Data Policy
Responsible Entity
Kompass Freytag & Berndt GmbH
Karl-Kapfererstraße 5
6020 Innsbruck
Austria
Authorized Representatives: Carl Rauch and Markus Schneider
Email Address: office[at]kompass-fb.com
Legal Notice: https://www.kompass-fb-com/legal-notice
Contact Data Protection Officer
datenschutz[at]kompass-fb.com
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Inventory data (e.g., master data).
- Employee data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication, and procedural data.
- Event data (Facebook).
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Prospective customers (interested parties).
- Communication partners.
- Users.
- Sweepstakes and contest participants.
- Business and contractual partners.
- Participants.
- Third parties.
- Customers.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement (audience measurement).
- Tracking.
- Office and organizational procedures.
- Conversion tracking (conversion measurement).
- Click tracking.
- Target group formation (targeting).
- Affiliate tracking.
- Organizational and administrative procedures.
- Conducting sweepstakes and contests.
- Feedback.
- Surveys and questionnaires.
- Marketing.
- Profiles with user-related information.
- Registration procedures.
- Provision of our online services and user-friendliness.
- Information technology infrastructure (IT infrastructure).
- Financial and payment management.
- Public relations.
- Sales promotion.
- Business processes and commercial operations.
Relevant Legal Bases
Applicable legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Furthermore, should more specific legal bases be applicable in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1) sentence 1 lit. a GDPR) - The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1) sentence 1 lit. c GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National Data Protection Regulations in Austria
In addition to the data protection regulations of the GDPR, national data protection provisions apply in Austria. This includes, in particular, the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG / Datenschutzgesetz). The Data Protection Act contains, among other things, special regulations on the right to access, the right to rectification or erasure, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated individual decision-making.
Relevant Legal Bases under the Swiss Data Protection Act
If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (short: "Swiss DPA" or "Swiss DSG"). Unlike the GDPR, for example, the Swiss DPA does not generally require that a legal basis be stated for the processing of personal data, and provides that the processing of personal data must be carried out in good faith and must be lawful and proportionate (Art. 6(1) and (2) of the Swiss DPA). In addition, personal data is only collected by us for a specific purpose that is recognizable to the data subject and is only processed in a manner compatible with this purpose (Art. 6(3) of the Swiss DPA).
Notice on the Applicability of the GDPR and the Swiss DPA
This privacy policy serves to provide information under both the Swiss DPA and the General Data Protection Regulation (GDPR). For this reason, please note that, due to its broader geographic scope of application and general comprehensibility, the terminology of the GDPR is used.
Specifically, instead of the terms "processing" (Bearbeitung) of "personal data" (Personendaten), "overriding interest" (überwiegendes Interesse), and "sensitive personal data" (besonders schützenswerte Personendaten) used in the Swiss DPA, the terms "processing" (Verarbeitung) of "personal data" (personenbezogene Daten), "legitimate interest" (berechtigtes Interesse), and "special categories of data" (besondere Kategorien von Daten) as used in the GDPR are applied. However, within the scope of application of the Swiss DPA, the legal meaning of these terms will continue to be determined in accordance with the Swiss DPA.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
Scope of Measures
These measures include, in particular:
- Data Protection & Control: Safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as system access, input, disclosure, availability assurance, and data segregation.
- Operational Procedures: We have established procedures to ensure the exercise of data subject rights, the deletion of data, and rapid responses to threats to data security.
- By Design and By Default: We take the protection of personal data into account as early as the development or selection of hardware, software, and processing methods, in accordance with the principles of data protection by design and by default.
Securing Online Connections via TLS/SSL Encryption Technology (HTTPS)
To protect user data transmitted through our online services from unauthorized access, we utilize TLS/SSL encryption technology.
- The Foundation: Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet.
- How it Works: These technologies encrypt the information transmitted between our website or app and the user's browser (or between two servers), thereby safeguarding the data from unauthorized access.
- Advanced Standards: TLS, as the more advanced and secure successor to SSL, ensures that all data transmissions meet the highest security standards.
- Visual Indicator: When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS appearing in the URL. This serves as a clear indicator to users that their data is being transmitted securely and in an encrypted format.
Transfer of Personal Data
In the context of our processing of personal data, it may happen that this data is transferred to other bodies, companies, legally independent organizational units, or individuals, or disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data designed to protect your data.
Data transfer within the group of companies:
We may transfer personal data to other companies within our group of companies or grant them access to it. This data disclosure is based on our legitimate corporate and business interests. These include, for example:
- The improvement of business processes
- Ensuring efficient and effective internal communication
- The optimal use of our human and technological resources
- The ability to make well-founded business decisions
In certain cases, the disclosure of data may also be necessary to fulfill our contractual obligations, or it may be based on the consent of the data subjects or a statutory permission.
International Data Transfers
Data processing in third countries:
If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies, or companies (which becomes recognizable from the postal address of the respective provider or if this privacy policy explicitly refers to data transfer to third countries), this always takes place in accordance with legal requirements.
Data Transfers to the USA (EU Context)
- Primary Safeguard (DPF): For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated July 10, 2023.
- Secondary Safeguard (SCCs): In addition, we have concluded Standard Contractual Clauses (SCCs) with the respective providers, which comply with the specifications of the EU Commission and establish contractual obligations to protect your data.
Dual Protection Principle: This two-tier safeguard ensures comprehensive protection of your data. The DPF forms the primary level of protection, while the Standard Contractual Clauses serve as an additional safety net. Should any changes occur regarding the DPF, the Standard Contractual Clauses will act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of political or legal changes.
In the descriptions of the individual service providers, we will inform you whether they are certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at: https://www.dataprivacyframework.gov/.
Data Transfers to Other Third Countries (EU Context)
For data transfers to other third countries, appropriate security measures apply, in particular Standard Contractual Clauses, explicit consent, or legally required transfers. You can find information on third-country transfers and applicable adequacy decisions on the European Commission's information page: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Disclosure of Personal Data Abroad (Swiss Context)
In accordance with the Swiss DPA, we only disclose personal data abroad if an adequate level of protection for the data subjects is guaranteed (Art. 16 Swiss DPA). If the Federal Council has not determined an adequate level of protection (List: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.
- Primary Safeguard (Swiss-U.S. DPF): For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of Switzerland dated June 7, 2024.
- Secondary Safeguard: In addition, we have concluded standard data protection clauses with the respective providers, which have been approved by the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) and establish contractual obligations to protect your data.
Dual Protection Principle (Switzerland): This two-tier safeguard ensures comprehensive protection of your data. The DPF forms the primary level of protection, while the standard data protection clauses serve as an additional safety net. Should any changes occur regarding the DPF, the standard data protection clauses will act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of political or legal changes.
In the descriptions of the individual service providers, we will inform you whether they are certified under the DPF and whether standard data protection clauses are in place. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at: https://www.dataprivacyframework.gov/.
For data transfers to other third countries, appropriate security measures apply, including international treaties, specific guarantees, standard data protection clauses approved by the FDPIC, or binding corporate rules recognized in advance by the FDPIC or a competent data protection authority of another country.
General Information on Data Storage and Erasure
We erase personal data that we process in accordance with statutory provisions as soon as the underlying consent is withdrawn or no other legal bases for processing exist. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule exist if statutory obligations or specific interests require a longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person, must be archived accordingly.
Our privacy policy contains additional information on the retention and erasure of data that applies specifically to certain processing operations.
If multiple retention periods or erasure deadlines apply to a single data point, the longest period is always decisive. Data that is no longer retained for its original purpose, but rather due to legal requirements or other reasons, will be processed by us solely for the reasons that justify its retention.
Retention and Erasure of Data: Austrian Law
The following general retention and archiving periods apply under Austrian law:
- 10 Years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers, and invoices, as well as all necessary work instructions and other organizational documents (Austrian Federal Fiscal Code (Bundesabgabenordnung – BAO § 132), Austrian Commercial Code (Unternehmensgesetzbuch – UGB §§ 190–212)).
- 6 Years – Other business documents: Received commercial or business letters, copies of sent commercial or business letters, and other documents, provided they are relevant for tax purposes. This includes, for example, hourly wage slips, cost accounting sheets, calculation documents, price tags, and payroll records, unless they already constitute accounting vouchers or cash register tapes (Austrian Federal Fiscal Code (BAO § 132), Austrian Commercial Code (UGB §§ 190–212)).
- 3 Years – Data required to address potential warranty and damage claims or similar contractual claims and rights, as well as to process related inquiries based on past business experience and standard industry practices, will be stored for the duration of the regular statutory limitation period of three years (§§ 1478, 1480 Austrian General Civil Code (Allgemeines Bürgerliches Gesetzbuch – ABGB)).
Retention and Erasure of Data: Swiss Law
The following general retention and archiving periods apply under Swiss law:
- 10 Years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers, and invoices, as well as all necessary work instructions and other organizational documents (Art. 958f of the Swiss Code of Obligations (Obligationenrecht – OR)).
- 10 Years (with exceptions) – Data necessary to address potential damage claims or similar contractual claims and rights, as well as to process related inquiries based on past business experience and standard industry practices, will be stored for the duration of the statutory limitation period of ten years, unless a shorter period of five years applies, which is relevant in certain cases (Art. 127, 130 OR).
