providers may process personal data only under Cloudflare’s instructions and in accordance with Cloudflare’s privacy policy and other confidentiality and security measures. Cloudflare does not disclose any personal data without our explicit consent.

How long and where is the data stored?

Cloudflare stores your information primarily in the United States and the European Economic Area. Cloudflare may transfer and access the information described above from anywhere in the world. In general, Cloudflare stores user-level data for domains on the Free, Pro, and Business plans for less than 24 hours. For Enterprise domains that have enabled Cloudflare Logs (formerly Enterprise LogShare or ELS), data may be stored for up to 7 days. However, if IP addresses trigger security alerts at Cloudflare, there may be exceptions to the retention period listed above.

How can I delete my data or prevent it from being stored?

Cloudflare retains data logs only as long as necessary, and in most cases, this data is deleted within 24 hours. Cloudflare also does not store any personally identifiable information, such as your IP address. However, there is some information that Cloudflare stores indefinitely as part of its permanent logs in order to improve the overall performance of Cloudflare Resolver and detect potential security risks. You can find out exactly which permanent logs are stored at https://www.cloudflare.com/application/privacypolicy/ Read more. All data that Cloudflare collects (whether temporarily or permanently) is stripped of any personally identifiable information. All permanent logs are also anonymized by Cloudflare.

In its Privacy Policy, Cloudflare states that it is not responsible for the content it receives. For example, if you ask Cloudflare to update or delete your content, Cloudflare will generally refer you to us as the website operator. You can also completely prevent Cloudflare from collecting and processing your data by disabling script execution in your browser or installing a script blocker in your browser.

Legal Basis

If you have consented to the use of Cloudflare, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) of the GDPR (Consent) the legal basis for the processing of personal data, as may occur when such data is collected by Cloudflare.

We also have a legitimate interest in using Cloudflare to optimize our online service and make it more secure. The legal basis for this is Art. 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Cloudflare if you have given your consent.

Cloudflare processes your data in the U.S., among other places. Cloudflare is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Cloudflare uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Cloudflare commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.

For more information about the standard contractual clauses and the data processed through the use of Cloudflare, please see the Privacy Policy at https://www.cloudflare.com/privacypolicy/.

Cloudflare Data Processing Agreement (DPA)

In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with Cloudflare. You can read more about what exactly a DPA is—and, most importantly, what must be included in a DPA—in our general section titled „Data Processing Agreement (DPA).“.

This agreement is required by law because Cloudflare processes personal data on our behalf. It specifies that Amazon Web Services and Cloudflare may only process data they receive from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://www.cloudflare.com/de-de/cloudflare-customer-dpa/.

Cookie Consent Management Platform Summary
👥 Affected parties: Website visitors
🤝 Purpose: To obtain and manage consent for specific cookies and, consequently, the use of specific tools
📓 Processed Data: Data used to manage cookie settings, such as IP address, time of consent, type of consent, and individual consents. For more details, please refer to the specific tool being used.
📅 Retention period: Depends on the tool used; you should expect periods of several years
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What is a cookie consent management platform?

We use Consent Management Platform (CMP) software on our website, which makes it easier for both us and you to handle scripts and cookies correctly and securely. The software automatically generates a cookie pop-up, scans and monitors all scripts and cookies, provides you with the cookie consent required under data protection laws, and helps both us and you keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide for yourself whether and which scripts and cookies you allow or do not allow. The following diagram illustrates the relationship between the browser, web server, and CMP.

Consent Management Platform Overview

Why do we use a cookie management tool?

Our goal is to provide you with the highest possible level of transparency regarding data protection. We are also legally required to do so. We want to inform you as thoroughly as possible about all tools and cookies that may store and process your data. It is also your right to decide for yourself which cookies you accept and which you do not. To grant you this right, we first need to know exactly which cookies are present on our website. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we are aware of all cookies and can provide you with information about them in compliance with the GDPR. You can then use the consent system to accept or reject cookies.

What data is processed?

Using our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. Your consent is stored so that we do not have to ask you for it every time you visit our website and so that we can provide proof of your consent if required by law. This information is stored either in an opt-in cookie or on a server. The retention period for your cookie consent varies depending on the provider of the cookie management tool. In most cases, this data (such as a pseudonymous user ID, the time of consent, details regarding cookie categories or tools, browser, and device information) is stored for up to two years.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases, you should expect a retention period of several years. You can usually find detailed information about the duration of data processing in the respective privacy policies of the individual providers.

Right to Object

You also have the right and the option to withdraw your consent to the use of cookies at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

You can find information about specific cookie management tools—if available—in the following sections.

Legal Basis

If you consent to cookies, your personal data will be processed and stored through these cookies. If, as a result of your Consent (Article 6(1)(a) of the GDPR) Since we are permitted to use cookies, this consent also serves as the legal basis for the use of cookies and the processing of your data. To manage consent for cookies and enable you to provide your consent, we use cookie consent management platform software. The use of this software allows us to operate the website efficiently and in compliance with the law, which is a legitimate interest (Article 6(1)(f) of the GDPR).

