Privacy policy
DATA PRIVACY STATEMENT
INTRODUCTORY REMARKS
With the following data protection declaration we would like to inform you which types of your personal data (hereinafter also referred to as "data") we process for which purposes and to what extent. The data protection declaration applies to all processing of personal data carried out by us, both within the scope of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offer").
The terms used are not gender-specific.
Status: November 21, 2019
TABLE OF CONTENTS
- introductory remarks
- person in charge
- Overview of processing operations
- Applicable legal bases
- Transmission and disclosure of personal data
- Data processing in third countries
- Use of cookies
- Commercial and business services
- Use of online marketplaces for e-commerce
- payment service provider
- Registration and Login
- Blogs and publication media
- Contact us
- Communication via Messenger
- Online conferences, meetings and webinars
- chatbots
- Surveys and surveys
- Provision of online services and web hosting
- application process
- cloud services
- Newsletter and broad communication
- Advertising communication by post, fax or telephone
- Sweepstakes and competitions
- Web Analysis and Optimization
- online marketing
- Offer an Affiliate Program
- Review Platforms
- Presence in social networks
- Plugins and embedded functions and content
- Planning, organisation and auxiliary tools
- Deletion of data
- Modification and updating of the data protection declaration
- Rights of data subjects
- definitions of terms
PERSON IN CHARGE
HALM Straws GmbH
Thaerstraße 19
10249 Berlin
Authorised representatives: Sebastian Müller
E-mail address: contact@halm.co
Imprint: https://www.halm.co/policies/legal-notice
OVERVIEW OF PROCESSING OPERATIONS
The following table summarises the types of data processed and the purposes of their processing and refers to the data subjects.
TYPES OF DATA PROCESSED
-
Inventory data (for example, names, addresses).
-
Applicant data (e.g. personal details, postal and contact addresses, the documents relating to the application and the information contained therein, e.g. covering letter, curriculum vitae, references and other personal or qualification information provided by applicants with regard to a specific job or voluntarily).
-
Content data (e.g. text input, photographs, videos).
-
Contact data (e.g. e-mail, telephone numbers).
-
Meta/communication data (e.g. device information, IP addresses).
-
Usage data (e.g. websites visited, interest in content, access times).
-
Social data (data that is subject to social confidentiality (§ 35 SGB I) and is processed, for example, by social insurance institutions, social assistance institutions or pension authorities).
-
Location data (data indicating the location of an end user's terminal equipment).
-
Contract data (for example, contract object, validity period, customer category).
-
Payment data (for example, bank details, invoices, payment history).
CATEGORIES OF DATA SUBJECTS
-
Employees (e.g. salaried employees, applicants, former employees).
-
Applicants.
-
Business partners and contractual partners.
-
Interested parties.
-
Communication partner.
-
Customers.
-
Users (e.g. website visitors, users of online services).
-
Participants in competitions and competitions.
PURPOSES OF PROCESSING
-
Affiliate tracking.
-
Provision of our online services and user friendliness.
-
Visit action evaluation.
-
Application procedure (justification and possible later implementation as well as possible later termination of the employment relationship).
-
Office and organisational procedures.
-
Click tracking.
-
Cross-Device Tracking (cross-device processing of user data for marketing purposes).
-
Direct marketing (e.g. by e-mail or post).
-
Conducting lotteries and competitions.
-
Feedback (e.g. collecting feedback via an online form).
-
Interest-based and behavioral marketing.
-
Contact requests and communication.
-
Conversion measurement (measurement of the effectiveness of marketing measures).
-
Profiling (creation of user profiles).
-
Remarketing.
-
Range measurement (e.g. access statistics, recognition of returning visitors).
-
Security measures.
-
Tracking (e.g. interest/behavioural profiling, use of cookies).
-
Contractual services and service.
-
Management and answering of inquiries.
-
Target group formation (determination of target groups relevant for marketing purposes or other output of content).
APPLICABLE LEGAL BASES
In the following we inform you about the legal basis of the Data Protection Ordinance (DSGVO), on the basis of which we process personal data. Please note that in addition to the provisions of the DSGVO, the national data protection regulations in your or our country of residence and domicile may apply.
-
Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO) - The data subject has given his/her consent to the processing of his/her personal data for one or more specific purposes.
-
Contract performance and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO) - Processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures at the request of the data subject.
-
Legal obligation (Art. 6 para. 1 sentence 1 lit. c. DSGVO) - The processing is necessary to fulfil a legal obligation to which the controller is subject.
-
Protection of vital interests (Art. 6 para. 1 sentence 1 lit. d. DSGVO) - Processing is necessary in order to protect the vital interests of the data subject or another natural person.
-
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO) - Processing is necessary to safeguard the legitimate interests of the data controller or of a third party, unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, prevail.
-
Art. 9 para. 1 sentence 1 lit. b DSGVO (application procedure as a pre-contractual or contractual relationship) (Insofar as special categories of personal data within the meaning of Art. 9 para. 1 DSGVO (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants so that the responsible person or the person concerned can exercise his/her rights under labour law and social security and social protection law and fulfil his/her obligations in this respect, their processing shall be carried out in accordance with Art. 9 para. 2 lit. b. DSGVO, in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, care or treatment in the health or social sector or for the administration of systems and services in the health or social sector in accordance with Art. 9 Para. 2 lit. h. DSGVO. In the case of a communication of special categories of data based on voluntary consent, their processing is carried out on the basis of Art. 9 para. 2 lit. a. DSGVO.) - .
National data protection regulations in Germany: In addition to the data protection regulations of the Basic Data Protection Regulation, national regulations apply to data protection in Germany. In particular, this includes the Act on Protection against Misuse of Personal Data in Data Processing (Bundesdatenschutzgesetz - BDSG). In particular, the BDSG contains special provisions on the right of information, the right of deletion, the right of objection, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for the purposes of the employment relationship (§ 26 BDSG), in particular with regard to the establishment, execution or termination of employment relationships as well as the consent of employees. Furthermore, data protection laws of the individual federal states may be applied.
TRANSMISSION AND DISCLOSURE OF PERSONAL DATA
As part of our processing of personal data, it may happen that the data is transferred to other offices, companies, legally independent organisational units or persons or that it is disclosed to them. Recipients of this data may include, for example, payment institutions within the framework of payment transactions, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases we observe the legal requirements and in particular conclude corresponding contracts or agreements with the recipients of your data which serve to protect your data.
Transferring Data within the Organization: We may transfer or provide access to personal information to other locations within our organization. Insofar as this disclosure is made for administrative purposes, the disclosure of data is based on our legitimate business and economic interests or is made if it is necessary to fulfill our contractual obligations or if the consent of the data subjects or a legal permission is present.
DATA PROCESSING IN THIRD COUNTRIES
If we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA)) or the processing takes place in the context of the use of services of third parties or the disclosure or transfer of data to other persons, bodies or companies, this is only done in accordance with the legal requirements.
Subject to express consent or transfer required by contract or law, we will only process or have the data processed in third countries with a recognised level of data protection, which includes US processors certified under the "Privacy Shield", or on the basis of special guarantees, such as a contractual obligation through so-called standard protection clauses of the EU Commission, the existence of certifications or binding internal data protection regulations (Art. 44 to 49 DSGVO, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de ).
USE OF COOKIES
Cookies are text files that contain data from visited websites or domains and are stored by a browser on the user's computer. A cookie serves primarily to store information about a user during or after his visit within an online offer. Stored information can include language settings on a website, login status, a shopping cart, or the location where a video was viewed. The term "cookies" also includes other technologies that perform the same functions as cookies (e.g. when user information is stored using pseudonymous online identifiers, also referred to as "user IDs").
The following cookie types and functions are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed his browser.
- Permanent cookies: Permanent cookies remain stored even after closing the browser. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. The interests of users who are used for range measurement or marketing purposes can also be stored in such a cookie.
- First-Party-Cookies: First-Party-Cookies are set by ourselves.
- Third party cookies: Third party cookies are mainly used by advertisers (so-called third parties) to process user information.
- Necessary (also: essential or absolutely necessary) cookies: Cookies may be absolutely necessary for the operation of a website (e.g. to store logins or other user inputs or for security reasons).
- Statistical, marketing and personalisation cookies: Cookies are also generally used to measure the user's range and when a user's interests or behaviour (e.g. viewing certain content, using functions, etc.) are stored on individual web pages in a user profile. Such profiles are used, for example, to display content to users that corresponds to their potential interests. This procedure is also referred to as "tracking", i.e. tracking the potential interests of users. . If we use cookies or "tracking" technologies, we will inform you separately in our privacy policy or in the context of obtaining consent.