Note on the 5-year limit: Claims expire after five years for rent, lease payments, capital interest, and other periodic payments; for the delivery of food, boarding, and tavern debts; and for manual work, retail sale of goods, medical treatment, professional work of attorneys, legal agents, proxies, and notaries, as well as from employment relationships of employees (Art. 128 OR).
Commencement of Period at the End of the Year
If a retention period does not explicitly start on a specific date and is at least one year long, it starts automatically at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships under which data is stored, the triggering event is the date on which the termination or other expiration of the legal relationship becomes effective.
Rights of the Data Subjects
Rights of Data Subjects under the GDPR
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to Object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions.Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right to Withdraw Consent: You have the right to withdraw any consent given at any time.
- Right of Access: You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and further information as well as a copy of the data in accordance with statutory requirements.
- Right to Rectification: In accordance with statutory requirements, you have the right to obtain the completion of incomplete data or the rectification of inaccurate personal data concerning you.
- Right to Erasure and Restriction of Processing: In accordance with statutory requirements, you have the right to demand that data concerning you be erased without undue delay, or, alternatively, to demand the restriction of processing of the data in accordance with statutory requirements.
- Right to Data Portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, or to demand its transmission to another controller in accordance with statutory requirements.
- Right to Lodge a Complaint with a Supervisory Authority: In accordance with statutory requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority—in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement—if you consider that the processing of personal data relating to you infringes the GDPR.
Rights of Data Subjects under the Swiss DPA
As a data subject, you are entitled to the following rights in accordance with the provisions of the Swiss DPA (Federal Act on Data Protection):
- Right of Access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to obtain the information necessary for you to assert your rights under this Act and to ensure transparent data processing.
- Right to Data Portability / Delivery: You have the right to request the delivery of your personal data that you have disclosed to us in a commonly used electronic format.
- Right to Rectification: You have the right to request the rectification of inaccurate personal data concerning you.
- Right to Object, Erasure, and Destruction: You have the right to object to the processing of your data and to demand that the personal data concerning you be erased or destroyed.
Business Services
We process the data of our contractual and business partners, e.g., customers and interested parties (collectively referred to as "contractual partners"), within the framework of contractual and comparable legal relationships, as well as associated measures, and with regard to communication with these contractual partners (including pre-contractually), such as to respond to inquiries.
We use this data to fulfill our contractual obligations. This includes, in particular, the obligation to provide the agreed services, any updating obligations, and remedies in the event of warranty and other performance defects. In addition, we use the data to safeguard our rights and for the purpose of administrative tasks associated with these obligations, as well as for company organization.
Furthermore, we process the data on the basis of our legitimate interests in both proper and economic business management and in security measures to protect our contractual partners and our business operations from misuse and the compromise of their data, secrets, information, and rights (e.g., for the involvement of telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Within the scope of applicable law, we only transfer the data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about other forms of processing, for example for marketing purposes, within this privacy policy.
We inform our contractual partners of which data is required for the aforementioned purposes before or during data collection—for example in online forms by means of special marking (e.g., colors) or symbols (e.g., asterisks or similar), or in person.
We erase the data after the expiration of statutory warranty and comparable obligations (i.e., generally after four years), unless the data is stored in a customer account, or for as long as it must be retained for statutory archiving reasons (such as for tax purposes, which is generally ten years). Data disclosed to us by the contractual partner as part of an order will be erased in accordance with the specifications and generally after the completion of the order.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Payment data (e.g., bank details, invoices, payment history)
- Contact data (e.g., postal and email addresses, phone numbers)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Service recipients and clients; interested parties; business and contractual partners.
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; organizational and administrative procedures; business processes and commercial operations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legal obligation (Art. 6(1) sentence 1 lit. c GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Online Shop, Order Forms, E-Commerce, and Performance of Services:
We process our customers' data to enable them to select, purchase, or order the chosen products, goods, and associated services, as well as to pay for, receive, or execute them.
Insofar as necessary for the execution of an order, we utilize service providers (in particular postal, forwarding, and shipping companies) to carry out the delivery or execution for our customers. To process payment transactions, we use the services of banks and payment service providers.
The required information is marked as such during the ordering or comparable acquisition process and includes the information required for delivery, provision, and billing, as well as contact information to enable any necessary consultation.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Business Processes and Procedures
Personal data of service recipients and clients—including customers, clients, or in special cases, professional clients (e.g., of attorneys or tax advisors), patients, or business partners, as well as other third parties—are processed within the framework of contractual and comparable legal relationships and pre-contractual measures, such as the initiation of business relationships. This data processing supports and facilitates business operations in areas such as customer management, sales, payment transactions, accounting, and project management.
The collected data is used to fulfill contractual obligations and to make business processes efficient. This includes the processing of business transactions, customer relationship management, the optimization of sales strategies, and the safeguarding of internal accounting and financial processes. In addition, the data supports the safeguarding of the controller's rights and promotes administrative tasks as well as the organization of the company.
Personal data may be shared with third parties if this is necessary to fulfill the stated purposes or legal obligations. Upon expiration of statutory retention periods or when the purpose of processing no longer applies, the data will be erased. This also includes data that must be stored for a longer period due to tax and statutory obligations to provide proof.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Payment data (e.g., bank details, invoices, payment history)
- Contact data (e.g., postal and email addresses, phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Log data (e.g., log files regarding logins, data retrieval, or access times)
- Employee data (information regarding employees and other persons in an employment relation)
- Data Subjects: Service recipients and clients; interested parties; communication partners; business and contractual partners; customers; third parties; users (e.g., website visitors, users of online services); employees (e.g., staff, applicants, temporary staff, and other employees).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures; business processes and commercial operations; security measures; provision of our online offering and user-friendliness; communication; marketing; sales promotion; financial and payment management; IT infrastructure (operation and provision of information systems and technical equipment like computers, servers, etc.).
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Legal obligation (Art. 6(1) sentence 1 lit. c GDPR)
Further Information on Processing Operations, Procedures, and Services
Customer Management and Customer Relationship Management (CRM):
Procedures necessary within the framework of customer management and customer relationship management (CRM) (e.g., customer acquisition in compliance with data protection requirements, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with consideration for data protection, data management and analysis to support the customer relationship, management of CRM systems, secure account management, customer segmentation, and target group identification).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Contact Management and Maintenance:
Procedures necessary within the scope of organizing, maintaining, and securing contact information (e.g., the setup and maintenance of a central contact database, regular updates of contact information, monitoring data integrity, implementing data protection measures, ensuring access controls, performing backups and recovery of contact data, training employees in the effective use of contact management software, regularly reviewing communication history, and adjusting contact strategies).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Customer Account:
Customers can create an account within our online offering (e.g., customer or user account, or "customer account" for short). If the registration of a customer account is required, customers will be informed of this as well as of the details necessary for registration. Customer accounts are not public and cannot be indexed by search engines. As part of registration, as well as subsequent logins and uses of the customer account, we store customers' IP addresses along with the access times in order to prove registration and prevent any misuse of the customer account. If a customer account has been terminated, the data of the customer account will be erased after the termination date, unless it is retained for purposes other than provision in the customer account or must be kept for legal reasons (e.g., internal storage of customer data, order transactions, or invoices). It is the customer's responsibility to secure their data upon termination of the customer account.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Watchlist / Wishlist:
Customers can create a product/wishlist. In this case, the products are stored within the scope of fulfilling our contractual obligations until the account is deleted, unless the product list entries are removed by the customer or we explicitly inform the customer of differing storage periods.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
General Payment Transactions:
Procedures necessary when executing payment transactions, monitoring bank accounts, and controlling payment flows (e.g., creating and verifying bank transfers, processing direct debits, checking bank statements, monitoring incoming and outgoing payments, managing returned direct debits, account reconciliation, cash management).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Accounting, Accounts Payable, Accounts Receivable:
Procedures necessary for recording, processing, and controlling business transactions in accounts payable and accounts receivable (e.g., creating and checking incoming and outgoing invoices, monitoring and managing open items, executing payment transactions, managing dunning processes, reconciling accounts in relation to receivables and payables, accounts payable, and accounts receivable).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legal obligation (Art. 6(1) sentence 1 lit. c GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Financial Accounting and Taxation:
Procedures necessary for recording, managing, and controlling financially relevant business transactions, as well as for calculating, reporting, and paying taxes (e.g., account assignment and posting of business transactions, preparing quarterly and annual financial statements, executing payment transactions, managing dunning processes, reconciling accounts, tax advisory, preparing and submitting tax returns, tax management).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legal obligation (Art. 6(1) sentence 1 lit. c GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Procurement / Purchasing:
Procedures necessary for purchasing goods, raw materials, or services (e.g., supplier selection and evaluation, price negotiations, order placement and monitoring, checking and controlling deliveries, invoice verification, order management, inventory management, establishing and maintaining procurement policies).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Sales:
Procedures necessary for planning, executing, and controlling measures to market and sell products or services (e.g., customer acquisition, quotation creation and follow-up, order processing, customer consulting and support, sales promotion, product training, sales controlling and analysis, sales channel management).
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Marketing, Advertising, and Sales Promotion:
Procedures necessary within the framework of marketing, advertising, and sales promotion (e.g., market analysis and target group determination, development of marketing strategies, planning and executing advertising campaigns, designing and producing promotional materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programs, sales promotion measures, performance measurement and optimization of marketing activities, budget management, and cost control).