AdSimple Consent Manager Privacy Policy Summary
👥 Affected parties: Website visitors
🤝 Purpose: To obtain consent for certain cookies and, consequently, the use of certain tools
📓 Data Processed: Data used to manage your cookie settings, such as your IP address, the time of consent, the type of consent, and individual consents. You can find more details on this further down in this Privacy Policy.
📅 Storage period: The cookie used expires after one year
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests)

What is the AdSimple Consent Manager?

On our website, we use the AdSimple Consent Manager from the software development and online marketing company AdSimple GmbH, Fabriksgasse 20, 2230 Gänserndorf. Among other things, the AdSimple Consent Manager allows us to provide you with a comprehensive and privacy-compliant cookie notice so that you can decide for yourself which cookies to accept and which to reject. When you use this software, your data is sent to and stored by AdSimple. In this privacy policy, we explain why we use the AdSimple Consent Manager, what data is transmitted and stored, and how you can prevent this data transmission.

The AdSimple Consent Manager is a software program that scans our website and identifies and categorizes all existing cookies. In addition, as a website visitor, you are informed about the use of cookies via a cookie notice script and can decide for yourself which cookies to allow and which to block.

Why do we use the AdSimple Consent Manager on our website?

We want to provide you with maximum transparency regarding data protection. To ensure this, we first need to know exactly which cookies have been placed on our website over time. Because AdSimple’s Consent Manager regularly scans our website and identifies all cookies, we have full control over these cookies and can thus operate in compliance with the GDPR. This allows us to provide you with detailed information about the use of cookies on our website. Furthermore, you’ll always receive an up-to-date and privacy-compliant cookie notice and can use a checkbox system to decide for yourself which cookies to accept or block.

What data is stored by the AdSimple Consent Manager?

If you accept cookies on our website, the AdSimple Consent Manager will set the following cookie:

Name: acm_status
Value: “:true,”statistics”:true,”marketing”:true,”social media”:true,”settings”:true}
Purpose: This cookie stores your consent status. This allows our website to read and honor your current status during future visits.
Expiration Date: after a year

How long and where is the data stored?

All data collected by the AdSimple Consent Manager is transmitted and stored exclusively within the European Union. The collected data is stored on AdSimple’s servers at Hetzner GmbH in Germany. Only AdSimple GmbH and Hetzner GmbH have access to this data.

How can I delete my data or prevent it from being stored?

You have the right to access and delete your personal data at any time. You can prevent the collection and storage of data, for example, by rejecting the use of cookies via the cookie notice script. Your browser also offers another way to prevent data processing or manage it according to your preferences. Cookie management works slightly differently depending on the browser. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.

Legal Basis

If you consent to cookies, your personal data will be processed and stored through these cookies. If, as a result of your Consent (Article 6(1)(a) of the GDPR) Since we are permitted to use cookies, this consent also serves as the legal basis for the use of cookies and the processing of your data. The AdSimple Consent Manager is used to manage consent to cookies and to enable you to provide your consent. Using this software enables us to operate the website efficiently and in compliance with the law, which is a legitimate interest (Article 6(1)(f) of the GDPR).

We hope we've provided you with a good overview of data traffic and data processing through the AdSimple Consent Manager. If you'd like to learn more about this tool, we recommend visiting the description page at https://www.adsimple.at/consent-manager/.

We use the consent management tool Real Cookie Banner on our website. The service provider is the German company devowl.io GmbH, Tannet 12, 94539 Grafling,
Germany.

For more information about the data processed when using Real Cookie Banner, please see the Privacy Policy at https://devowl.io/de/datenschutzerklaerung/.

Usercentrics Privacy Policy

We use Usercentrics, a consent management platform (CMP), on our website. The service provider is the German company Usercentrics GmbH, located at Sendlinger Straße 7, 80331 Munich, Germany.

You can learn more about the data processed through the use of Usercentrics in the Privacy Policy at https://usercentrics.com/privacy-policy/.

Security & Anti-Spam

Security & Anti-Spam Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: Cybersecurity
📓 Processed data: Data such as your IP address, name, or technical information such as your browser version
You can find more details below and in the individual privacy policies.
📅 Retention period: In most cases, the data is retained until it is no longer needed to provide the service.
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is security and anti-spam software?

With so-called security and anti-spam software, you can protect yourself—and us—from various spam and phishing emails, as well as other potential cyberattacks. Spam refers to unsolicited bulk promotional emails that you did not request. Such emails are also called junk mail and can incur costs. Phishing emails, on the other hand, are messages designed to build trust through fake messages or websites in order to obtain personal information. Anti-spam software generally protects against unwanted spam messages or malicious emails that could, for example, introduce viruses into our system. We also use general firewall and security systems that protect our computers from unwanted network attacks.