Notes on legal bases: The legal basis on which we process your personal data with the help of cookies depends on whether we ask you for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is your declared consent. Otherwise, the data processed with the aid of cookies will be processed on the basis of our legitimate interests (e.g. in a business operation of our online service and its improvement) or, if the use of cookies is necessary to fulfill our contractual obligations.
General information on revocation and objection (opt-out): Depending on whether processing is based on a consent or legal permission, you have the option at any time to revoke a consent given or to object to the processing of your data using cookie technologies (collectively referred to as "opt-out"). You can initially explain your objection using your browser settings, e.g. by deactivating the use of cookies (which may also restrict the functionality of our online service). An objection to the use of cookies for the purposes of online marketing can also be raised through a variety of services, particularly in the case of tracking, via the websites http://optout.aboutads.info and http://www.youronlinechoices.com/ . In addition, you can receive further objection notices within the framework of the information on the service providers used and cookies.
Processing of cookie data on the basis of consent: Before we process or have processed data within the framework of the use of cookies, we ask the user for consent that can be revoked at any time. Before the consent has not been given, we may use cookies that are necessary for the operation of our online offer. Their use is based on our interest and the user's interest in the expected functionality of our online service.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
COMMERCIAL AND BUSINESS SERVICES
We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as "contractual partners") within the framework of contractual and comparable legal relationships as well as associated measures and within the framework of communication with the contractual partners (or pre-contractual), e.g. in order to answer inquiries.
We process this data in order to fulfil our contractual obligations, to safeguard our rights and for the purposes of the administrative tasks associated with this data and the entrepreneurial organisation. Within the framework of the applicable law, we only pass on the data of the contractual partners to third parties insofar as this is necessary for the aforementioned purposes or for the fulfilment of legal obligations or is carried out with the consent of the contractual partners (e.g. to involved telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). The contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the framework of this data protection declaration.
Which data are necessary for the aforementioned purposes, we inform the contracting partners before or in the context of the data collection, e.g. in on-line forms, by special marking (e.g. colors) and/or symbols (e.g. asterisks or the like), or personally.
We delete the data after expiry of statutory warranty and comparable obligations, i.e., in principle after expiry of 4 years, unless the data are stored in a customer account, e.g., as long as they must be kept for legal reasons of archiving (e.g. for tax purposes usually 10 years). Data disclosed to us by the contractual partner within the framework of an order shall be deleted in accordance with the specifications of the order, in principle after the end of the order.
If we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms shall apply in the relationship between the users and the providers.
Customer account: Contracting parties can create an account within our online offer (e.g. customer or user account, in short "customer account"). If the registration of a customer account is required, the contractual partners will be informed of this as well as of the information required for registration. The customer accounts are not public and cannot be indexed by search engines. In the course of registration as well as subsequent registrations and uses of the customer account, we store the IP addresses of the customers along with the access times in order to be able to prove registration and prevent any misuse of the customer account.
If customers have terminated their customer account, the data relating to the customer account will be deleted, subject to retention, which is required for legal reasons. It is the responsibility of the customer to secure their data upon termination of the customer account.
Economic analyses and market research: For economic reasons and in order to be able to recognise market trends, wishes of contractual partners and users, we analyse the data available to us on business transactions, contracts, enquiries, etc., whereby contractual partners, interested parties, customers, visitors and users of our online offer may fall into the group of persons concerned.
The analyses are carried out for the purpose of business evaluations, marketing and market research (for example, to determine customer groups with different characteristics). If available, we can take into account the profiles of registered users including their details, e.g. on services used. The analyses serve us alone and are not disclosed externally unless they are anonymous analyses with summarised, i.e. anonymised values. Furthermore, we respect the privacy of the users and process the data for analysis purposes as pseudonymously as possible and, if feasible, anonymously (e.g. as combined data).
Shop and e-commerce: We process the data of our customers in order to enable them to select, purchase or order the selected products, goods and related services, as well as their payment and delivery, or performance.
The required details are identified as such within the framework of the ordering or comparable purchase process and include the details required for delivery or provision and invoicing as well as contact information in order to be able to hold any consultation.
Publishing activities: We process the data of our contact partners, interview partners and other persons who are the subject of our publishing, editorial, journalistic and related activities. In this context, we refer you to the application of protective provisions of freedom of expression and freedom of the press pursuant to Art. 85 DSGVO in conjunction with the respective national laws. The processing serves the fulfilment of our order activities and otherwise takes place in particular on the basis of the general public's interest in information and media offers.
-
Processed data types: inventory data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact data (e.g. e-mail, telephone numbers), contract data (e.g. subject of contract, duration, customer category), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Interested parties, business and contractual partners, customers.
-
Purposes of processing: contractual services, contact requests and communication, office and organisational procedures, administration and response to requests, security measures, evaluation of visits, marketing based on interests and behaviour, profiling (creation of user profiles).
-
Legal basis: Contract performance and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO), legal obligation (Art. 6 para. 1 sentence 1 lit. c. DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
USE OF ONLINE MARKETPLACES FOR E-COMMERCE
We offer our services on online platforms operated by other service providers. In this context, the data protection notices of the respective platforms apply in addition to our data protection notices. This applies in particular to the methods used on the platforms for range measurement and interest-related marketing.
-
Processed data types: inventory data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact data (e.g. e-mail, telephone numbers), contract data (e.g. subject of contract, duration, customer category), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Customers.
-
Purposes of processing: Contractual services and service.
-
Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Alibaba.com: online marketplace for e-commerce; service provider: Alibaba (China) Co., Ltd, 969 West Wen Yi Road, Yu Hang District. Hangzhou 311121, China; Website: https://www.alibaba.com; Privacy Policy: https://rule.alibaba.com/rule/detail/2034.htm?spm=a2700.8293689.0.0.ef1765aaqDK7qq.
-
Amazon: Online marketplace for e-commerce; service provider: Amazon Europe Core S.à.r.l., Amazon EU S.à.r.l., Amazon Services Europe S.à.r.l. and Amazon Media EU S.à.r.l., all four located at 38, avenue John F. Kennedy, L-1855 Luxembourg, and Amazon Instant Video Germany GmbH, Domagkstr. 28, 80807 Munich (together "Amazon Europe"), parent company: Amazon.com, Inc. 2021 Seventh Ave, Seattle, Washington 98121, USA; Website: https://www.amazon.de; Privacy Statement: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4tatus=Active.
-
avocadostore: online marketplace for e-commerce; service provider: Avocado Store GmbH, Cremon 32, 20457 Hamburg, Germany; Website: https://www.avocadostore.de/; Privacy Policy: https://www.avocadostore.de/privacy.
-
eBay: Online Marketplace for E-Commerce; Service Provider: eBay Marketplaces GmbH, Helvetiastrasse 15/17, 3005 Bern, Switzerland; Website: https://www.ebay.de/; Privacy Policy: https://www.ebay.de/help/policies/member-behavior-policies/datenschutzerklrung?id=4260.
-
Etsy: online marketplace for e-commerce; service provider: Etsy, Inc. 55 Washington Street, Suite 712, Brooklyn, NY 11201, USA; Website: https://www.etsy.com/de; Privacy Policy: https://www.etsy.com/de/legal/privacy/?ref=ftr.
-
Lieferando: delivery service platform for catering services; service provider: yd. yourdelivery GmbH, Am Karlsbad 16, D-10785 Berlin, Germany; website: https://www.lieferando.de; privacy policy: https://www.lieferando.de/privacy-statement.
-
shopify: e-commerce platform and cloud services; service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.de; Privacy Policy: https://www.shopify.de/legal/datenschutz.
PAYMENT SERVICE PROVIDER
Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the persons concerned efficient and secure payment options and use other payment service providers in addition to banks and credit institutions (collectively "payment service providers").
The data processed by the payment service providers includes inventory data, such as name and address, bank data, such as account or credit card numbers, passwords, TANs and checksums, as well as contract, total and recipient details. The information is required to complete the transactions. However, the data entered will only be processed and stored by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information with confirmation or negative information about the payment. The data may be transmitted by payment service providers to credit reference agencies. The purpose of this transmission is to check identity and creditworthiness. In this regard, we refer to the General Terms and Conditions and the data protection information of the payment service providers.