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Economic Analyses and Market Research:
To fulfill business purposes and to identify market trends and the wishes of contractual partners and users, the available data on business transactions, contracts, inquiries, etc., are analyzed. The group of data subjects may include contractual partners, interested parties, customers, visitors, and users of the controller's online offering. These analyses are conducted for the purposes of business evaluations, marketing, and market research (e.g., to identify customer groups with different characteristics). In doing so, profiles of registered users—including their details on the services they have used—will be taken into account, if available. The analyses serve the controller exclusively and are not disclosed externally, unless they are anonymous analyses with consolidated, i.e., anonymized values. In addition, the privacy of the users is respected; the data is processed for analysis purposes in a pseudonymized and, where feasible, anonymized manner (e.g., as consolidated data).
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Use of Online Platforms for Offering and Sales Purposes
We offer our services on online platforms operated by other service providers. In this context, the privacy policies of the respective platforms apply in addition to our privacy policy. This applies in particular with regard to the processing of payment transactions and the procedures used on the platforms for measuring reach and interest-based marketing.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Payment data (e.g., bank details, invoices, payment history)
- Contact data (e.g., postal and email addresses, phone numbers)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Service recipients and clients; business and contractual partners.
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; marketing; business processes and commercial operations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Libri: Online Shop and Order Processing:
Sale of goods via a subdomain operated by Libri. The processing of personal data in connection with orders, payments, and deliveries is carried out by Libri.
- Service Provider: Libri GmbH, Friedensallee 273, 22763 Hamburg, Germany
- Website: https://www.libri.de
- Privacy Policy: https://www.libri.de/de/datenschutz/
Payment Procedures
In the context of contractual and other legal relationships, on the basis of legal obligations, or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options. For this purpose, we utilize other service providers in addition to banks and credit institutions (collectively referred to as "payment service providers").
To ensure security in line with the state of the art, payment transactions are carried out exclusively via encrypted connections, safeguarding the entered data from unauthorized access during transmission.
Data Processing by Payment Service Providers
The data processed by the payment service providers includes master data (such as name and address), banking data (such as account numbers or credit card numbers), passwords, TANs, and checksums, as well as contractual, transaction total, and recipient-related information. This information is strictly required to execute the transactions.
However, the entered data is processed and stored solely by the payment service providers. This means:
- We do not receive any account- or credit-card-related information.
- We only receive confirmation of payment success or information indicating a failed payment transaction.
- Under certain circumstances, payment service providers may transmit data to credit bureaus for identity and creditworthiness checks.
For further details on this, please refer to the terms and conditions and privacy policies of the respective payment service providers. Payment transactions are subject to the terms and conditions and the privacy policies of the respective payment service providers, which can be accessed within their websites or transaction applications. We also refer to these for further information and to assert your rights of withdrawal, access, and other data subject rights.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Payment data (e.g., bank details, invoices, payment history)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Contact data (e.g., postal and email addresses, phone numbers)
- Data Subjects: Service recipients and clients; business and contractual partners; interested parties.
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; business processes and commercial operations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services:
- Apple Pay: Payment services (technical integration of online payment methods);
- Service Provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA;
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR);
- Website: https://www.apple.com/de/apple-pay/
- Privacy Policy: https://www.apple.com/legal/privacy/de-ww/
- Google Pay: Payment services (technical integration of online payment methods);
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR);
- Website: https://pay.google.com/intl/de_de/about/
- Privacy Policy: https://policies.google.com/privacy
- Stripe: Payment services (technical integration of online payment methods);
- Service Provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA;
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR);
- Website: https://stripe.comStripe: Payment services (technical integration of online payment methods);
- Privacy Policy: https://stripe.com/de/privacy
Provision of the Online Offering and Web Hosting
We process user data in order to make our online services available to them. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
Key Information on Data Processing
- Processed Data Types:
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Log data (e.g., log files regarding logins, data retrieval, or access times)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Data Subjects: Users (e.g., website visitors, users of online services); service recipients and clients.
- Purposes of Processing: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment like computers, servers, etc.); security measures; provision of contractual services and fulfillment of contractual obligations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures, and Services
Provision of the Online Offering on Rented Storage Space:
To provide our online offering, we use storage space, computing capacity, and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a "web hoster").
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Collection of Access Data and Log Files:
Access to our online offering is logged in the form of so-called "server log files". These server log files may include the address and name of the accessed web pages and files, date and time of access, volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider.
Server log files are used, on the one hand, for security purposes—such as preventing server overload (particularly in the event of abusive attacks, so-called DDoS attacks)—and, on the other hand, to ensure server capacity utilization and stability.
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
- Data Erasure: Log file information is stored for a maximum period of 30 days and is then deleted or anonymized. Data whose further retention is required for evidentiary purposes is excluded from erasure until final clarification of the respective incident.
Hetzner:
Services in the field of providing information technology infrastructure and associated services (e.g., storage space and/or computing capacities).
- Service Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.hetzner.com
- Privacy Policy: https://www.hetzner.com/de/rechtliches/datenschutz
- Data Processing Agreement: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/
Kinsta:
Services in the field of providing information technology infrastructure and associated services (e.g., storage space and/or computing capacities).
- Service Provider: Kinsta Inc., 8605 Santa Monica Blvd #92581, West Hollywood, CA 90069, USA
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://kinsta.com
- Privacy Policy: https://kinsta.com/de/legal/datenschutzpolitik/
- Data Processing Agreement: https://kinsta.com/legal/data-processing-addendum/
Venus:
Hosting and provision of tour data. Both our own tours and tours uploaded by users are stored, managed, and retrieved on the platform for display on the website. In this context, users' personal data is processed when tours are uploaded or retrieved.
- Service Provider: Venus AI GmbH & Co. KG, Elsa-Brändström-Str. 2, 94327 Bogen, Germany
- Website: https://www.venus.bayern/
- Privacy Policy: https://www.venus.bayern/datenschutz
Sentry:
Monitoring of system stability and detection of code errors. Information regarding the device or the time of the error is collected pseudonymously and subsequently deleted.
- Service Provider: Functional Software Inc., Sentry, 132 Hawthorne Street, San Francisco, California 94107, USA
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://sentry.io
- Security Measures: IP masking (pseudonymization of the IP address)
- Privacy Policy: https://sentry.io/privacy/
- Data Processing Agreement: https://sentry.io/legal/dpa/
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://sentry.io/legal/dpa/ ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
Use of HubSpot
We use HubSpot for our online marketing activities, customer relationship management (CRM), and contact forms. The provider is the US company HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 USA (as well as HubSpot Ireland Ltd., 1 Sir John Rogerson’s Quay, Dublin 2, Ireland).
HubSpot is certified under the EU-U.S. Data Privacy Framework. This ensures an adequate level of data protection. In addition, we have concluded a Data Processing Agreement (DPA) with HubSpot in accordance with Art. 28 GDPR.
When you visit our website or enter form data (e.g., your name and email address), this data is processed on HubSpot's servers. Usage information, IP addresses, and device data may also be collected in the process.
Processing is based on your consent (Art. 6(1) lit. a GDPR) or for the implementation of pre-contractual measures and our legitimate interest in efficient customer management (Art. 6(1) lit. f GDPR). You can withdraw your consent at any time.
Further information on HubSpot's data protection can be found in the HubSpot Privacy Policy.
Use of Cookies
The term "cookies" refers to functions that store and read information on users' end devices. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings, as well as creating analyses of visitor flows.
We use cookies in accordance with statutory regulations. For this purpose, we obtain prior consent from users where required. If consent is not necessary, we rely on our legitimate interests. This applies when storing and reading information is strictly necessary in order to provide explicitly requested content and functions. This includes, for example, saving user settings as well as ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information on its scope and which cookies are used.
Information on Legal Bases: Whether we process personal data using cookies depends on consent. If consent has been granted, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage Duration: With regard to storage duration, a distinction is made between the following types of cookies:
- Temporary Cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their end device (e.g., browser or mobile application).
- Permanent Cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved and preferred content can be displayed directly when the user visits a website again. Likewise, user data collected via cookies can be used to measure reach. Unless we provide users with explicit information on the type and storage duration of cookies (e.g., when obtaining consent), users should assume that they are permanent and that the storage duration can be up to two years.
General Notes on Withdrawal and Objection (Opt-Out): Users can withdraw any consent they have given at any time and also object to processing in accordance with statutory requirements, including via the privacy settings of their browser.
Key Information on Data Processing
- Processed Data Types: Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data Subjects: Users (e.g., website visitors, users of online services).
- Legal Bases:
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
Further Information on Processing Operations, Procedures, and Services
Processing Cookie Data Based on Consent:
We use a consent management solution to obtain user consent for the use of cookies or the procedures and providers mentioned within the consent management solution. This procedure serves to obtain, log, manage, and withdraw consents, particularly regarding the use of cookies and similar technologies employed to store, read, and process information on users' end devices.
As part of this process, user consents for the use of cookies and the associated processing of information—including the specific processing operations and providers mentioned in the consent management procedure—are obtained. Users also have the option to manage and withdraw their consent at any time.
The consent declarations are stored to avoid asking again and to be able to provide proof of consent in accordance with legal requirements. Storage takes place server-side and/or in a cookie (a so-called "opt-in cookie") or by means of comparable technologies in order to assign the consent to a specific user or their device.