Why do we use security and anti-spam software?

We place a particularly high priority on security on our website. After all, it’s not just about our security, but above all about yours. Unfortunately, cyber threats have become an everyday reality in the world of IT and the Internet. Hackers often use cyberattacks to try to steal personal data from an IT system. That’s why a robust defense system is absolutely essential. A security system monitors all incoming and outgoing connections to our network and computers. To achieve even greater protection against cyberattacks, we use additional external security services in addition to the standard security systems on our computers. This helps prevent unauthorized data transfers, thereby protecting us from cybercrime.

What data is processed by security and anti-spam software?

Exactly what data is collected and stored naturally depends on the specific service. However, we always strive to use only programs that collect data sparingly or store only the data necessary to provide the service offered. In general, the service may store data such as your name, address, IP address, email address, and technical data such as browser type or browser version. Performance and log data may also be collected to detect potential incoming threats in a timely manner. This data is processed within the scope of the services and in compliance with applicable laws. For U.S. providers, this includes the GDPR (via the Standard Contractual Clauses). In some cases, these security services also collaborate with third-party providers who may store and/or process data under instruction and in accordance with the privacy policy and other security measures. Data is typically stored using cookies.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details. For example, security programs store data until you or we revoke consent for data storage. In general, personal data is stored only for as long as is strictly necessary to provide the services. Unfortunately, in many cases, we do not have precise information from the providers regarding the duration of storage.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party security software at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since such security services may also use cookies, we recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

We use these security services primarily based on our legitimate interests (Art. 6(1)(f) of the GDPR) in maintaining a robust security system against various cyberattacks.

Certain processing activities, in particular the use of cookies and security features, require your consent. If you have consented to the processing and storage of your data by integrated security services, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the services we use place cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.

You can find information about specific tools—if available—in the following sections.

Akismet Privacy Policy

We use Akismet, an anti-spam solution for WordPress, on our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

Automattic processes your data in the U.S., among other places. Akismet and Automattic are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Automattic commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.

The Data Processing Agreements, which refer to the Standard Contractual Clauses, can be found at https://wordpress.com/support/data-processing-agreements/.

For more information about the data processed through the use of Akismet or WordPress, please see the privacy policy at https://automattic.com/de/privacy/.

External Online Platforms: Introduction

External Online Platforms: Privacy Policy Summary
👥 Individuals affected: Website visitors or visitors to external online platforms
🤝 Purpose: To present and optimize our services, and to communicate with visitors and prospective customers
📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.
You can find more details on this on the respective platform.
📅 Retention period: depends on the platforms used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What are external online platforms?

In order to offer our services or products outside of our website, we also use external platforms. These are mostly online marketplaces such as Amazon or eBay. In addition to our responsibility for data protection, the privacy policies of the external platforms we use also apply. This is especially the case when our products are purchased through the platform—that is, when a payment transaction takes place. Furthermore, most platforms also use your data to optimize their own marketing efforts. For example, using the data collected, the platform can tailor advertisements precisely to the interests of customers and website visitors.

Why do we use external online platforms?

In addition to our website, we also want to offer our products on other platforms to reach more customers. External online marketplaces such as Amazon, eBay, and Digistore24 provide large sales platforms that showcase our products to people who may not be familiar with our website. It may also happen that embedded elements on our site redirect users to an external online platform. Data processed and stored by the online platform in question is used by the company both to log the payment transaction and to conduct web analytics.

The goal of these analyses is to enable the development of more precise and personalized marketing and advertising strategies. Based on your behavior on a platform, the analyzed data can be used to draw relevant conclusions about your interests and create so-called user profiles. This also enables the platforms to present you with customized advertisements or products. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.

Please note that when you use the platforms or our embedded elements, your data may also be processed outside the European Union, as online platforms—such as Amazon or eBay—are U.S. companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.

What data is processed?

Exactly which data is stored and processed depends on the specific external platform. However, it usually includes data such as phone numbers, email addresses, information you enter into a contact form, user data (such as which buttons you click and when you visited which pages), information about your device, and your IP address. Very often, most of this data is stored in cookies. If you have your own profile on an external platform and are logged in there, data may be linked to that profile. The collected data is stored on the servers of the platforms used and processed there. You can find out exactly how an external platform stores, manages, and processes data in its respective privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the platform directly.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. For example, Amazon stores data until it is no longer needed for its own purposes. In general, we process personal data only for as long as is strictly necessary to provide our services and products.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies at any time. You can do this either through our cookie management tool or through the opt-out features on the respective external platform. Furthermore, you can prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since cookies may be used, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective external platforms.

Legal Basis

If you have consented to having your data processed and stored by external platforms, this applies Consent as the legal basis for data processing (Art. 6(1)(a) of the GDPR). In general, if consent has been given, your data will also be processed on the basis of a legitimate interest (Art. 6(1)(f) of the GDPR) for the purpose of ensuring prompt and effective communication with you or other customers and business partners. If we have embedded elements from external platforms on our website, we use them only to the extent that you have given your consent.