Payment transactions are subject to the terms and conditions and data protection notices of the respective payment service providers, which can be accessed within the respective websites or transaction applications. We also refer to these for the purpose of further information and assertion of revocation, information and other rights affected.
-
Processed data types: inventory data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contract data (e.g. subject of contract, duration, customer category), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), contact data (e.g. e-mail, telephone numbers).
-
Affected persons: Customers, interested parties.
-
Purposes of processing: contractual services and service, contact requests and communication, affiliate tracking.
-
Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Amazon Payments: payment services; service providers: Amazon Payments Europe S.C.A. 38 avenue J.F. Kennedy, L-1855 Luxembourg; Website: https://pay.amazon.com/de; Privacy Policy: https://pay.amazon.com/de/help/201212490.
-
Apple Pay: payment services; service providers: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; website: https://www.apple.com/de/apple-pay/; privacy policy: https://www.apple.com/legal/privacy/de-ww/.
-
Google Pay: payment services; service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://pay.google.com/intl/de_de/about/; Privacy Policy: https://policies.google.com/privacy.
-
Klarna / Sofortüberweisung: payment services; service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden; Website: https://www.klarna.com/de; Privacy Policy: https://www.klarna.com/de/datenschutz.
-
for Mastercard: payment services; service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Website: https://www.mastercard.de/de-de.html; Privacy Policy: https://www.mastercard.de/de-de/datenschutz.html.
-
PayPal: payment services and solutions (e.g. PayPal, PayPal Plus, Braintree); service providers: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Website: https://www.paypal.com/de; Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
-
Stripe: payment services; service providers: Stripe, Inc. 510 Townsend Street, San Francisco, CA 94103, USA; Website: https://stripe.com/de; Privacy Policy: https://stripe.com/de/privacy.
-
Visa: payment services; service providers: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, GB; Website: https://www.visa.de; Privacy Policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
REGISTRATION AND LOGIN
Users can create a user account. During the registration process, users are provided with the required mandatory information and processed for the purpose of providing the user account on the basis of contractual fulfilment of obligations. The data processed includes in particular the login information (name, password and an e-mail address). The data entered during registration will be used for the purposes of using the user account and its purpose.
Users may be informed by e-mail of transactions relevant to their user account, such as technical changes. If users have terminated their user account, their data will be deleted with regard to the user account, subject to a statutory retention obligation. It is the responsibility of the users to secure their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all user data stored during the term of the contract.
When using our registration and login functions as well as the user account, we store the IP address and the time of the respective user action. The storage takes place on the basis of our legitimate interests as well as those of the users in a protection against misuse and other unauthorized use. This data will not be passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so.
Online forum: Participation in the Forum is subject to registration, which, unless otherwise stated in the registration form, requires one or more of your name, password and email address to which access data will be sent. For security reasons, the password should be state of the art, i.e. complicated (users will be notified of this during registration if necessary) and should not be used elsewhere. Forum posts are visible to the public unless their visibility is limited to specific members or groups of members. The contributions of the authors are stored with their names, if registered or indicated, the time and the entry content. In the case of registrations and the creation of entries, the IP addresses of the users are also stored if the entries have an inadmissible content and the IP addresses could be used for legal prosecution. The person responsible reserves the right to delete registrations and entries on the basis of an appropriate assessment.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), meta/communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Purposes of processing: contractual services and service, security measures, management and response to inquiries.
-
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), performance of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f DSGVO).
BLOGS AND PUBLICATION MEDIA
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data will only be processed for the purposes of the publication medium to the extent necessary for its presentation and communication between authors and readers or for security reasons. For the rest, we refer to the information on the processing of visitors to our publication medium in the context of this data protection notice.
Comments and contributions: When users leave comments or other contributions, their IP addresses may be stored based on our legitimate interests. This is done for our safety, if someone leaves illegal contents (insults, forbidden political propaganda etc.) in comments and contributions. In this case, we ourselves can be prosecuted for the comment or contribution and are therefore interested in the author's identity.
Furthermore, we reserve the right to process user data for the purpose of spam detection on the basis of our legitimate interests.
On the same legal basis, in the case of surveys, we reserve the right to store the IP addresses of users for the duration of the surveys and to use cookies in order to avoid multiple votes.
The personal information provided in the course of comments and contributions, any contact and website information as well as the content information will be stored permanently by us until the user objects.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Purposes of processing: contractual services, feedback (e.g. collection of feedback via online form), security measures, administration and response to inquiries.
-
Legal basis: fulfilment of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO), consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), protection of vital interests (Art. 6 para. 1 sentence 1 lit. d. DSGVO).
CONTACT US
When contacting us (e.g. via contact form, e-mail, telephone or via social media), the data of the inquiring persons are processed insofar as this is necessary to answer the contact enquiries and any requested measures.
The response to contact enquiries within the framework of contractual or pre-contractual relationships is made in order to fulfil our contractual obligations or to respond to (pre)contractual enquiries and otherwise on the basis of the legitimate interests in responding to the enquiries.
Chat function: We offer a chat function within our online offering for the purposes of communication and answering enquiries. The input of the users within the chat will be processed for the purpose of answering their requests.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Communication partners, interested parties.
-
Purposes of processing: contact requests and communication, management and response to requests.
-
Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
COMMUNICATION VIA MESSENGER
We use Messenger services for communication purposes and therefore ask you to observe the following information on the functionality of Messengers, on encryption, on the use of the metadata of communication and on the possibilities for objection.
You can also contact us by alternative means, e.g. telephone or e-mail. Please use the contact options provided to you or the contact options provided within our online offer.
In the case of end-to-end encryption of content (i.e., the content of your message and attachments), we point out that the communication content (i.e., the content of the message and attachments) is encrypted end-to-end. This means that the content of the messages is not visible, not even by the messenger providers themselves. You should always use a current version of Messenger with encryption enabled to ensure that message content is encrypted.
We would also like to point out to our communication partners that although the providers of messengers do not view the content, they can find out that and when communication partners communicate with us and that technical information on the communication partner's device used and, depending on the settings of their device, also location information (so-called metadata) is processed.
Information on legal bases: If we ask communication partners for permission before communicating with them via Messenger, the legal basis of our processing of their data is their consent. Otherwise, if we do not request consent and you contact us, for example, voluntarily, we use Messenger in our dealings with our contractual partners and as part of the contract initiation process as a contractual measure and in the case of other interested parties and communication partners on the basis of our legitimate interests in fast and efficient communication and meeting the needs of our communication partners for communication via Messengers. We would also like to point out that we do not transmit the contact data provided to us to the messengers for the first time without your consent.
Revocation, objection and deletion: You can revoke your consent at any time and object to communication with us via Messenger at any time. In the case of communication via Messenger, we delete the messages in accordance with our general deletion guidelines (i.e., as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) and otherwise as soon as we can assume that we have answered any information provided by the communication partners, if no reference back to a previous conversation is to be expected and there are no legal obligations to store the messages to prevent deletion.
Reservation of reference to other communication channels: Finally, we would like to point out that we reserve the right, for reasons of your safety, not to answer enquiries via Messenger. This is the case if, for example, internal contractual matters require special secrecy or if an answer via Messenger does not meet the formal requirements. In such cases we refer you to more appropriate communication channels.
-
Processed data types: contact data (e.g. e-mail, telephone numbers), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), content data (e.g. text input, photographs, videos).
-
Affected persons: Communication partner.
-
Purposes of processing: contact enquiries and communication, direct marketing (e.g. by e-mail or post).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Facebook Messenger: Facebook Messenger with end-to-end encryption (end-to-end Facebook Messenger encryption requires activation unless activated by default); service providers: https://www.facebook.com, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: https://www.facebook.com/settings?tab=ads.
-
Slack: Slack Messenger without end-to-end encryption; service provider: Slack Technologies, Inc. 500 Howard Street, San Francisco, CA 94105, USA; Website: https://slack.com/intl/de-de/; Privacy Statement: https://slack.com/intl/de-de/legal; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnMBAA0tatus=Active.
-
WhatsApp: WhatsApp Messenger with end-to-end encryption; service provider: WhatsApp Inc. WhatsApp Legal 1601 Willow Road Menlo Park, California 94025, USA; Website: https://www.whatsapp.com/; Privacy Statement: https://www.whatsapp.com/legal; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TSnwAAGtatus=Active.