Unless specific details regarding providers of consent management services are provided, the following general notices apply:
- Storage Duration: The storage duration of the consent is up to two years.
- Stored Data: A pseudonymous user identifier is created, which is stored together with the timestamp of consent, information on the scope of consent (e.g., relevant categories of cookies and/or service providers), as well as information about the browser, system, and end device used.
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR).
Use of the HubSpot Cookie Consent Banner
We use the integrated consent management tool (cookie banner) provided by HubSpot on our website. This tool enables us to obtain, manage, and document in a legally compliant manner the consent required by law from users for the placement of cookies and the tracking of user activities.
When you access our website, the tool establishes a connection to HubSpot's servers. In doing so, a technically necessary cookie is stored in your browser to document the consents you have granted or denied for this website and to assign them during subsequent page visits. No evaluation of your browsing behavior takes place merely for the purpose of storing your consent.
The processing of this data is carried out to fulfill our legal obligation to obtain consent in accordance with Art. 6(1) lit. c GDPR.
You can change your cookie settings and any consents granted at any time, or withdraw them with effect for the future, via the cookie settings link or button provided on our website.
Data Processing in the Context of the Application (App)
We process the data of the users of our application insofar as this is necessary to provide users with the application and its functionalities, monitor its security, and further develop it. Furthermore, we may contact users in compliance with statutory provisions if communication is required for the purposes of administration or the use of the application. In all other respects, with regard to the processing of user data, we refer to the data protection notices in this privacy policy.
Legal Bases: The processing of data required to provide the functionalities of the application serves to fulfill contractual obligations. This also applies if the provision of functions requires authorization from the user (e.g., granting permissions for device functions). If the processing of data is not required for the provision of the functionalities of the application, but serves the security of the application or our business interests (e.g., collection of data for optimization or security purposes), it is based on our legitimate interests. If users are explicitly asked for their consent to the processing of their data, the processing of the data covered by the consent is based on consent.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Payment data (e.g., bank details, invoices, payment history)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Location data (information on the geographical position of a device or a person)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Commercial Use:
We process the data of the users of our application, registered users, and any test users (hereinafter uniformly referred to as "users") in order to provide our contractual services to them and, on the basis of legitimate interests, to ensure the security of our application and further develop it. The required information is marked as such in the context of entering into a usage, service, order, or comparable contract and may include details required for performance and billing, as well as contact information for any necessary consultations.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Processing of Location Data:
In the context of using our application, location data collected by the device used or otherwise entered by users is processed. The use of location data requires permission from the user, which can be revoked at any time. The use of location data serves solely to provide the respective functionality of our application in accordance with its description to users or its typical and expected mode of operation.
No Location History and No Motion Profiles:
Location data is used only selectively and is not processed to create a location history or motion profile of the devices used or their users.
Obtaining Applications via App Stores
Our application is obtained via special online platforms operated by other service providers (so-called "app stores"). In this context, the privacy policies of the respective app stores apply in addition to our privacy policy. This applies in particular with regard to the procedures used on the platforms for measuring reach and interest-based marketing, as well as any applicable fees.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Payment data (e.g., bank details, invoices, payment history)
- Contact data (e.g., postal and email addresses or phone numbers)
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Service recipients and clients; users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures, and Services
Apple App Store:
App and software sales platform.
- Service Provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.apple.com/de/app-store/
- Privacy Policy: https://www.apple.com/legal/privacy/de-ww/
Google Play:
App and software sales platform.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://play.google.com/store/apps?hl=de
- Privacy Policy: https://policies.google.com/privacy
Registration, Login, and User Account
Users can create a user account. As part of the registration process, the required mandatory information is communicated to users and processed for the purpose of providing the user account on the basis of contractual fulfillment. The processed data includes, in particular, login information (username, password, and an email address).
When using our registration and login functions as well as the user account, we store the IP address and the timestamp of the respective user action. This storage is based on our legitimate interests as well as those of the users in protecting against misuse and other unauthorized use. In principle, this data is not transferred to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so.
Users may be informed by email about events relevant to their user account, such as technical changes.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses, phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Log data (e.g., log files regarding logins, data retrieval, or access times)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; organizational and administrative procedures; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Erasure upon termination.
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Registration with Pseudonyms:
Users are permitted to use pseudonyms as usernames instead of real names.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Erasure of Data After Termination:
If users have terminated their user account, their data with regard to the user account will be erased, subject to any statutory permission, obligation, or consent of the users.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Community Features
The community features provided by us allow users to engage in conversations or otherwise exchange information with one another. Please note that the use of community features is permitted only in compliance with applicable law, our terms and guidelines, and the rights of other users and third parties.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Adjusting Post Visibility:
Users can use settings to determine the extent to which posts and content created by them are visible or accessible to the public or only to specific persons or groups.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Data Storage for Security Purposes:
User posts and other inputs are processed for the purposes of community and conversation features and, subject to legal obligations or statutory permission, will not be disclosed to third parties. An obligation to disclose data may arise, in particular, in the case of unlawful posts for the purpose of legal prosecution. Please note that, in addition to the content of the posts, the timestamp and the user's IP address are also stored. This is done in order to take appropriate measures to protect other users and the community.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Right to Delete Content and Information:
The deletion of user posts, content, or information is permissible to the necessary extent following an appropriate assessment, provided there are specific indications that they constitute a violation of statutory rules, our guidelines, or the rights of third parties.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR).
Single Sign-On Login (SSO)
"Single Sign-On" or "Single Sign-On login" / "authentication" refers to procedures that allow users to log in to our online offering using a user account with a Single Sign-On provider (e.g., a social network). The prerequisite for Single Sign-On authentication is that users are registered with the respective Single Sign-On provider and enter the required credentials in the designated online form, or are already logged in with the Single Sign-On provider and confirm the Single Sign-On login via a button.
Authentication takes place directly with the respective Single Sign-On provider. As part of such authentication, we receive a user ID with the information that the user is logged in under this user ID with the respective Single Sign-On provider, as well as an ID that is unusable for us for other purposes (a so-called "user handle"). Whether additional data is transmitted to us depends solely on the Single Sign-On procedure used, the data sharing permissions selected during authentication, and which data users have released in the privacy or other settings of their user account with the Single Sign-On provider. Depending on the Single Sign-On provider and the user's choices, this data may vary, but typically includes the email address and username. The password entered at the Single Sign-On provider as part of the Single Sign-On procedure is neither visible to us nor stored by us.
Users are asked to note that their details stored with us can automatically be matched with their user account with the Single Sign-On provider; however, this is not always possible or actually done. For example, if users change their email address, they must manually update it in their user account with us.
If agreed with users, we may use Single Sign-On login as part of or prior to contract performance, process it on the basis of consent where users were asked for it, and otherwise use it on the basis of our legitimate interests and the interests of users in an effective and secure login system.
Should users decide at any time that they no longer wish to use the link between their user account with the Single Sign-On provider for the Single Sign-On procedure, they must remove this connection within their user account with the Single Sign-On provider. If users wish to delete their data stored with us, they must cancel their registration with us.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses, phone numbers)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Event data (Facebook) ("Event data" refers to information sent to the provider Meta—for example via Meta Pixel, whether via apps or other channels—that relates to individuals or their actions. This data includes, for instance, details on website visits, interactions with content and features, app installations, and product purchases. The processing of event data is aimed at creating target groups for content and promotional messages (Custom Audiences). It is important to note that event data does not include actual content such as written comments, login information, or contact details like names, email addresses, or phone numbers. "Event data" is erased by Meta after a maximum of two years, and the target groups created from it disappear upon the deletion of our Meta user accounts.)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures; login procedures; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Erasure upon termination.
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
- Apple Single Sign-On: Authentication services for user logins, provision of Single Sign-On functionality, management of identity information, and application integrations;
- Service Provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA;
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
- Website: https://www.apple.com/de/ ;
- Privacy Policy: https://www.apple.com/legal/privacy/de-ww/ .
- Facebook Single Sign-On: Authentication service of the Facebook platform;
- Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
- Website: https://www.facebook.com ;
- Privacy Policy: https://www.facebook.com/privacy/policy/ ;
- Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing ;
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- ).
- Google Single Sign-On: Authentication services for user logins, provision of Single Sign-On functionality, management of identity information, and application integrations;
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
- Website: https://www.google.de ;
- Privacy Policy: https://policies.google.com/privacy ;
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF);
- Opt-Out Option: Settings for the display of advertisements: https://myadcenter.google.com/ .
Contact and Inquiry Management
When contacting us (e.g., by mail, contact form, email, telephone, or via social media) as well as within the framework of existing user and business relationships, the details of the inquiring persons are processed to the extent necessary to respond to the contact inquiries and any requested measures.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses or phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Communication partners.
- Purposes of Processing: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via online form); provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
Further Information on Processing Operations, Procedures, and Services
Contact Form:
When contacting us via our contact form, by email, or other communication channels, we process the personal data transmitted to us to answer and process the respective request. As a rule, this includes details such as name, contact information, and, if applicable, further information communicated to us that is necessary for appropriate processing. We use this data exclusively for the specified purpose of contact and communication.
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Freshdesk:
Management of contact inquiries and communication.