Information about specific external platforms—if available—can be found in the following sections.

Amazon (Europe) Privacy Policy

We also use the online marketplace Amazon (Europe). The service provider is the U.S. company Amazon Inc. For the European region, the company responsible is Amazon Europe Core S.à r.l. (Société à responsabilité limitée), 38 avenue John F. Kennedy, L-1855 Luxembourg.

Amazon processes your data in the United States, among other places. Amazon is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Amazon uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Amazon commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Amazon Data Processing Terms (AWS GDPR DATA PROCESSING), which are consistent with the Standard Contractual Clauses, can be found at https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf.

For more information about the data processed through the use of Amazon, please see the Privacy Policy at https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010&ref_=footer_privacy .

Amazon App Store Privacy Policy

We also use the Amazon App Store. The service provider is the U.S. company Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.

Amazon processes your data in the United States, among other places. Amazon is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Amazon uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Amazon commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Amazon Data Processing Terms (AWS GDPR DATA PROCESSING), which are consistent with the Standard Contractual Clauses, can be found at https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf.

For more information about the data processed when using the Amazon App Store, please see the Privacy Policy at https://aws.amazon.com/de/privacy/.

Audio & Video Introduction

Audio & Video Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.
You can find more details on this below in the relevant privacy policy texts.
📅 Retention period: Data is generally retained for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What are audio and video elements?

We have embedded audio and video elements on our website so that you can, for example, watch videos or listen to music or podcasts directly through our website. The content is provided by service providers. All content is therefore retrieved from the providers’ respective servers.

These are embedded features from platforms such as YouTube, Vimeo, or Spotify. Use of these platforms is generally free, but paid content may also be published. These embedded features allow you to listen to or watch the respective content via our website.

If you use audio or video elements on our website, your personal data may also be transmitted to, processed by, and stored by the service providers.

Why do we use audio and video elements on our website?

Of course, we want to provide you with the best content on our website. And we realize that content is no longer conveyed solely through text and static images. Instead of simply giving you a link to a video, we offer audio and video formats directly on our website that are entertaining or informative—and ideally, both. This expands our service and makes it easier for you to access interesting content. Thus, in addition to our text and images, we also offer video and/or audio content.

What data is stored by audio and video elements?

When you visit a page on our website that contains, for example, an embedded video, your server connects to the service provider’s server. In the process, your data is also transmitted to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider. This usually includes your IP address, browser type, operating system, and other general information about your device. In addition, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which buttons you clicked, or which website you used to access the service. All of this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymized data is typically stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.

Duration of Data Processing

You can find out exactly how long data is stored on third-party providers’ servers either further down in the privacy policy for the respective tool or in the provider’s privacy statement. As a general rule, personal data is processed only for as long as is absolutely necessary to provide our services or products. This generally applies to third-party providers as well. In most cases, you can assume that certain data will be stored on third-party servers for several years. Data stored in cookies, in particular, can be retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. The lawfulness of the processing up until the time of revocation remains unaffected.

Since cookies are typically used on our site due to the embedded audio and video features, you should also review our general privacy policy regarding cookies. You can find more detailed information about how your data is handled and stored in the privacy policies of the respective third-party providers.

Legal Basis

If you have consented to the processing and storage of your data through embedded audio and video elements, this consent serves as the legal basis for the data processing. (Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest (Art. 6(1)(f) of the GDPR) for the purpose of ensuring prompt and effective communication with you or other customers and business partners. However, we only use the embedded audio and video elements to the extent that you have given your consent.

YouTube Data API Privacy Policy

We also use the YouTube Data API. The service provider is the U.S. company Google Inc. In Europe, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google processes your data in the U.S., among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

For more information about the data processed through the use of the YouTube Data API, see the Privacy Policy at https://policies.google.com/privacy?hl=de.

YouTube Privacy Policy

YouTube Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To optimize our services
📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.
You can find more details on this further down in this privacy policy.
📅 Retention period: Data is generally retained for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is YouTube?

We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video platform that has been a subsidiary of Google since 2006. The video platform is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has an embedded YouTube video, your browser automatically connects to YouTube’s or Google’s servers. In the process, various types of data are transmitted (depending on your settings). Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing within Europe.

Below, we’d like to explain in more detail what data is processed, why we’ve embedded YouTube videos, and how you can manage or delete your data.

On YouTube, users can watch, rate, comment on, and upload videos for free. Over the past few years, YouTube has become one of the most important social media platforms worldwide. To allow us to display videos on our website, YouTube provides a code snippet that we have embedded on our site.

Why do we use YouTube videos on our website?