ONLINE CONFERENCES, MEETINGS AND WEBINARS
We use third-party platforms and applications (hereinafter referred to as "Third Party Providers") for the purposes of conducting video and audio conferences, webinars and other types of video and audio meetings. When selecting third-party providers and their services, we observe the legal requirements.
In this context data of the communication participants are processed and stored on the servers of the third party providers, as far as these are part of communication processes with us. This data may include, but is not limited to, login and contact information, visual and voice contributions, chats and shared screen content.
If users are referred to the third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party provider processing may process usage data and metadata that is processed by them for security purposes, service optimisation or marketing purposes. We therefore ask you to observe the data protection information of the respective third party providers.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing is consent. Furthermore, their use can be a component of our (pre)contractual services, provided that the use of the third party was agreed within this framework. Otherwise, the user data will be based on our legitimate interests (i.e., interest in effizie). In this context, we would also like to refer you to the information on the use of cookies in this privacy statement.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Communication partners, users (e.g. website visitors, users of online services).
-
Purposes of processing: contractual services, contact requests and communication, office and organisational procedures.
-
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), performance of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f DSGVO).
Services and service providers used:
-
Google Hangouts: Messenger and conferencing software; service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://hangouts.google.com/; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active.
-
Slack: messenger and conference software; service provider: Slack Technologies, Inc. 500 Howard Street, San Francisco, CA 94105, USA; Website: https://slack.com/intl/de-de/; Privacy Statement: https://slack.com/intl/de-de/legal; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnMBAA0tatus=Active.
-
TeamViewer: conference software; service provider: TeamViewer GmbH, Jahnstr. 30, 73037 Göppingen, Germany; Website: https://www.teamviewer.com/de; Privacy Policy: https://www.teamviewer.com/de/datenschutzerklaerung/.
CHATBOTS
We offer a so-called "chatbot" as a communication option. A chatbot is software that answers users' questions or informs them about messages. If you talk to our chatbot, we can process your personal data.
If you communicate with the chatbot within an online platform, your identification number will also be stored within the respective platform. We may also collect information about which users interact with our chatbot and when. Furthermore, we store the content of your conversations with the chatbot and log registration and consent processes in order to be able to prove these according to legal requirements.
We would like to point out that the respective platform provider can find out that and when users can communicate with our chatbot as well as collect technical information on the user's device used and, depending on the settings of their device, also location information (so-called metadata) for purposes of optimising the respective services and security. Likewise, the metadata of communication via chatbot (i.e. e.g., the information as to who has communicated with whom) could be used by the respective platform providers for marketing purposes or to display advertisements tailored to users in accordance with their provisions to which we refer for further information.
If users agree to the chatbot to activate information with regular messages, they have the option at any time to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. By unsubscribing from chatbot messages, user data is deleted from the directory of message recipients.
We use the aforementioned information to operate our chatbot, e.g. to address users personally, to answer their questions to the chatbot, to transmit any requested content and also to improve our chatbot (e.g. to "teach" it answers to frequently asked questions or to recognize unanswered requests).
Notes on legal bases: We use the chatbot on the basis of consent, if we have previously obtained permission from the users to process their data by the chatbot (this applies to cases in which users are asked for consent, e.g. so that the chatbot regularly sends them messages). If we use the chatbot to answer user queries about our services or our company, this is done for contractual and pre-contractual communication. In addition, we use the Chatbot based on our legitimate interests in optimizing the Chatbot, its operating efficiency and enhancing the positive user experience.
Revocation, contradiction and deletion: You can revoke a given consent at any time or contradict the processing of your data in the context of our Chatbot use.
-
Processed data types: contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Communication partners, users (e.g. website visitors, users of online services).
-
Purposes of processing: contact enquiries and communication, direct marketing (e.g. by e-mail or post), measurement of reach (e.g. access statistics, recognition of returning visitors), tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, evaluation of visit campaigns, profiling (creation of user profiles), conversion measurement (measurement of the effectiveness of marketing measures).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
HubSpot: chatbot and assistance software and related services; service provider: HubSpot, Inc. 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Website: https://www.hubspot.de; Privacy Policy: https://legal.hubspot.com/de/privacy-policy.
SURVEYS AND SURVEYS
The surveys and surveys we conduct (hereinafter referred to as "surveys") are evaluated anonymously. Personal data is only processed insofar as this is necessary for the provision and technical execution of the surveys (e.g. processing the IP address to display the survey in the user's browser or to enable a resumption of the survey with the aid of a temporary cookie (session cookie)) or users have consented.
Information on legal bases: If we ask the participants for their consent to the processing of their data, this is the legal basis for the processing, otherwise the processing of the participants' data takes place on the basis of our legitimate interests in carrying out an objective survey.
-
Processed data types: contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Communication partners, users (e.g. website visitors, users of online services).
-
Purposes of processing: contact enquiries and communication, direct marketing (e.g. by e-mail or post), tracking (e.g. interest/behavioural profiling, use of cookies), feedback (e.g. collecting feedback via online forms).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Google form: Google Cloud Forms; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://firebase.google.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: Opt-Out Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Advertising Display Settings: https://adssettings.google.com/authenticated.
PROVISION OF ONLINE SERVICES AND WEB HOSTING
In order to provide our online services securely and efficiently, we use the services of one or more web hosting providers from whose servers (or servers they manage) the online services can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services, as well as security and technical maintenance services.
The data processed within the framework of the provision of the hosting offer may include all information relating to the users of our online offer that is collected within the scope of use and communication. This regularly includes the IP address, which is necessary to be able to deliver the contents of online offers to browsers, and all entries made within our online offer or from websites.
E-mail dispatch and hosting: The web hosting services we use also include the dispatch, receipt and storage of e-mails. For these purposes, the addresses of the recipients and senders as well as further information regarding the sending of e-mails (e.g. the providers involved) and the contents of the respective e-mails are processed. The above data may also be processed for SPAM detection purposes. Please note that e-mails on the Internet are generally not sent in encrypted form. As a rule, e-mails are encrypted during transport, but not on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used). We can therefore accept no responsibility for the transmission path of e-mails between the sender and reception on our server.
Collection of access data and log files: We ourselves (or our web hosting provider) collect data on each access to the server (so-called server log files). Server log files may include the address and name of the web pages and files accessed, the date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider.
The server log files can be used for security purposes, e.g. to avoid overloading the servers (especially in the case of abusive attacks, so-called DDoS attacks) and to ensure the utilization of the servers and their stability.
-
Processed data types: Content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
APPLICATION PROCESS
The application process requires applicants to provide us with the data necessary for their assessment and selection. The information required can be found in the job description or, in the case of online forms, in the information provided there.
In principle, the required information includes personal information such as name, address, a contact option and proof of the qualifications required for a job. Upon request, we will be happy to provide you with additional information.
If made available, applicants can submit their applications via an online form. The data will be transmitted to us encrypted according to the state of the art. Applicants can also send us their applications by e-mail. Please note, however, that e-mails on the Internet are generally not sent in encrypted form. As a rule, e-mails are encrypted during transport, but not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of the application between the sender and the reception on our server.
For the purposes of searching for applicants, submitting applications and selecting applicants, we may make use of the applicant management and recruitment software, platforms and services of third-party providers in compliance with legal requirements.
Applicants are welcome to contact us about how to submit their application or send it to us by post.
Processing of special categories of data: Insofar as special categories of personal data within the meaning of Art. 9 para. 1 DSGVO (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants within the framework of the application procedure, so that the responsible person or the person concerned can exercise the rights accruing to him or her from labour law and social security and social protection law and fulfil his or her duties in this regard, their processing shall be carried out in accordance with Art. 9 para. 2 lit. b. DSGVO, in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, for care or treatment in the health or social sector or for the administration of systems and services in the health or social sector in accordance with Art. 9 Para. 2 lit. h. DSGVO. In the case of a communication of the special categories of data based on voluntary consent, their processing shall be carried out on the basis of Art. 9 para. 2 lit. a. DSGVO.
Deletion of data: In the event of a successful application, the data provided by the applicants may be further processed by us for the purposes of the employment relationship. Otherwise, if the application for a job offer is not successful, the applicant's data will be deleted. Applicants' data will also be deleted if an application is withdrawn, to which applicants are entitled at any time. Subject to a justified revocation by the applicant, the deletion will take place at the latest after the expiry of a period of six months, so that we can answer any follow-up questions regarding the application and comply with our duty of proof under the regulations on equal treatment of applicants. Invoices for any reimbursement of travel expenses are archived in accordance with tax regulations.