- Service Provider: Freshworks, Inc., 2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, USA
- Legal Bases: Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.freshworks.com
- Privacy Policy: https://www.freshworks.com/privacy/
- Data Processing Agreement: https://www.freshworks.com/data-processing-addendum/
- Basis for Third-Country Transfers: EU/EEA - Standard Contractual Clauses (https://www.freshworks.com/data-processing-addendum/ ), Switzerland - Standard Contractual Clauses (
- ).
Push Notifications
With the user's consent, we can send users so-called "push notifications". These are messages displayed on users' screens, end devices, or in browsers, even when our online service is not currently actively in use.
To sign up for push notifications, users must confirm the prompt from their browser or end device regarding the receipt of push notifications. This consent process is documented and stored. Storage is necessary to recognize whether users have consented to receiving push notifications and to be able to prove consent. For these purposes, a pseudonymous browser identifier (a so-called "push token") or the device ID of an end device is stored.
Push notifications may, on the one hand, be required for the performance of contractual obligations (e.g., technical and organizational information relevant to the use of our online offering) and are otherwise sent on the basis of user consent, unless specifically mentioned below. Users can change or disable the receipt of push notifications at any time using the notification settings of their respective browsers or end devices.
Content: We automatically point out interesting places on the map to you. Only Pro users can change this setting.
Key Information on Data Processing
- Processed Data Types:
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Location data (information on the geographical position of a device or a person)
- Data Subjects: Communication partners.
- Purposes of Processing: Communication; provision of our online offering and user-friendliness.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Erasure upon termination.
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
Location-Dependent Sending of Push Notifications:
The push notifications sent by us can be displayed depending on the location of the user, based on the location data transmitted by the end device used.
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR).
Newsletters and Electronic Notifications
We send newsletters, emails, and other electronic notifications (hereinafter "newsletters") exclusively with the consent of the recipients or on a legal basis. Insofar as the contents of the newsletter are specified in the context of registering for the newsletter, these contents are decisive for the consent of the users. Normally, providing your email address is sufficient to register for our newsletter. However, in order to offer you a personalized service, we may ask you to provide your name for a personal salutation in the newsletter, or further information if this is necessary for the purpose of the newsletter.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to prove consent that was previously given. The processing of this data is restricted to the purpose of a potential defense against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address in a blocklist solely for this purpose.
The logging of the registration process takes place on the basis of our legitimate interests for the purpose of proving that it was conducted properly. Insofar as we commission a service provider with the sending of emails, this is done on the basis of our legitimate interests in an efficient and secure dispatch system.
Content: The KOMPASS newsletter informs subscribers about inspiring tour suggestions, exciting travel reports, news about KOMPASS products, and competitions related to the outdoor topic. The newsletter is sent on average once or twice a month and can be unsubscribed at any time with just one click.
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses, phone numbers)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Data Subjects: Communication partners.
- Purposes of Processing: Direct marketing (e.g., via email or post).
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Option to Object (Opt-Out): You can cancel the receipt of our newsletter at any time, i.e., withdraw your consent or object to further receipt. You can find a link to cancel the newsletter either at the end of each newsletter or use one of the contact options specified above, preferably email.
Further Information on Processing Operations, Procedures, and Services
Measurement of Open and Click Rates:
The newsletters contain a so-called "web beacon", i.e., a pixel-sized file retrieved from our server (or the server of our email service provider, if utilized) when the newsletter is opened. As part of this retrieval, technical information such as details about your browser and system, as well as your IP address and the timestamp of retrieval, are initially collected.
This information is used for the technical improvement of our newsletter based on technical data or target audiences and their reading behavior, using their retrieval locations (which can be determined via the IP address) or access times. This analysis also includes determining whether and when newsletters are opened and which links are clicked. This information is assigned to individual newsletter recipients and stored in their profiles until deletion. The evaluations serve to recognize the reading habits of our users and adapt our content to them or send different content in accordance with the interests of our users.
The measurement of open and click rates, the storage of measurement results in user profiles, and their further processing take place on the basis of user consent. A separate withdrawal of performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be canceled or objected to. In that case, the stored profile information will be erased.
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR).
Newsletter Dispatch via HubSpot
For the dispatch of our newsletters, we use the services of HubSpot (HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA). HubSpot is an integrated software solution that we use to organize, among other things, our customer relationship management (CRM) and email marketing. [1, 2, 3]
When you sign up for our newsletter, the data you enter (e.g., email address, name) is processed on HubSpot's servers. Our newsletters contain so-called web beacons (tracking pixels). When opening the newsletter, technical information (e.g., browser, IP address) as well as usage data (e.g., clicks on links) are recorded. These analyses serve to understand the reading habits of our users and to optimally adapt the content.
- Legal Basis: The processing of your data and the performance measurement take place exclusively on the basis of your explicit consent pursuant to Art. 6(1) lit. a GDPR (and § 25(1) TDDDG for the placement of the tracking pixel).
- Third-Country Transfer: Data transfer to the USA is legally safeguarded by the EU-U.S. Data Privacy Framework (DPF) and additionally through the conclusion of EU Standard Contractual Clauses (SCCs).
- Withdrawal of Consent: You can withdraw your consent to receive the newsletter and to performance measurement at any time with effect for the future. To do so, please use the unsubscribe link at the end of each newsletter.
Competitions and Contests
We process the personal data of participants in competitions and contests only in compliance with the relevant data protection regulations, insofar as the processing is contractually necessary for the provision, execution, and handling of the competition, participants have consented to the processing, or processing serves our legitimate interests (e.g., in the security of the competition or protecting our interests against misuse, such as by recording IP addresses when competition entries are submitted).
If participants' entries are published as part of the competition (e.g., in the context of voting, presenting competition entries or winners, or reporting on the competition), we point out that participants' names may also be published in this context. Participants may object to this at any time.
If the competition takes place within an online platform or social network (e.g., Facebook or Instagram, hereinafter referred to as "online platform"), the terms of use and privacy policies of the respective platforms apply in addition. In these cases, we point out that we are responsible for the participant details provided in the context of the competition and that inquiries regarding the competition should be addressed to us.
Participants' data will be erased as soon as the competition or contest has ended and the data is no longer required to inform the winners or because inquiries regarding the competition are no longer to be expected. In principle, participants' data will be erased no later than 6 months after the end of the competition. Winners' data may be retained longer, for example to answer inquiries regarding the prizes or to fulfill prize obligations; in this case, the retention period depends on the nature of the prize and, for example in the case of physical items or services, can be up to three years in order to handle warranty claims. Furthermore, participant data may be stored longer, for example in the form of reporting on the competition in online and offline media.
If data was also collected for other purposes within the scope of the competition, its processing and retention period are governed by the privacy notices for that specific use (e.g., in the case of subscribing to a newsletter within the framework of a competition).
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses, phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Data Subjects: Competition and contest participants.
- Purposes of Processing: Conducting competitions and contests.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Performance of a contract and prior contract inquiries (Art. 6(1) sentence 1 lit. b GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Surveys and Questionnaires
We conduct surveys and questionnaires in order to collect information for the respective communicated survey or questionnaire purpose. The surveys and questionnaires conducted by us (hereinafter "surveys") are evaluated anonymously. Personal data is processed only to the extent necessary to provide and technically execute the surveys (e.g., processing the IP address to display the survey in the user's browser or using a cookie to enable resuming the survey).
Key Information on Data Processing
- Processed Data Types:
- Master data (e.g., full name, residential address, contact information, customer number, etc.)
- Contact data (e.g., postal and email addresses, phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Data Subjects: Participants.
- Purposes of Processing: Feedback (e.g., collecting feedback via online form); surveys and questionnaires (e.g., surveys with input options, multiple-choice questions).
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures, and Services
Google Forms:
Creation and evaluation of online forms, surveys, feedback questionnaires, etc.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.google.de/intl/de/forms
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- ).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as "reach measurement") serves to evaluate visitor flows to our online offering and can include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offering or its features or content are used most frequently, or encourage return visits. Likewise, it enables us to understand which areas require optimization.
In addition to web analytics, we can also use testing procedures, for example, to test and optimize different versions of our online offering or its components.
Unless stated otherwise below, profiles (i.e., data summarized for a usage session) can be created for these purposes, and information can be stored in a browser or on an end device and subsequently read out. The information collected includes, in particular, visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. If users have consented to the collection of their location data to us or to the providers of the services we use, the processing of location data is also possible.
Furthermore, the IP addresses of users are stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. In general, no clear data of users (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimization, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.
Information on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Key Information on Data Processing
- Processed Data Types:
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Reach measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles); provision of our online offering and user-friendliness; security measures; IT infrastructure (operation and provision of information systems and technical equipment like computers, servers, etc.).
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless stated otherwise, cookies and similar storage methods can be stored on users' devices for a period of two years.).
- Security Measures: IP masking (pseudonymization of the IP address).
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
- Firebase: Google Firebase is a platform for developers of applications (short: "apps") for mobile devices and websites. Google Firebase offers a variety of functions for testing apps, monitoring their functionality, and optimizing them (displayed on the following overview page: https://firebase.google.com/products-build ).