YouTube is the video platform with the most visitors and the best content. We strive to provide you with the best possible user experience on our website. And, of course, interesting videos are a must. With our embedded videos, we provide you with additional helpful content alongside our text and images. In addition, the embedded videos make our website easier to find on the Google search engine. Even when we run ads through Google Ads, Google—thanks to the data it collects—can ensure that these ads are shown only to people who are interested in our offerings.

What data does YouTube store?

As soon as you visit one of our pages that has an embedded YouTube video, YouTube sets at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually associate your interactions on our website with your profile using cookies. This includes data such as session duration, bounce rate, approximate location, and technical information such as browser type, screen resolution, or your internet service provider. Additional data may include contact information, any ratings you’ve given, sharing content via social media, or adding content to your YouTube favorites.

If you are not signed in to a Google or YouTube account, Google stores data using a unique identifier linked to your device, browser, or app. This ensures, for example, that your preferred language setting is retained. However, much of your interaction data cannot be stored because fewer cookies are set.

The following list shows cookies that were set in the browser during a test. On the one hand, we show cookies that are set without a logged-in YouTube account. On the other hand, we show cookies that are set with a logged-in account. This list is not exhaustive, as user data always depends on interactions on YouTube.

Name: YSC
Value: b9-CV6ojI5Y322988387-1
Purpose: This cookie stores a unique ID to track statistics on the video that was viewed.
Expiration Date: after the meeting ends

Name: PREF
Value: f1=50,000,000
Purpose: This cookie also records your unique ID. Google uses PREF to collect statistics on how you use YouTube videos on our website.
Expiration Date: after 8 months

Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiration Date: after 30 minutes

Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user's bandwidth on our websites (which include embedded YouTube videos).
Expiration Date: after 8 months

Other cookies that are set when you are signed in to your YouTube account:

Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7322988387-
Purpose: This cookie is used to create a profile based on your interests. The data is used for personalized advertisements.
Expiration Date: after 2 years

Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user's consent to use various Google services. CONSENT also serves a security purpose by verifying users and protecting user data from unauthorized attacks.
Expiration Date: after 19 years

Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile based on your interests. This data helps us display personalized ads.
Expiration Date: after 2 years

Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login credentials.
Expiration Date: after 2 years

Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.
Expiration Date: after 2 years

Name: SID
Value: oQfNKjAsI322988387-
Purpose: This cookie stores your Google account ID and the time of your last sign-in in a digitally signed and encrypted format.
Expiration Date: after 2 years

Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and what advertisements you may have seen before visiting our site.
Expiration Date: after 3 months

How long and where is the data stored?

The data that YouTube receives from you and processes is stored on Google's servers. Most of these servers are located in the United States. Under https://www.google.com/about/datacenters/locations/?hl=de See exactly where Google's data centers are located. Your data is distributed across the servers. This makes the data more accessible and better protected against tampering.

Google stores the collected data for varying lengths of time. You can delete some data at any time; other data is automatically deleted after a limited period of time; and still other data is stored by Google for a longer period. Some data (such as items from „My Activity,“ photos, documents, or products) stored in your Google Account remains there until you delete it. Even if you’re not signed in to a Google Account, you can delete some data associated with your device, browser, or app.

How can I delete my data or prevent it from being stored?

In general, you can manually delete data from your Google Account. With the automatic deletion feature for location and activity data introduced in 2019, information is stored for either 3 or 18 months—depending on your choice—and then deleted.

Whether or not you have a Google account, you can configure your browser to delete or disable cookies from Google. Depending on which browser you use, this works in different ways. Under the „Cookies“ section, you’ll find links to the instructions for the most popular browsers.

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide whether to allow each individual cookie or not.

Legal Basis

If you have consented to the processing and storage of your data through embedded YouTube elements, this consent serves as the legal basis for the data processing. (Art. 6(1)(a) of the GDPR). In general, your data is also processed based on our legitimate interest (Art. 6(1)(f) of the GDPR) for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded YouTube elements if you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.

YouTube processes your data in the United States, among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

Since YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to learn more about how your data is handled, we recommend that you review the privacy policy at https://policies.google.com/privacy?hl=de.

YouTube Subscribe Button Privacy Policy

We've added the YouTube Subscribe button to our website. You can usually recognize the button by the classic YouTube logo. The logo displays the words „Subscribe“ or „YouTube“ in white text on a red background, with the white „play“ icon to the left of it. However, the button may also appear in a different design.

Our YouTube channel regularly features funny, interesting, or exciting videos. With the built-in „Subscribe“ button, you can subscribe to our channel directly from our website without having to visit the YouTube website separately. We want to make it as easy as possible for you to access our extensive content. Please note that this allows YouTube to store and process your data.