Admission to an applicant pool: Admission to an applicant pool, if offered, is based on consent. Applicants are informed that their consent to be included in the talent pool is voluntary, has no influence on the current application process and that they can revoke their consent at any time for the future.
-
Processed data types: Applicant data (e.g. personal details, postal and contact addresses, the documents pertaining to the application and the information contained therein, such as cover letters, curriculum vitae, certificates and other personal or qualification information provided by applicants with regard to a specific job or voluntarily).
-
Affected persons: Applicants.
-
Purposes of processing: Application procedure (justification and possible subsequent performance and possible subsequent termination of employment.).
-
Legal basis: Art. 9 para. 1 sentence 1 lit. b DSGVO (application procedure as a pre-contractual or contractual relationship) (Insofar as special categories of personal data within the meaning of Art. 9 para. 1 DSGVO (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants so that the responsible person or the person concerned can exercise his/her rights under labour law and social security and social protection law and fulfil his/her obligations in this respect, their processing shall be carried out in accordance with Art. 9 para. 2 lit. b. DSGVO, in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, care or treatment in the health or social sector or for the administration of systems and services in the health or social sector in accordance with Art. 9 Para. 2 lit. h. DSGVO. In the case of a communication of special categories of data based on voluntary consent, their processing is carried out on the basis of Art. 9 para. 2 lit. a. DSGVO.).
CLOUD SERVICES
We use software services ("Cloud Services", also referred to as "Software as a Service") that are accessible over the Internet and executed on the servers of its providers for the following purposes: document storage and administration, calendar management, e-mail delivery, spreadsheets and presentations, exchange of documents, content and information with specific recipients or publication of websites, forms or other content and information as well as chats and participation in audio and video conferences.
Within this framework, personal data may be processed and stored on the provider's servers insofar as these are part of communication processes with us or are otherwise processed by us as set out in this data protection declaration. This data may include in particular master data and contact data of users, data on processes, contracts, other processes and their contents. Cloud service providers also process usage data and metadata that they use for security and service optimization purposes.
If we use cloud services to provide other users or publicly accessible websites with forms or other documents and content, providers may store cookies on users' devices for the purpose of web analysis or to remember users' settings (e.g. in the case of media control).
Notes on legal bases: If we ask for consent to the use of cloud services, the legal basis for processing is consent. Furthermore, their use can be a component of our (pre)contractual services, provided that the use of cloud services has been agreed within this framework. Otherwise, user data will be processed based on our legitimate interests (i.e., interest in efficient and secure administrative and collaboration processes).
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Customers, employees (e.g. salaried employees, applicants, former employees), interested parties, communication partners.
-
Purposes of processing: office and organisational procedures.
-
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), performance of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f DSGVO).
Services and service providers used:
-
Google Cloud Services: cloud storage services; service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://cloud.google.com/; Privacy Statement: https://www.google.com/policies/privacy; Security Notices: https://cloud.google.com/security/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000000001L5AAItatus=Aktive; Standard Contractual Clauses: https://cloud.google.com/terms/data-processing-terms; Additional Privacy Notices: https://cloud.google.com/terms/data-processing-terms.
NEWSLETTER AND BROAD COMMUNICATION
We send newsletters, e-mails and other electronic notifications (hereinafter referred to as "newsletters") only with the consent of the recipient or a legal permission. Insofar as the contents of the newsletter are specifically described within the framework of registration, they are decisive for the consent of the user. In addition, our newsletters contain information about our services and us.
To subscribe to our newsletters, it is sufficient to enter your e-mail address. However, we may ask you to provide a name for the purpose of personally contacting us in the newsletter, or other information if this is required for the purposes of the newsletter.
Double opt-in process: The registration to our newsletter takes place in principle in a so-called Double-Opt-In procedure. This means that you will receive an e-mail after registration asking you to confirm your registration. This confirmation is necessary so that no one can register with foreign e-mail addresses. The registrations for the newsletter are logged in order to be able to prove the registration process according to the legal requirements. This includes storing the login and confirmation times as well as the IP address. Likewise the changes of your data stored with the dispatch service provider are logged.
Deletion and limitation of processing: We may store the unsubscribed email addresses for up to three years based on our legitimate interests before deleting them to provide evidence of prior consent. The processing of these data is limited to the purpose of a possible defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe contradictions, we reserve the right to store the e-mail address solely for this purpose in a blacklist.
The logging of the registration procedure is carried out on the basis of our legitimate interests for the purpose of proving its proper course. If we hire a service provider to send e-mails, we do so on the basis of our legitimate interests in an efficient and secure delivery system.
Notes on legal bases: The newsletter is sent on the basis of the recipient's consent or, if consent is not required, on the basis of our legitimate interests in direct marketing, provided and to the extent that this is permitted by law, e.g. in the case of existing customer advertising. If we commission a service provider to send e-mails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests to demonstrate that it has been conducted in accordance with the law.
Contents: Information about us, our services, promotions and offers.
Success measurement: The newsletters contain a so-called "web-beacon", i.e. a pixel-sized file, which is retrieved from our server or, if we use a dispatch service provider, from its server when the newsletter is opened. Within the scope of this retrieval, technical information such as information about the browser and your system, as well as your IP address and the time of the retrieval, are first collected.
This information is used for the technical improvement of our newsletter on the basis of technical data or target groups and their reading behaviour on the basis of their retrieval locations (which can be determined with the help of the IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is neither our aim nor, if used, that of the shipping service provider to monitor individual users. Rather, the evaluations serve us to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
The evaluation of the newsletter and the performance measurement are carried out, subject to the express consent of the user, on the basis of our legitimate interests for the purposes of using a user-friendly and secure newsletter system which serves both our business interests and the expectations of the user.
A separate revocation of the performance measurement is unfortunately not possible, in this case the entire newsletter subscription must be cancelled or contradicted.
Prerequisite for the use of free services: Consent to the sending of mailings can be made dependent on the use of free services (e.g. access to certain content or participation in certain campaigns) as a prerequisite. If the users wish to make use of the free service without registering for the newsletter, please contact us.
Sending via SMS: Our communications are (also) sent via SMS text messages.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), meta/communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).
-
Affected persons: Communication partners, users (e.g. website visitors, users of online services).
-
Purposes of processing: direct marketing (e.g. by e-mail or post), contractual services, contact enquiries and communication.
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
-
Opt-out: You can cancel the receipt of our newsletter at any time, i.e. revoke your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can otherwise use one of the contact options listed above, preferably e-mail.
Services and service providers used:
-
HubSpot: email marketing platform; service provider: HubSpot, Inc. 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Website: https://www.hubspot.de; Privacy Policy: https://legal.hubspot.com/de/privacy-policy.
-
Mailchimp: e-mail marketing platform; service provider: "Mailchimp" - Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA; website: https://mailchimp.com; privacy statement: https://mailchimp.com/legal/privacy/; privacy shield: https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAGtatus=Active.
-
WhatsApp Broadcasts: WhatsApp Broadcasts - Messenger with end-to-end encryption; service provider: WhatsApp Inc. WhatsApp Legal 1601 Willow Road Menlo Park, California 94025, USA; Website: https://www.whatsapp.com/; Privacy Statement: https://www.whatsapp.com/legal; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TSnwAAGtatus=Active.
-
Zapier: Import of e-mail addresses to the dispatch service providers used from other platforms or other sources; service provider: Zapier, Inc., 548 Market St #62411, San Francisco, California 94104, USA; Website: https://zapier.com; Privacy Statement: https://zapier.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TNk2AAGtatus=Active.
ADVERTISING COMMUNICATION BY POST, FAX OR TELEPHONE
We process personal data for the purposes of advertising communication, which can take place via various channels such as e-mail, telephone, post or fax. In this context, we comply with legal requirements and obtain the necessary consents, unless the communication is legally permitted.
Recipients have the right to revoke consent given at any time or to object to advertising communication at any time.
After revocation or objection, we may store the data required to prove consent for up to three years on the basis of our legitimate interests before we delete them. The processing of these data is limited to the purpose of a possible defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers).
-
Affected persons: Communication partner.
-
Purposes of processing: direct marketing (e.g. by e-mail or post).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
SWEEPSTAKES AND COMPETITIONS
We process the personal data of participants in sweepstakes and competitions only in compliance with the relevant data protection regulations, insofar as the processing is contractually necessary for the provision, execution and handling of the sweepstake, the participants have consented to the processing or the processing serves our legitimate interests (e.g. in the security of the sweepstake or the protection of our interests against misuse by possible collection of IP addresses when submitting sweepstake entries).