These functions include, among other things, the storage of apps including personal data of application users, such as content created by them or information regarding their interaction with the apps (so-called "cloud computing"). Google Firebase also provides interfaces that allow interaction between app users and other services, e.g., authentication via services such as Facebook, Twitter, or an email-password combination.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://firebase.google.com
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- Google Analytics: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain unique data, such as names or email addresses. It serves to allocate analytical information to an end device in order to recognize which content users have accessed within one or several usage processes, which search terms they have used, whether they have re-visited them, or how they interacted with our online offering. Likewise, the time and duration of use are stored, as well as the sources referring users to our online offering and technical aspects of their end devices and browsers.In doing so, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides coarse geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before it is immediately erased. It is not logged, accessible, or used for any further purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before traffic is forwarded to Analytics servers for processing.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://marketingplatform.google.com/intl/de/about/analytics/
- Security Measures: IP masking (pseudonymization of the IP address)
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: https://business.safety.google/adsprocessorterms/
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- Opt-Out Option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de , Settings for the display of advertisements:
- )
- Further Information: https://business.safety.google/adsservices/ (Types of processing and data processed).
- Google as Recipient of Consent: The consent granted by users within the scope of a consent dialog (also known as "cookie opt-in/consent", "cookie banner", etc.) serves several purposes. Firstly, it serves us to fulfill our obligation to obtain consent for storing and reading information on and from users' end devices (in accordance with ePrivacy directives). Secondly, it covers the processing of users' personal data in accordance with data protection regulations. In addition, this consent also applies to Google, as the company is required under the Digital Markets Act to obtain consent for personalized services. Therefore, we share the status of user consents with Google. Our consent management software informs Google whether consent has been granted or not. The aim is to ensure that users' granted or denied consents are taken into account when using Google Analytics and when integrating functions and external services. In this way, user consents and their withdrawal within the context of Google Analytics and other Google services in our online offering can be adjusted dynamically depending on the user's choice.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://support.google.com/analytics/answer/9976101?hl=de
- Privacy Policy: https://policies.google.com/privacy
- Google Tag Manager: We use Google Tag Manager, a software provided by Google that allows us to centrally manage so-called website tags via a user interface. Tags are small code elements on our website designed to capture and analyze visitor activity. This technology supports us in improving our website and the content provided on it. Google Tag Manager itself does not create user profiles, store cookies with user profiles, or perform independent analyses. Its function is limited to simplifying and streamlining the integration and management of tools and services we use on our website. Nevertheless, when using Google Tag Manager, users' IP addresses are transmitted to Google, which is technically necessary to implement the services we use. Cookies may also be set in the process. However, this data processing only occurs if services are integrated via Tag Manager. For more detailed information on these services and their data processing, please refer to the relevant sections of this privacy policy.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://marketingplatform.google.com
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: https://business.safety.google/adsprocessorterms
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- ).
- plausible.io: Reach measurement and web analytics; no use of cookies or comparable persistent online identifiers; returning visitors are recognized using a pseudonymous identifier that is deleted after one day; no other personal data is stored (https://plausible.io/data-policy ); no data is passed on to third parties; processing takes place on the plausible.io server on the basis of a Data Processing Agreement.
- Service Provider: Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonia
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://plausible.io/
- Privacy Policy: https://plausible.io/privacy
- Data Processing Agreement: https://plausible.io/dpa
- Firebase Crashlytics: Collection and analysis of crash reports, real-time crash reporting for rapid troubleshooting, provision of detailed insights into the causes of app crashes, grouping of similar crashes for easier management and identification of critical issues, integration with other developer tools to optimize workflows. In the event of a crash, anonymous information is transmitted to Google's servers in the USA (state of the app at the time of the crash, installation UUID, crash trace, manufacturer and operating system of the end device, last log messages). This information contains no personal data. Crash reports are only sent with your explicit consent. When using iOS apps, you can grant consent in the app settings or after a crash. On Android apps, you have the option to generally consent to the transmission of crash reports to Google and app developers when setting up the mobile device.
- Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://firebase.google.com/products/crashlytics
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- ).
- ).
Online Marketing
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of promotional and other content (collectively referred to as "content") based on users' potential interests, as well as measuring its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (a so-called "cookie") or similar procedures are used, by means of which user information relevant to the display of the aforementioned content is saved. This may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical information such as the browser used, the computer system used, and information on usage times and features used. If users have consented to the collection of their location data, this data may also be processed.
In addition, user IP addresses are stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect users. In general, no clear data of users (such as email addresses or names) is stored as part of the online marketing process, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is generally stored in cookies or by means of similar procedures. These cookies can generally also be read out later on other websites that use the same online marketing procedure, analyzed for the purpose of displaying content, supplemented with further data, and stored on the server of the online marketing procedure provider.
In exceptional cases, clear data can be assigned to the profiles, primarily if, for example, users are members of a social network whose online marketing procedure we use and the network connects the user profiles with the aforementioned information. Please note that users can enter into additional agreements with the providers, for instance by giving consent during registration.
In principle, we only receive access to aggregated information regarding the success of our advertisements. However, in the context of so-called conversion measurements, we can examine which of our online marketing procedures led to a so-called conversion, i.e., for example, to the conclusion of a contract with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless stated otherwise, please assume that cookies used are stored for a period of two years.
Information on Legal Bases: If we ask users for their consent to the use of third-party providers, consent serves as the legal basis for data processing. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Notes on Withdrawal and Objection (Opt-Out):
We refer to the privacy policies of the respective providers and the objection options (so-called "opt-outs") specified for those providers. If no explicit opt-out option has been specified, you can, on the one hand, disable cookies in your browser settings. However, this may restrict the functionality of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for respective regions:
- a) Europe: https://www.youronlinechoices.eu
- b) Canada: https://youradchoices.ca/
- c) USA: https://optout.aboutads.info/
- d) Cross-regional: https://optout.aboutads.info
Key Information on Data Processing
- Processed Data Types:
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Event data (Facebook) ("Event data" refers to information sent to the provider Meta—for example via Meta Pixel, whether via apps or other channels—that relates to individuals or their actions. This data includes, for instance, details on website visits, interactions with content and features, app installations, and product purchases. The processing of event data is aimed at creating target groups for content and promotional messages (Custom Audiences). It is important to note that event data does not include actual content such as written comments, login information, or contact details like names, email addresses, or phone numbers. "Event data" is erased by Meta after a maximum of two years, and the target groups created from it disappear upon the deletion of our Meta user accounts.)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Reach measurement (e.g., access statistics, recognition of returning visitors); tracking (e.g., interest-/behavior-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); target group formation; marketing; profiles with user-related information (creation of user profiles); provision of our online offering and user-friendliness; click tracking.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless stated otherwise, cookies and similar storage methods can be stored on users' devices for a period of two years.).
- Security Measures: IP masking (pseudonymization of the IP address).
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
- Meta Pixel and Target Group Formation (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting event data or contact information via interfaces in apps), it is possible for Meta to determine the visitors to our online offering as a target group for the display of advertisements (so-called "Meta Ads"). Accordingly, we use the Meta Pixel to display the Meta Ads placed by us only to those users on Meta platforms and within the services of partners cooperating with Meta (so-called "Audience Network" https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who exhibit certain characteristics (e.g., interest in certain topics or products determined based on the websites visited) that we transmit to Meta (so-called "Custom Audiences"). With the help of the Meta Pixel, we also want to ensure that our Meta Ads correspond to the potential interest of users and do not have a harassing effect. Furthermore, with the help of the Meta Pixel, we can track the effectiveness of Meta Ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta Ad (so-called "conversion measurement").
- Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://www.facebook.com
- Privacy Policy: https://www.facebook.com/privacy/policy/
- Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- Further Information: User event data, i.e., behavior and interest details, are processed for the purposes of targeted advertising and target group formation on the basis of a joint controllership agreement ("Controller Addendum", https://www.facebook.com/legal/controller_addendum ). Joint responsibility is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing
- )
- al Clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Google Ads and Conversion Measurement: Online marketing procedures for the purpose of placing content and advertisements within the service provider's advertising network (e.g., in search results, in videos, on web pages, etc.) so that they are displayed to users who have a presumed interest in the ads. In addition, we measure the conversion of ads, i.e., whether users took them as an opportunity to interact with the ads and utilize the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR), Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://marketingplatform.google.com
- Privacy Policy: https://policies.google.com/privacy
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF)
- Further Information: Types of processing and processed data: https://business.safety.google/adsservices/ . Data processing terms between controllers and Standard Contractual Clauses for third-country data transfers:
- .
- Taboola: Provision of functions for displaying personalized advertising based on interest- and behavior-based information, which includes demographic characteristics, interests, and users' browsing history, stored in user profiles.
- Service Provider: Taboola, Inc. 16 Madison Square West 7th Floor New York, New York 10010, USA
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://www.taboola.com/de
- Privacy Policy: https://www.taboola.com/privacy-policy
- Data Processing Agreement: Provided by the service provider
- Basis for Third-Country Transfers: EU/EEA - Standard Contractual Clauses (Provided by the service provider), Switzerland - Standard Contractual Clauses (Provided by the service provider)
- Erasure of Data: Taboola stores user information collected directly for the purpose of serving ads for a maximum of eighteen (18) months following the user's last interaction with Taboola services, anonymizing it by removing personal identifiers or aggregating the data. Taboola stores anonymous or aggregated data that cannot identify an individual or device, used for reporting and analytics purposes, for as long as commercially necessary.