If you see an embedded subscription button on our site, YouTube—according to Google—sets at least one cookie. This cookie stores your IP address and our URL. YouTube can also use this to obtain information about your browser, your approximate location, and your default language. In our test, the following four cookies were set without being logged in to YouTube:

Name: YSC
Value: b9-CV6ojI5322988387Y
Purpose: This cookie stores a unique ID to track statistics on the video that was viewed.
Expiration Date: after the meeting ends

Name: PREF
Value: f1=50,000,000
Purpose: This cookie also records your unique ID. Google uses PREF to collect statistics on how you use YouTube videos on our website.
Expiration Date: after 8 months

Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiration Date: after 30 minutes

Name: VISITOR_INFO1_LIVE
Value: 32298838795Chz8bagyU
Purpose: This cookie attempts to estimate the user's bandwidth on our websites (which include embedded YouTube videos).
Expiration Date: after 8 months

Note: These cookies were set following a test and are not intended to be exhaustive.

If you are logged into your YouTube account, YouTube can use cookies to store many of your actions and interactions on our website and associate them with your YouTube account. This allows YouTube to obtain information such as how long you browse our site, what type of browser you use, what screen resolution you prefer, or what actions you take.

YouTube uses this data both to improve its own services and offerings and to provide analytics and statistics for advertisers (who use Google Ads).

YouTube Similar Audiences Privacy Policy

We also use the YouTube Similar Audiences advertising tool. The service provider is the U.S. company Google LLC. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible.

YouTube processes your data in the United States, among other places. YouTube is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en

In addition, YouTube—like Google—uses standard contractual clauses (Art. 46, paras. 2 and 3 of the GDPR). These model clauses, provided by the European Commission, ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (e.g., the U.S.). Through the EU-U.S. Data Privacy Framework and the standard contractual clauses, YouTube commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. You can find the corresponding implementing decision and the standard contractual clauses here, among other places:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more information about the data processed through the use of YouTube Similar Audiences, please see the Privacy Policy at https://policies.google.com/privacy.

YouTube IFrame Player Privacy Policy

We also use the YouTube iFrame player to embed videos on our website. The service provider is the U.S. company Google Inc. In Europe, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google processes your data in the U.S., among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

For more information about the data processed when using the YouTube iFrame player, please see the Privacy Policy at https://policies.google.com/privacy?hl=de.

YouTube Video Widget Privacy Policy

We also use the YouTube video widget on our website. The service provider is the U.S. company Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google processes your data in the U.S., among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses what are known as Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

For more information about the data processed when using the YouTube video widget, please see the Privacy Policy at https://policies.google.com/privacy?hl=de.

Web Design Introduction

Web Design Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Processed Data: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, technical data, language settings, browser version, screen resolution, and browser name. You can find more details in the documentation for the respective web design tools.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is web design?

We use various tools on our website to support our web design. Web design isn’t just about making our website look nice—as is often assumed—but also about functionality and performance. But of course, creating the right visual look for a website is also one of the main goals of professional web design. Web design is a subset of media design and deals with the visual, structural, and functional aspects of a website. The goal of web design is to enhance your experience on our website. In web design jargon, the terms „user experience“ (UX) and “usability” are used in this context. User experience refers to all the impressions and experiences a website visitor has while on a website. Usability is a key component of user experience; it pertains to how user-friendly a website is. The primary focus here is on ensuring that content, subpages, and products are clearly structured so that you can find what you’re looking for quickly and easily. To provide you with the best possible experience on our website, we also use third-party web design tools. In this Privacy Policy, the “Web Design” category therefore includes all services that enhance the design of our website. These may include, for example, fonts, various plugins, or other integrated web design features.

Why do we use web design tools?

How you take in information on a website depends heavily on the site’s structure, functionality, and visual appeal. That’s why a high-quality, professional web design has become increasingly important to us as well. We’re constantly working to improve our website and view this as an added service for you, our website visitors. Furthermore, an attractive and functional website also offers economic benefits for us. After all, you’ll only visit us and take advantage of our offerings if you feel completely at ease.

What data is stored by web design tools?

When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data is involved depends, of course, largely on the tools used. Below, you can see exactly which tools we use for our website. For more detailed information about data processing, we also recommend that you read the respective privacy policies of the tools we use. In most cases, these policies will tell you what data is processed, whether cookies are used, and how long the data is retained. For example, fonts such as Google Fonts automatically transmit information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers.

Duration of Data Processing

How long data is processed varies greatly from case to case and depends on the web design elements used. For example, if cookies are used, the retention period can range from just one minute to a few years. Please familiarize yourself with this information. We recommend reviewing our general section on cookies as well as the privacy policies of the tools we use. There, you’ll typically find details on exactly which cookies are used and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. As a general rule, data is only retained for as long as necessary to provide the service. Data may also be stored for longer periods if required by law.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out features. You can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. However, some data—particularly related to web design elements (most commonly fonts)—cannot be deleted quite so easily. This is the case when data is automatically collected directly upon visiting a page and transmitted to a third-party provider (such as Google). In that case, please contact the support team of the respective provider. For Google, you can reach support at https://support.google.com/.

Legal Basis

If you have consented to the use of web design tools, this consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional online experience. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use web design tools to the extent that you have given your consent. We would like to emphasize this point once again here.