In the event that contributions by participants are published as part of the sweepstakes (e.g. as part of a vote or presentation of the sweepstakes contributions or the winner or reporting on the sweepstakes), we would like to point out that the names of participants may also be published in this context. The participants can object to this at any time.
If the competition takes place within an online platform or a social network (e.g. Facebook or Instagram, hereinafter referred to as "online platform"), the usage and data protection provisions of the respective platforms also apply. In these cases we would like to point out that we are responsible for the information provided by the participants in the context of the competition and that we must be contacted with regard to the competition.
The data of the participants will be deleted as soon as the competition has ended and the data is no longer required to inform the winners or because queries regarding the competition are to be expected. In principle, the data of the participants will be deleted at the latest 6 months after the end of the competition. Winners' data may be retained for a longer period of time, e.g. in order to be able to answer questions about the prizes or to fulfil the prizes; in this case, the retention period depends on the type of prize and is up to three years for items or services, e.g. in order to be able to process warranty claims. Furthermore, the participants' data may be stored for longer, e.g. in the form of reports on the competition in online and offline media.
Insofar as data was collected for other purposes as part of the competition, its processing and storage period shall be governed by the data protection information for this use (e.g. in the case of registration for a newsletter as part of a competition).
-
Processed data types: inventory data (e.g. names, addresses), content data (e.g. text input, photographs, videos).
-
Affected persons: Participants in competitions and competitions.
-
Purposes of processing: Conducting lotteries and competitions.
-
Legal basis: Contract performance and pre-contractual enquiries (Art. 6 para. 1 p. 1 lit. b. DSGVO).
WEB ANALYSIS AND OPTIMIZATION
Web analysis (also referred to as "range measurement") serves to evaluate the visitor flows of our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of the range analysis we can, for example, recognize at which time our online offer or its functions or contents are most frequently used or invite for reuse. We can also determine which areas require optimization.
In addition to web analysis, we can also use test procedures, e.g. to test and optimize different versions of our online offering or its components.
For these purposes, so-called user profiles can be created and stored in a file (so-called "cookie") or similar procedures with the same purpose can be used. This information may include, for example, content viewed, websites visited and elements and technical data used there, such as the browser used, the computer system used and information on times of use. If users have consented to the collection of their location data, these may also be processed depending on the provider.
The IP addresses of the users are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect the user. In general, within the framework of web analysis, A/B testing and optimisation, no user data (such as e-mail addresses or names) is stored, but pseudonyms. This means that both we and the providers of the software used do not know the actual identity of the users, but only the data stored in their profiles for the purposes of the respective procedures.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing of data is consent. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Purposes of processing: measurement of reach (e.g. access statistics, recognition of returning visitors), tracking (e.g. interest/behavioural profiling, use of cookies), evaluation of visitor actions, profiling (creation of user profiles), interest-based and behavioural marketing.
-
Security measures: IP masking (pseudonymization of the IP address).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Google Optimize: Use of Google Analytics data for the purpose of improving areas of our online offering and improving the alignment of our marketing efforts with users' potential interests; service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://optimize.google.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: Opt-Out Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Advertising Display Settings: https://adssettings.google.com/authenticated.
ONLINE MARKETING
We process personal data for the purposes of online marketing, which may include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as "Content") based on the potential interests of users and the measurement of their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called "cookie") or similar procedures are used, by means of which the user information relevant for the presentation of the aforementioned content is stored. This information may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used and information on times of use. If users have consented to the collection of their location data, these can also be processed.
The IP addresses of the users are also stored. However, we use available IP masking methods (i.e. pseudonymisation by shortening the IP address) to protect the user. In general, within the framework of the online marketing procedure, no plain data of the users (such as e-mail addresses or names) is stored, but pseudonyms. This means that we as well as the providers of online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is usually stored in the cookies or by means of similar procedures. These cookies can later be generally used on other websites that use the same online marketing process, read out and analyzed for content display purposes as well as supplemented with other data and stored on the server of the online marketing process provider.
Exceptionally, plain data can be assigned to the profiles. This is the case, for example, if the users are members of a social network whose online marketing procedures we use and the network links the profiles of the users in the aforementioned information. We kindly ask you to note that users can make additional agreements with the providers, e.g. by consenting within the scope of registration.
As a matter of principle, we only gain access to summarised information about the success of our advertisements. However, within the framework of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. to the conclusion of a contract with us, for example. The conversion measurement is used alone to analyze the success of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used will be stored for a period of two years.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing of data is consent. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
Target group formation with Google Analytics: We use Google Analytics in order to display the ads placed by Google and its partners within advertising services only to users who have also shown an interest in our online services or who have certain characteristics (e.g. interests in certain topics or products which are determined on the basis of the websites visited) which we transmit to Google (so-called "remarketing" or "Google Analytics Audiences"). With the help of remarketing audiences, we also want to ensure that our ads match the potential interest of users
Google Universal Analytics: We use Google Analytics in the form of Universal Analytics (https://support.google.com/analytics/answer/2790010?hl=deef_topic=6010376). "Universal Analytics" refers to a Google Analytics process in which user analysis is performed on the basis of a pseudonymous user ID, thereby creating a pseudonymous profile of the user with information from the use of various devices (so-called "cross-device tracking").
Facebook pixels: With the help of Facebook pixels, Facebook is able on the one hand to determine the visitors of our online offering as the target group for the display of ads (so-called "Facebook ads"). Accordingly, we use Facebook pixels to display Facebook ads placed by us only to users on Facebook and within the services of partners cooperating with Facebook (so-called "audience network" https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who have certain characteristics (e.g. interest in certain topics or products that can be seen on the websites visited) that we transmit to Facebook (so-called "custom audiences"). With the help of Facebook pixels, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not appear annoying. The Facebook pixel also enables us to track the effectiveness of Facebook ads for statistical and market research purposes by seeing whether users were referred to our website after clicking on a Facebook ad (known as "conversion measurement").
Advanced Facebook pixel matching: When using the Facebook pixel, the additional function "extended comparison" is used. In this context, data, such as users' e-mail addresses or Facebook IDs, are transmitted to Facebook (encrypted) to form target groups.
Facebook - Target group education via data upload: Upload data such as telephone numbers, e-mail addresses or Facebook IDs to the Facebook platform. The data is encrypted here. The upload process is only used to display advertisements to the owners of the data or persons whose user profiles match any user profiles of the owners of the data on Facebook. This is to ensure that ads are only displayed to users who have an interest in our information and services.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), location data (data indicating the location of the end device of an end user), social data (data subject to social confidentiality (§ 35 SGB I) and processed, for example, by social insurance institutions, social welfare institutions or care authorities).
-
Affected persons: Users (e.g. website visitors, users of online services), interested parties, customers, employees (e.g. employees, applicants, former employees), communication partners.
-
Purposes of processing: Tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, evaluation of visitation campaigns, interest-based and behavioural marketing, profiling (creation of user profiles), conversion measurement (measurement of the effectiveness of marketing measures), range measurement (e.g. Access statistics, recognition of returning visitors), cross-device tracking (cross-device processing of user data for marketing purposes), target group formation (determination of target groups relevant for marketing purposes or other output of content), click tracking, direct marketing (e.g. by e-mail or post).
-
Security measures: IP masking (pseudonymization of the IP address).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
-
Opt-out: We refer you to the data protection information of the respective providers and the opt-out options provided by the providers. If no explicit opt-out option has been specified, it is possible to deactivate cookies in the settings of your browser. However, this may restrict the functions of our online offer. We therefore recommend the following additional opt-out options, which are offered in summary for each area: a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) Cross-regional: http://optout.aboutads.info.
Services and service providers used:
-
Google Tag Manager: Google Tag Manager is a solution that allows us to manage website tags through a single interface (including Google Analytics and other Google marketing services into our online offerings). The Tag Manager itself (which implements the tags) does not process any personal user data. With regard to the processing of users' personal data, reference is made to the following information on Google services. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active.
-
Google Analytics: online marketing and web analytics; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: Opt-Out-Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Settings for the Display of Advertisements: https://adssettings.google.com/authenticated.