- Opt-Out Option: https://www.taboola.com/privacy-policy#user-choices-and-optout
- UTM Parameters: Analysis of sources and user actions based on extending web addresses referring to us with an additional parameter, the "UTM" parameter. For example, a UTM parameter
utm_source=platformX&utm_medium=videocan tell us that a person clicked the link on Platform X within a video. UTM parameters provide information about the source of the link, the medium used (e.g., social media, website, newsletter), the type of campaign, or the content of the campaign (e.g., post, link, image, and video). With the help of this information, we can, for example, check our online visibility or the effectiveness of our campaigns.- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
- Ströer: Provision of functions for displaying personalized advertising based on interest- and behavior-based information, which includes demographic characteristics, interests, and users' browsing history, stored in user profiles.
- Service Provider: Ströer Core GmbH & Co. KG, Marie-Curie-Straße 8, 51377 Leverkusen, Germany
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://www.stroeer.com/
- Privacy Policy: https://www.stroeer.de/datenschutz/
Affiliate Programs and Affiliate Links
In our online offering, we integrate so-called affiliate links or other references (which may include, for example, search masks, widgets, or discount codes) to the offers and services of third-party providers (collectively referred to as "affiliate links"). When users follow the affiliate links or subsequently take advantage of the offers, we may receive a commission or other benefits from these third-party providers (collectively referred to as "commission").
In order to track whether users have taken advantage of the offers of an affiliate link used by us, it is necessary for the respective third-party providers to learn that users have followed an affiliate link placed within our online offering. The attribution of affiliate links to respective business transactions or other actions (e.g., purchases) serves solely the purpose of commission accounting and is canceled as soon as it is no longer required for this purpose.
For the purpose of the aforementioned attribution of affiliate links, the affiliate links may be supplemented with certain values that are a component of the link or can be stored elsewhere, e.g., in a cookie. These values may include, in particular, the referring website (referrer), the timestamp, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer, and an online identifier of the user.
Information on Legal Bases: If we ask users for their consent to the use of third-party providers, consent serves as the legal basis for processing data. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Key Information on Data Processing
- Processed Data Types:
- Contractual data (e.g., subject matter of the contract, term, customer category)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Data Subjects: Interested parties; users (e.g., website visitors, users of online services).
- Purposes of Processing: Affiliate tracking.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
- Amazon Partner Program: Affiliate partner program (Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or one of its affiliates).
- Service Provider: Amazon EU S.à r.l. (Société à responsabilité limitée), 38 avenue John F. Kennedy, L-1855 Luxembourg
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.amazon.de
- Privacy Policy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF).
- AWIN Partner Program (formerly Zanox and Affilinet): Affiliate marketing partner program.
- Service Provider: AWIN AG, Eichhornstr. 3, 10785 Berlin, Germany
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.awin.com/de
- Privacy Policy: https://www.awin.com/de/rechtliches/privacy-policy-DACH
Social Media Presences
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.
We point out that user data may be processed outside the European Union in this context. This may create risks for users, for example because enforcing user rights could be rendered more difficult.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and resulting user interests. The latter may in turn be used, for instance, to display advertisements inside and outside the networks that presumably correspond to the interests of the users. For this purpose, cookies are generally stored on the users' computers, recording user behavior and interests. In addition, data independent of the devices used by users may also be stored in the usage profiles (especially if they are members of the respective platforms and logged into them).
For a detailed presentation of the respective processing operations and the options for objection (opt-out), we refer to the privacy policies and details provided by the operators of the respective networks.
In the event of requests for information and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the latter have access to user data in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you may contact us.
Key Information on Data Processing
- Processed Data Types:
- Contact data (e.g., postal and email addresses, phone numbers)
- Content data (e.g., text or image messages and contributions, as well as information concerning them, such as authorship details or creation timestamps)
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Communication; feedback (e.g., collecting feedback via online form); public relations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure".
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures, and Services
- Instagram: Social network, enables sharing of photos and videos, commenting and liking posts, sending messages, subscribing to profiles and pages.
- Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.instagram.com
- Privacy Policy: https://privacycenter.instagram.com/policy/
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF).
- Facebook Pages: Profiles within the social network Facebook. The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page ("Fanpage"). This includes, in particular, information about user behavior (e.g., content viewed or interacted with, actions taken) as well as device information (e.g., IP address, operating system, browser type, language settings, cookie data). Further details can be found in the Facebook Privacy Policy: https://www.facebook.com/privacy/policy/ .
Facebook also uses this data to provide us with statistical evaluations via the "Page Insights" service, which provide insight into how people interact with our page and its content. The basis for this is an agreement with Facebook ("Page Insights Controller Addendum": https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Users can therefore address requests for access or erasure directly to Facebook. User rights (in particular access, erasure, objection, complaint to a supervisory authority) remain unaffected by this. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for further processing, including possible transmission to Meta Platforms, Inc. in the USA.
- Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.facebook.com
- Privacy Policy: https://www.facebook.com/privacy/policy/
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- LinkedIn: Social network. We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of visitors used to create "Page Insights" (statistics) for our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as the actions they take. Details about the devices used are also recorded, such as IP addresses, operating system, browser type, language settings, and cookie data, as well as details from user profiles, such as job function, country, industry, hierarchy level, company size, and employment status. Privacy information on the processing of user data by LinkedIn can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy .
- ).
We have entered into a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum", https://legal.linkedin.com/pages-joint-controller-addendum), which specifically regulates which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill the rights of data subjects (i.e., users can, for example, address requests for access or erasure directly to LinkedIn). User rights (in particular the right to access, erasure, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company based in the EU. The further processing of the data is solely the responsibility of LinkedIn Ireland Unlimited Company, particularly regarding the transmission of data to the parent company LinkedIn Corporation in the USA.
- Service Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.linkedin.com
- Privacy Policy: https://www.linkedin.com/legal/privacy-policy
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa ), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (
- Opt-Out Option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
- Xing: Social network.
- Service Provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.xing.com/
- Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung
- )
Plugins and Embedded Functions as well as Content
We integrate functional and content elements into our online offering that are retrieved from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos, or maps (hereinafter uniformly referred to as "content").
This integration always requires that the third-party providers of this content process the IP address of the users, as they could not send the content to their browser without an IP address. The IP address is therefore required for the display of this content or functionality. We strive to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Through these "pixel tags," information such as visitor traffic on the pages of this website can be evaluated. Furthermore, the pseudonymous information may be stored in cookies on the user's device and may contain technical information regarding the browser and operating system, referring websites, time of visit, as well as other details on the use of our online offering, but can also be combined with such information from other sources.
Information on Legal Bases: If we ask users for their consent to the use of third-party providers, consent serves as the legal basis for data processing. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Key Information on Data Processing
- Processed Data Types:
- Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions)
- Metadata, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved)
- Location data (information on the geographical position of a device or a person)
- Data Subjects: Users (e.g., website visitors, users of online services).
- Purposes of Processing: Provision of our online offering and user-friendliness; reach measurement (e.g., access statistics, recognition of returning visitors); tracking (e.g., interest-/behavior-based profiling, use of cookies); target group formation; marketing; provision of contractual services and fulfillment of contractual obligations.
- Retention and Erasure: Erasure in accordance with the specifications in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless stated otherwise, cookies and similar storage methods can be stored on users' devices for a period of two years.).
- Legal Bases:
- Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
Further Information on Processing Operations, Procedures, and Services
- OpenStreetMap: We integrate the maps of the "OpenStreetMap" service, which are offered on the basis of the Open Data Commons Open Database License (ODbL) by the OpenStreetMap Foundation (OSMF). User data is used by OpenStreetMap exclusively for the purposes of displaying map functions and temporarily storing selected settings. This data may include, in particular, IP addresses and location data of users, which are, however, not collected without their consent (typically given via their end device or browser settings).
- Service Provider: OpenStreetMap Foundation (OSMF)
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.openstreetmap.de
- Privacy Policy: https://osmfoundation.org/wiki/Privacy_Policy
- reCAPTCHA: We integrate the "reCAPTCHA" function to recognize whether inputs (e.g., in online forms) are made by humans and not by automated machines (so-called "bots"). Processed data may include IP addresses, information on operating systems, devices, or browsers used, language settings, location, mouse movements, keystrokes, dwell time on web pages, previously visited web pages, interactions with reCAPTCHA on other web pages, possibly cookies, as well as results of manual recognition processes (e.g., answering questions or selecting objects in images). Data processing takes place on the basis of our legitimate interest in protecting our online offering against abusive automated crawling and spam.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.google.com/recaptcha/
- Privacy Policy: https://policies.google.com/privacy
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF)
- Opt-Out Option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de , Settings for the display of advertisements:
- YouTube Videos: Video content.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://www.youtube.com
- Privacy Policy: https://policies.google.com/privacy
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF)
- Opt-Out Option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de , Settings for the display of advertisements:
- YouTube Videos (Enhanced Privacy Mode): Videos stored on YouTube are embedded within our online offering. The integration of these YouTube videos takes place via a special domain using the "youtube-nocookie" component in the so-called "enhanced privacy mode". In "enhanced privacy mode", until the video starts, only information including your IP address as well as browser and end device details required by YouTube for the delivery, control, and optimization of the video display can be stored on your end device in cookies or using comparable procedures. As soon as you play the videos, additional information may be processed by YouTube to analyze user behavior, store data in user profiles, and personalize content and ads. The storage duration for cookies can be up to two years.