Information on specific web design tools—if available—can be found in the following sections.

Content Search Providers: Introduction

Content Search Provider Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Processed Data: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, search interests, and/or technical data. You can find more details in the documentation for each tool used.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is a content search provider?

By now, we’ve published a lot of content on our website. And of course, we don’t want it to simply fall by the wayside just because people can’t find it. That’s why we use a content search provider on our website. You’re probably familiar with major search engines like Google. A content search provider is essentially a search engine as well, but unlike Google, it doesn’t scan the entire web for content—it only searches the website you’re currently visiting. You can enter terms related to the content you’re looking for in a text field, and the search program will find the posts you want. When you use the integrated search function, your personal data may also be processed.

Why do we use a content search provider?

As you browse our website, you’ll quickly notice just how much useful content we’ve published over the years. There are some real gems in there, and we want you to find them quickly without having to click around for too long. With a content search feature built right into our website, you can quickly and easily find the content you’re looking for by using keywords related to your topic. This feature is really handy, and we see it as our mission to make your experience on our website as pleasant and helpful as possible. That’s why we’ve decided to integrate a content search tool into our website.

What data is processed?

When you use the search function on our website, the integrated content search provider (such as Algolia Places or Giphy) may automatically receive and store data from you. This includes technical data about your browser as well as information such as your IP address, device ID, and the search terms you enter. Please note that IP addresses are considered personal data. The providers„ privacy policies state that this information is collected and stored to enhance security and improve their own services. The automatically collected usage data—which does not include personal data and is processed in an anonymized form—may also be used for analytical purposes. Some providers also share this anonymized data with third parties. To learn more about this, we recommend that you carefully read the specific privacy policies of the individual providers. To ensure that the services function properly, cookies are generally set in your browser. You can learn more about cookies in our general section titled “Cookies.” You can find out whether and which cookies the individual search tools use—if applicable—below or in the respective privacy policies of the integrated tools.

How long and where is the data stored?

As a general rule, each content search provider processes different types of data. Therefore, this general section cannot address the data processing practices of individual tools in detail. However, these services typically store personal data only for as long as necessary to ensure the tools function properly. Some services (such as Giphy) also retain personal data for longer periods if required by legal obligations. Most providers also retain data in a de-identified form for longer periods. Content search providers may also use cookies to store various types of data. You can learn more about this in our general section on cookies. If you want to know more about the specific cookies used by a search provider, we recommend reviewing the privacy policy of the providers we use. You’ll usually find an illustrative list of the cookies used there.

Right to Object

Always keep in mind: if you do not want your personal data to be processed, it must not be processed. You always have the right to access your personal data and to object to its use. You can also withdraw your consent at any time using the cookie consent tool or other opt-out options. You can easily manage, delete, or disable cookies yourself through your browser. If you delete cookies, some features of the tool may no longer work. So please don’t be surprised if that happens. How you manage cookies in your browser depends on which browser you’re using. In the „Cookies“ section, you’ll also find links to guides for the most popular browsers.

Legal Basis

If you have consented to the use of a content search provider, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur when such data is collected by a content search provider.

We also have a legitimate interest in using a content search provider to optimize our service on our website. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use a content search provider if you have given your consent. We want to make this absolutely clear once again here.

Information about specific content search providers—if available—can be found in the following sections.

Online Booking Systems: Introduction

Online Booking Systems Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience and organization
📓 Processed Data: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, contact and payment information, and/or technical data. You can find more details in the documentation for each tool used.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What is an online booking system?

We use one or more booking systems so that you can make reservations through our website. This makes it very easy to schedule appointments online. A booking system is a software application integrated into our website that displays available resources (such as open time slots) and allows you to book directly online and, in most cases, pay as well. You’re probably already familiar with such booking systems from the restaurant or hotel industries. However, such systems are now used in a wide variety of industries. Depending on the tool and settings, booking systems can be used both internally by us and by customers like you. In the process, personal data about you is generally collected and stored.

In most cases, the booking process works as follows: On our website, you’ll find the booking system where you can book an appointment for a service directly with a click of the mouse and by entering your information—and in most cases, you can pay right away. You may be able to enter various personal details using a form. Please be aware that all data you enter may be stored and managed in a database.

Why do we use an online booking system?

In a way, we also see our website as a free service for you. We want you to find helpful information and feel completely at home on our site. This includes an online service that makes booking appointments or services as easy as possible for you. Gone are the days when you had to wait days on end for a booking confirmation via phone or email. With an online booking system, you can get everything done in just a few clicks and get back to taking care of other things. The system also makes it easier for us to manage all bookings and appointments. That’s why we consider such a booking system to be absolutely beneficial for both you and us.

What data is processed?