-
Google Ads and Conversion Measurement: We use the online marketing method "Google Ads" to place ads on the Google Advertising Network (e.g., in search results, videos, web pages, etc.) so that they are displayed to users who have an alleged interest in the ads. We also measure the conversion of the ads. However, we only know the anonymous total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag. However, we ourselves do not receive any information that can be used to identify users. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active.
-
Google Ad Manager: We use the "Google Marketing Platform" (and services such as "Google Ad Manager") to place ads on the Google advertising network (e.g., in search results, in videos, on websites, etc.). The Google Marketing Platform is characterised by the fact that ads are displayed in real time according to the presumed interests of the users. This allows us to display ads for and within our online offering in a more targeted manner in order to present users only with ads that potentially match their interests. If, for example, a user is shown ads for products in which he is interested on other online offers, this is referred to as "remarketing". Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active.
-
Google Signals: Additional marketing options that only affect users who have enabled personalized ads on Google (https://support.google.com/ads/answer/2662856) and include device-based and cross-device data processing; service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://support.google.com/analytics/answer/7532985?hl=de; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: Opt-Out-Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Settings for the Display of Advertisements: https://adssettings.google.com/authenticated.
-
Facebook pixels: Facebook pixels; service providers: https://www.facebook.com, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.facebook.com/settings?tab=ads; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Privacy Policy: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: https://www.facebook.com/settings?tab=ads.
-
Amazon: Marketing of advertising materials and advertising space; service provider: Amazon Europe Core S.à.r.l., Amazon EU S.à.r.l., Amazon Services Europe S.à.r.l. and Amazon Media EU S.à.r.l., all four located at 38, avenue John F. Kennedy, L-1855 Luxembourg, and Amazon Instant Video Germany GmbH, Domagkstr. 28, 80807 Munich (together \"Amazon Europe\"), parent company: Amazon.com, Inc., 2021 Seventh Ave, Seattle, Washington 98121, USA; website: https://www.amazon.de; data protection declaration: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010; Privacy Shield (guaranteeing the level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4tatus=Active.
-
LinkedIn: Insights tag / conversion measurement; service provider: LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA; website: https://www.linkedin.com; security measures: IP masking (pseudonymisation of the IP address); privacy policy: https://www.linkedin.com/legal/privacy-policy, cookie policy: https://www.linkedin.com/legal/cookie_policy; privacy shield (guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0tatus=Active; opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
-
Microsoft Advertising: Microsoft Advertising; service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Website: https://about.ads.microsoft.com/; Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000KzNaAAKtatus=Active; Opt-Out: http://choice.microsoft.com/de-DE/opt-out.
-
Outbrain: display personalized advertisements; service provider: Outbrain Inc, 39 West 13th Street, 3rd floor, New York, NY 10011, USA; website: https://www.outbrain.com; privacy policy: https://www.outbrain.com/legal/privacy; standard contractual clauses (guarantee of data protection level when processing in a third country): use in contracts with Outbrain service providers; deletion of data: The stored personal data will be deleted or anonymized after 13 months.
-
Pinterest Web Analytics: online marketing and web analytics; service provider: Pinterest Inc. 635 High Street, Palo Alto, CA, 94301, USA; Website: https://analytics.pinterest.com/; Privacy Policy: https://about.pinterest.com/de/privacy-policy.
OFFER AN AFFILIATE PROGRAM
We offer an affiliate program, i.e., commissions or other benefits (collectively referred to as "Commission") to users (collectively referred to as "Affiliates") who refer to our offers and services. The reference is made through a link associated with the Affiliate or other methods (e.g., discount codes) that allow us to recognize that the use of our services was based on the reference (collectively, "Affiliate Links").
In order to track whether users have perceived our services based on affiliate links used by affiliates, it is necessary for us to know that users have followed an affiliate link. The assignment of the affiliate links to the respective business transactions or to the other use of our services serves solely the purpose of the commission settlement and is cancelled as soon as it is no longer necessary for the purpose.
For the purposes of the aforementioned assignment of affiliate links, the affiliate links may be supplemented by certain values that are part of the link or can otherwise be stored, e.g. in a cookie. The values may include in particular the source website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer and an online identifier of the user.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing of data is consent. Furthermore, their use can be a component of our (pre)contractual services, provided that the use of the third party was agreed within this framework. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
-
Processed data types: contract data (e.g. subject matter of contract, duration, customer category), usage data (e.g. websites visited, interest in content, access times).
-
Affected persons: Users (e.g. website visitors, users of online services), business partners and contractual partners.
-
Purposes of processing: contractual services and service, affiliate tracking.
-
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), performance of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f DSGVO).
REVIEW PLATFORMS
We participate in assessment procedures to evaluate, optimise and promote our services. If users evaluate us via the participating evaluation platforms or procedures or give us feedback in any other way, the General Terms and Conditions of Business or Use and the data protection notices of the providers also apply. As a rule, this Reviews also requires registration with the respective providers.
In order to ensure that the evaluators have actually made use of our services, we transmit the necessary data regarding the customer and the service used to the respective evaluation platform (including name, e-mail address and order number or article number) with the consent of the customer. This data is used solely to verify the authenticity of the user.
Rating widget: We include so-called "rating widgets" in our online offer. A widget is a functional and content element integrated into our online offer that displays variable information. It can, for example, be displayed in the form of a seal or comparable element, sometimes also called a "badge". Although the corresponding content of the widget is displayed within our online offer, it is called up at that moment by the servers of the respective widget provider. Only in this way can the current content always be displayed, especially the current Reviews. For this purpose, a data connection must be established from the website called up within our online offer to the widget provider's server and the widget provider receives certain technical data (access data, including IP address), which are necessary to deliver the widget's content to the user's browser.
In addition, the widget provider receives information that users have visited our online services. This information may be stored in a cookie and used by the widget provider to identify which online offerings participating in the review process have been visited by the user. The information can be stored in a user profile and used for advertising or market research purposes.
-
Processed data types: contract data (e.g. subject matter of contract, duration, customer category), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Customers, users (e.g. website visitors, users of online services).
-
Purposes of processing: Feedback (e.g. collecting feedback via an online form), measurement of reach (e.g. access statistics, recognition of returning visitors), evaluation of visitor actions, interest based and behaviour based marketing, profiling (creation of user profiles).
-
Legal basis: consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
PRESENCE IN SOCIAL NETWORKS
We maintain online presences within social networks in order to communicate with the users active there or to offer information about us there.
We would like to point out that user data may be processed outside the European Union. This may entail risks for users, e.g. by making it more difficult to enforce users' rights. With regard to US providers that are certified under the Privacy Shield or offer comparable guarantees of a secure level of data protection, we would like to point out that by doing so they commit themselves to complying with EU data protection standards.
In addition, user data is usually processed within social networks for market research and advertising purposes. For example, user profiles can be created on the basis of user behaviour and the resulting interests of users. The user profiles can in turn be used, for example, to place advertisements within and outside the networks which are presumed to correspond to the interests of the users. For these purposes, cookies are usually stored on the user's computer, in which the user's usage behaviour and interests are stored. Furthermore, data may be stored in the user profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the possibilities for objection (opt-out), we refer to the data protection declarations and information of the operators of the respective networks.
Also in the case of requests for information and the assertion of rights of data subjects, we point out that these can be asserted most effectively with the providers. Only the providers have access to the data of the users and can directly take appropriate measures and provide information. If you still need help, please do not hesitate to contact us.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Users (e.g. website visitors, users of online services).
-
Purposes of processing: contact enquiries and communication, tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, range measurement (e.g. access statistics, recognition of returning visitors).
-
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO).
Services and service providers used:
-
Instagram : Social Network; Service Provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; Website: https://www.instagram.com; Privacy Policy: http://instagram.com/about/legal/privacy.
-
Facebook: Social network; service provider: Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Statement: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: Advertisement Settings: https://www.facebook.com/settings?tab=ads; Additional Privacy Notice: Agreement on the Shared Processing of Personal Information on Facebook Pages: https://www.facebook.com/legal/terms/page_controller_addendum; Privacy Notice for Facebook Pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
-
LinkedIn: Social Network; Service Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Statement: https://www.linkedin.com/legal/privacy-policy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0tatus=Active; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
-
Pinterest: social network; service provider: Pinterest Inc. 635 High Street, Palo Alto, CA, 94301, USA; website: https://www.pinterest.com; privacy policy: https://about.pinterest.com/de/privacy-policy; opt-out: https://about.pinterest.com/de/privacy-policy.