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Legal Bases: Consent (Art. 6(1) sentence 1 lit. a GDPR)
- Website: https://www.youtube.com
- Privacy Policy: https://policies.google.com/privacy
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF)
- Further Information: https://support.google.com/youtube/answer/171780?hl=de#zippy=%2Cturn-on-privacy-enhanced-mode%2Cerweiterten-datenschutzmodus-aktivieren
- Mapbox: Provision and editing of geographic and other maps, plans, and location-based information.
- Service Provider: Mapbox, Inc., 740 15th St Nw Suite 500 Washington, DC 20005, USA
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://www.mapbox.com/
- Privacy Policy: https://www.mapbox.com/legal/privacy
- Data Processing Agreement: Provided by the service provider
- Basis for Third-Country Transfers: EU/EEA - Data Privacy Framework (DPF), Standard Contractual Clauses (Provided by the service provider), Switzerland - Data Privacy Framework (DPF), Standard Contractual Clauses (Provided by the service provider)
- GraphHopper: Integration of GraphHopper for tour planning. Personal data is processed when users enter locations or addresses to calculate routes.
- Service Provider: GraphHopper GmbH, Lipowskystr. 30, 81373 Munich, Germany
- Website: https://www.graphhopper.com
- Privacy Policy: https://www.graphhopper.com/privacy/
- Gravitystorm: Provision of map services and map tiles via the Thunderforest API. Thunderforest (a service of Gravitystorm Limited) provides map images and map content used on the website to display routes, locations, or geographical information. In doing so, personal data such as IP addresses may be transmitted when users retrieve maps or routes.
- Service Provider: Gravitystorm Limited, 53 Ancaster Crescent, New Malden KT3 6BD, United Kingdom
- Website: https://www.thunderforest.com/
- Privacy Policy: https://www.thunderforest.com/privacy/
- mapTiler: Integration of MapTiler for displaying maps. Personal data is processed when users enter locations or addresses, e.g., to display routes or locations.
- Service Provider: MapTiler AG, Zugerstrasse 22/Unterägeri, Zug 6314, Switzerland
- Website: https://www.maptiler.com
- Privacy Policy: https://www.maptiler.com/privacy-policy/
- OpenWeather: Integration of information on weather conditions and weather forecasts.
- Service Provider: OpenWeather Ltd., 4 Queens Road, Wimbledon, SW19 8YB, United Kingdom
- Legal Bases: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR)
- Website: https://openweathermap.org/
- Privacy Policy: https://openweather.co.uk/privacy-policy
- Dynalinks: Integration of the Dynalinks service for creating and managing dynamic links and redirects. In this context, personal data may be processed, e.g., when users access URLs or are redirected via the service.
- Service Provider: Dynalinks (provider name available without a clear postal address), Contact: admins@dynalinks.app
- Website: https://dynalinks.app/
- Privacy Policy: https://dynalinks.app/privacy
- VLB: Integration of the VLB (Verzeichnis Lieferbarer Bücher / German Books in Print) to query book information, availabilities, and metadata. In doing so, no personal data of website users is directly transmitted to the provider.
- Service Provider: MVB GmbH, Braubachstraße 16, 60311 Frankfurt am Main, Germany
- Website: https://vlb.de/
- Privacy Policy: https://mvb-online.de/datenschutz
Definitions of Terms
This section provides an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their statutory definitions shall apply. The following explanations, on the other hand, are intended primarily for ease of understanding.
- Affiliate Tracking: As part of affiliate tracking, links used by linking websites to direct users to websites with product or other offers are logged. The operators of the respective linking websites may receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g., purchase goods or use services). For this purpose, it is necessary for providers to be able to track whether users who are interested in certain offers subsequently take advantage of them at the instance of the affiliate links. Therefore, for affiliate links to function, they must be supplemented with certain values that become a component of the link or are stored elsewhere, e.g., in a cookie. These values include, in particular, the referring website (referrer), the timestamp, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user, as well as tracking-specific values such as ad media ID, partner ID, and categorizations.
- Employees: Employees are defined as persons who are in an employment relationship, whether as staff, employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee established by an employment contract or agreement. It entails the employer's obligation to pay the employee remuneration, while the employee performs their work. The employment relationship comprises various phases, including establishment (when the employment contract is concluded), performance (when the employee carries out their work activities), and termination (when the employment relationship ends, whether by notice of termination, severance agreement, or otherwise). Employee data includes all information relating to these persons within the context of their employment. This encompasses aspects such as personal identification data, identification numbers, salary and bank details, working hours, vacation entitlements, health data, and performance evaluations.
- Master Data: Master data includes essential information necessary for the identification and administration of contractual partners, user accounts, profiles, and similar attributions. This data may include, among other things, personal and demographic details such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Master data forms the basis for any formal interaction between persons and services, institutions, or systems by enabling unambiguous attribution and communication.
- Content Data: Content data includes information generated during the creation, editing, and publication of content of all kinds. This category of data can include texts, images, videos, audio files, and other multimedia content published across various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content itself, such as tags, descriptions, author information, and publication dates.
- Click Tracking: Click tracking makes it possible to oversee user movements throughout an entire online offering. Since the results of these tests are more accurate if user interaction can be tracked over a certain period of time (e.g., so we can find out if a user likes to return), cookies are generally stored on users' computers for these test purposes.
- Contact Data: Contact data is essential information that enables communication with persons or organizations. It includes, among other things, phone numbers, postal addresses, and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Conversion Measurement: Conversion measurement (also referred to as "visit action evaluation") is a procedure used to determine the effectiveness of marketing measures. For this purpose, a cookie is generally stored on users' devices within the web pages on which the marketing measures take place and is then retrieved again on the target web page. For example, this allows us to track whether advertisements placed by us on other web pages were successful.
- Metadata, Communication, and Process Data: Metadata, communication, and process data are categories that contain information about how data is processed, transmitted, and managed. Metadata, also known as data about data, includes information describing the context, origin, and structure of other data. It may include details such as file size, creation date, author of a document, and revision histories. Communication data captures the exchange of information between users across various channels, such as email traffic, call logs, social media messages, and chat histories, including the persons involved, timestamps, and transmission paths. Process data describes the procedures and workflows within systems or organizations, including workflow documentation, transaction and activity logs, and audit logs used to trace and verify operations.
- Usage Data: Usage data refers to information capturing how users interact with digital products, services, or platforms. This data includes a wide range of information showing how users use applications, which features they prefer, how long they stay on certain pages, and the paths through which they navigate an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences, and potential problem areas within digital offerings.
- Personal Data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Profiles with User-Related Information: The processing of "profiles with user-related information", or "profiles" for short, includes any form of automated processing of personal data consisting of the use of personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information regarding demographics, behavior, and interests, such as interaction with websites and their content, etc., e.g., interest in specific content or products, click behavior on a website, or location). For profiling purposes, cookies and web beacons are frequently used.
- Log Data: Log data is information about events or activities logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages, and other details regarding the use or operation of a system. Log data is often used to analyze system problems, for security monitoring, or to generate performance reports.
- Reach Measurement: Reach measurement (also referred to as web analytics) serves to evaluate visitor flows to an online offering and can include visitor behavior or interest in specific information, such as web page content. With the help of reach analysis, operators of online offerings can, for example, recognize at what time users visit their web pages and what content interests them. This enables them, for example, to better adapt the content of the web pages to the needs of their visitors. For reach analysis purposes, pseudonymous cookies and web beacons are frequently used to recognize returning visitors and thus obtain more precise analyses regarding the use of an online offering.
- Location Data: Location data is generated when a mobile device (or another device with the technical prerequisites for location determination) connects to a cell tower, Wi-Fi network, or similar technical means and functions of location determination. Location data serves to specify the geographically determinable position on Earth where the respective device is located. Location data can be used, for example, to display map functions or other location-dependent information.
- Tracking: "Tracking" refers to when user behavior can be traced across multiple online offerings. As a rule, behavior and interest information regarding the online offerings used is stored in cookies or on the servers of tracking technology providers (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that presumably correspond to their interests.
- Controller: "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether collecting, evaluating, storing, transmitting, or erasing.
- Contractual Data: Contractual data is specific information relating to the formalization of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged, or sold. This data category is essential for managing and fulfilling contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contractual data may include contract start and end dates, the nature of agreed services or products, price agreements, payment terms, termination rights, renewal options, and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is crucial for clarifying rights and obligations, enforcing claims, and resolving disputes.
- Payment Data: Payment data includes all information required to process payment transactions between buyers and sellers. This data is of crucial importance for e-commerce, online banking, and any other form of financial transaction. It includes details such as credit card numbers, bank account details, payment amounts, transaction dates, verification numbers, and billing information. Payment data may also contain information on payment status, chargebacks, authorizations, and fees.
- Target Group Formation (Custom Audiences): Target group formation (English: "Custom Audiences") refers to determining target groups for advertising purposes, e.g., displaying advertisements. For example, based on a user's interest in certain products or topics on the Internet, it can be inferred that this user is interested in advertisements for similar products or the online shop where they viewed the products. "Lookalike Audiences" (or similar target groups), on the other hand, refers to displaying content deemed suitable to users whose profiles or interests presumably correspond to the users for whom the profiles were created. For the purpose of forming Custom Audiences and Lookalike Audiences, cookies and web beacons are generally used.