Of course, we cannot tell you exactly what data is processed in this general information text about booking systems. That always depends on the tool used and the functions and capabilities it offers. In addition to the standard booking function, many booking systems also offer a range of other features. For example, many systems also have an external online payment system (e.g., Stripe, Klarna, or PayPal) and a calendar synchronization feature integrated. Accordingly, depending on the features, different types and varying amounts of data may be processed. Typically, data such as your IP address, name, and contact information, technical details about your device, and the time of a booking are processed. If you also make a payment through the system, banking information such as account numbers, credit card numbers, passwords, TANs, etc., is stored and shared with the respective payment provider. We recommend that you carefully read the privacy policy of the tool you are using so that you know exactly which of your data is being processed.

Duration of Data Processing

Each booking system stores data for different lengths of time. For this reason, we cannot yet provide specific details here regarding the duration of data processing. In general, however, personal data is stored only for as long as is absolutely necessary to provide the services. Booking systems typically also use cookies, which store information for varying lengths of time. Some cookies are deleted immediately after you leave the page, while others may be stored for several years. You can learn more about this in our „Cookies“ section. Please also review the respective privacy policies of the providers. These should explain how long your data will be stored in each specific case.

Right to Object

If you have consented to data processing by a booking system, you naturally always have the option and the right to revoke that consent. So please always be aware that you have rights regarding your personal data and that you can exercise those rights at any time. If you do not want your personal data to be processed, then no personal data may be processed. It’s that simple. The easiest way to revoke consent for data processing is through a cookie consent tool or other opt-out features provided. You can also manage data storage via cookies directly in your browser, for example. The lawfulness of data processing remains unaffected until you revoke your consent.

Legal Basis

If you have consented to the use of booking systems, that consent serves as the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur through booking systems.

Furthermore, we also have a legitimate interest in using booking systems because they allow us, on the one hand, to expand our customer service and, on the other hand, to optimize our internal booking processes. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools to the extent that you have given your consent. We would like to emphasize this point once again here.

Information on specific booking systems—if available—can be found in the following sections.

Miscellaneous: Introduction

Miscellaneous Privacy Policy Summary
👥 Data Subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Processed Data: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses and/or technical data. You can find more details in the documentation for each tool used.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) of the GDPR (Consent), Art. 6(1)(f) of the GDPR (Legitimate Interests)

What falls under „Other“?

The „Other“ category includes services that do not fit into any of the categories listed above. These are generally various plugins and embedded elements that enhance our website. These features are generally sourced from third-party providers and integrated into our website. Examples include web search services such as Algolia Place, Giphy, and Programmable Search Engine, as well as online services for weather data such as OpenWeather.

Why do we use other third-party providers?

With our website, we aim to offer you the best online experience in our industry. A website has long since ceased to be merely a business card for companies. Rather, it is a place designed to help you find what you’re looking for. To ensure our website remains as interesting and helpful as possible for you, we use various third-party services.

What data is processed?

Whenever elements are integrated into our website, your IP address is transmitted to the respective provider, stored, and processed there. This is necessary because otherwise the content would not be sent to your browser and, consequently, would not be displayed properly. Service providers may also use pixel tags or web beacons. These are small graphics on websites that can record a log file and generate analyses of that file. Providers can use the information obtained to improve their own marketing efforts. In addition to pixel tags, such information (such as which button you click or when you visit a particular page) can also be stored in cookies. These cookies may contain not only analytics data regarding your web behavior but also technical information such as your browser type or operating system. Some providers may also link the collected data to other internal services or to third-party providers. Each provider handles your data differently. Therefore, we recommend that you carefully read the privacy policies of the respective services. As a general rule, we strive to use only services that take data protection very seriously.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products.

Legal Basis

If we ask for your consent and you agree to allow us to use the service, this serves as the legal basis for the processing of your data (Art. 6(1)(a) GDPR).  In addition to your consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools to the extent that you have given your consent.

Information about the specific tools—if available—can be found in the following sections.

Explanation of Terms Used

We always strive to make our privacy policy as clear and understandable as possible. However, this isn’t always easy, especially when it comes to technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or certain technical terms (such as “cookies” or “IP address”). However, we do not want to use these terms without explanation. Below, you will find an alphabetical list of important terms we use that we may not have addressed sufficiently in the privacy policy so far. If these terms are taken from the GDPR and are definitions, we will also cite the relevant GDPR text here and, where appropriate, add our own explanations.

Closing Remarks

Congratulations! If you’re reading this, you’ve either really „battled your way through“ our entire Privacy Policy or at least scrolled down to this point. As you can see from the length of our Privacy Policy, we take the protection of your personal data very seriously.
It is important to us to inform you, to the best of our knowledge and belief, about the processing of personal data. In doing so, we want not only to tell you what data is processed, but also to explain the reasons for using various software programs. Privacy policies usually sound very technical and legalistic. However, since most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this isn’t always possible given the nature of the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the data controller. We hope you continue to enjoy your visit and look forward to welcoming you back to our website soon.

All texts are protected by copyright.

Cookie Consent with a Real Cookie Banner