-
Twitter: social network; service provider: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Privacy Statement: https://twitter.com/de/privacy, (Settings) https://twitter.com/personalization; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAOtatus=Active.
-
YouTube: Social network; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: https://adssettings.google.com/authenticated.
-
Xing: social network; service provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany; Website: https://www.xing.de; Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung.
PLUGINS AND EMBEDDED FUNCTIONS AND CONTENT
We include in our online offer functional and content elements that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may, for example, be graphics, videos or social media buttons as well as contributions (hereinafter uniformly referred to as "Content").
The integration always presupposes that the third party providers of this content process the IP address of the user, since they could not send the content to their browser without the IP address. The IP address is therefore required for the presentation of these contents or functions. We strive to use only those contents, whose respective offerers use the IP address only for the distribution of the contents. Third parties may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain technical information about the browser and operating system, websites to be referred to, visiting times and other information about the use of our online services, as well as may be linked to such information from other sources.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing of data is consent. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), inventory data (e.g. names, addresses).
-
Affected persons: Users (e.g. website visitors, users of online services), communication partners.
-
Purposes of processing: provision of our online services and user-friendliness, contractual services and support, contact enquiries and communication, direct marketing (e.g. by e-mail or post), tracking (e.g. interest/behavioural profiling, use of cookies), interest-based and behavioural marketing, profiling (creation of user profiles), security measures, administration and response to enquiries.
-
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. DSGVO), consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), fulfilment of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. DSGVO).
Services and service providers used:
-
Facebook Social Plugins: Facebook Social Plugins - This can include content such as images, videos or text and buttons with which users can share content from this online service within Facebook. The list and appearance of Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/; Service Providers: https://www.facebook.com, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent Company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active; Opt-Out: Settings for Advertisements: https://www.facebook.com/settings?tab=ads.
-
Google Fonts: We integrate the fonts ("Google Fonts") of the provider Google, whereby the data of the users are used solely for purposes of the representation of the fonts in the browser of the users. The integration takes place on the basis of our legitimate interests in a technically secure, maintenance-free and efficient use of fonts, their uniform presentation and taking into account possible licensing restrictions for their integration. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://fonts.google.com/; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TRkEAAWtatus=Active.
-
Google Maps: We integrate the maps of the service "Google Maps" of the provider Google. The data processed may include, in particular, IP addresses and location data of users, which are not collected without their consent (usually within the framework of the settings of their mobile devices). Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://maps.google.de; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TRkEAAWtatus=Active; Opt-Out: Opt-Out-Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Settings for the Display of Advertisements: https://adssettings.google.com/authenticated.
-
Instagram plugins and buttons: Instagram Plugins and Buttons - This can include content such as images, videos, or text and buttons with which users can share content from this online offering within Instagram. Service Provider: https://www.instagram.com, Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; Web Site: https://www.instagram.com; Privacy Statement: http://instagram.com/about/legal/privacy.
-
LinkedIn plugins and buttons: LinkedIn Plugins and Buttons - This can include content such as images, videos or text and buttons with which users can share content from this online offering within LinkedIn. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.instagram.com; Privacy Statement: https://www.linkedin.com/legal/privacy-policy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0tatus=Active; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
-
Pinterest Plugins and Buttons: Pinterest Plugins and Buttons - This can include content such as images, videos or text and buttons with which users can share content of this online offer within Pinterest. Service provider: Pinterest Inc. 635 High Street, Palo Alto, CA, 94301, USA; Website: https://www.pinterest.com; Privacy Policy: https://about.pinterest.com/de/privacy-policy.
-
ReCaptcha: We integrate the function "ReCaptcha" for the recognition of bots, e.g. for entries in online forms. The behaviour data of the users (e.g. mouse movements or queries) are evaluated in order to be able to distinguish people from bots. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.google.com/recaptcha/; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TRkEAAWtatus=Active; Opt-Out: Opt-Out Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Advertising Display Settings: https://adssettings.google.com/authenticated.
-
Twitter plugins and buttons: Twitter plugins and buttons - This may include content such as images, videos or text and buttons with which users can share content from this online service within Twitter. Service provider: Twitter Inc. 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Website: https://twitter.com/de; Privacy Policy: https://twitter.com/de/privacy.
-
YouTube: Videos; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com; Privacy Statement: https://policies.google.com/privacy; Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active; Opt-Out: Opt-Out-Plugin: http://tools.google.com/dlpage/gaoptout?hl=de; Settings for the Display of Advertisements: https://adssettings.google.com/authenticated.
-
Vimeo: video platform; service provider: Vimeo Inc, Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA; Website: https://vimeo.com; Privacy Policy: https://vimeo.com/privacy; Opt-Out: We point out that Vimeo may use Google Analytics and refer to the Privacy Policy (https://policies.google.com/privacy) as well as the Opt-Out options for Google Analytics (http://tools.google.com/dlpage/gaoptout?hl=de) or the Google settings for data use for marketing purposes (https://adssettings.google.com/).
PLANNING, ORGANISATION AND AUXILIARY TOOLS
We use services, platforms and software from other providers (hereinafter referred to as "Third Party Providers") for the purposes of organizing, administering, planning and providing our services. When selecting third-party providers and their services, we observe the legal requirements.
Within this framework, personal data may be processed and stored on the servers of third parties. This may affect various data that we process in accordance with this privacy statement. This data may include in particular master data and contact data of users, data on processes, contracts, other processes and their contents.
If users are referred to third parties or their software or platforms as part of communication, business or other relationships with us, the third parties may process usage data and metadata for security, service optimisation or marketing purposes. We therefore ask you to observe the data protection information of the respective third party providers.
Information on legal bases: If we ask the users for their consent to the use of third party providers, the legal basis of the processing of data is consent. Furthermore, their use can be a component of our (pre)contractual services, provided that the use of the third party was agreed within this framework. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
-
Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text input, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
-
Affected persons: Communication partners, users (e.g. website visitors, users of online services).
-
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a DSGVO), performance of contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b DSGVO), legitimate interests (Art. 6 para. 1 sentence 1 lit. f DSGVO).
DELETION OF DATA
The data processed by us will be deleted in accordance with the statutory provisions as soon as their consent permitted for processing is revoked or other permissions lapse (e.g. if the purpose of processing this data has lapsed or it is not necessary for the purpose).
If the data are not deleted because they are required for other and legally permissible purposes, their processing is limited to these purposes. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax reasons or whose storage is necessary to assert, exercise or defend legal claims or to protect the rights of another natural or legal person.
Further information on the deletion of personal data can also be found in the individual data protection notices of this data protection declaration.
MODIFICATION AND UPDATING OF THE DATA PROTECTION DECLARATION
We ask you to inform yourself regularly about the content of our data protection declaration. We will adapt the data protection declaration as soon as changes in the data processing we carry out make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, we ask you to note that addresses may change over time and to verify the information before contacting us.
RIGHTS OF DATA SUBJECTS
Under the DSGVO, they are entitled to various rights as affected parties, which result in particular from Articles 15 to 18 and 21 DSGVO:
- Right of objection: You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you on the basis of Art. 6 para. 1 lit. e or f DSGVO; this also applies to profiling based on these provisions. If the personal data concerning you are processed for the purpose of direct advertising, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such advertising; this also applies to profiling to the extent that it is connected with such direct advertising.
- Right of withdrawal for consents: You have the right to revoke your consent at any time.
- Right of access: You have the right to obtain confirmation as to whether the data in question will be processed and to obtain access to such data, as well as further information and a copy of the data in accordance with the provisions of the law.
- Right of rectification: You have the right, in accordance with the law, to request the completion of data concerning you or the rectification of incorrect data concerning you.
- Right to deletion and limitation of processing: You have the right, in accordance with the statutory provisions, to demand that data concerning you be deleted immediately or, alternatively, to demand a limitation of data processing in accordance with the statutory provisions.
- Right to data transfer: You have the right to receive data concerning you which you have provided to us in a structured, common and machine-readable format in accordance with the legal requirements, or to demand that it be transferred to another responsible party.
- Complaint to the supervisory authority: You also have the right, in accordance with the statutory provisions, to complain to a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement was committed, if you are of the opinion that the processing of your personal data is in breach of the DSGVO.
DEFINITIONS OF TERMS
This section provides an overview of the terms used in this privacy statement. Many of the terms are taken from the law and defined above all in Art. 4 DSGVO. The legal definitions are binding. The following explanations, on the other hand, are intended above all for the sake of understanding. The terms are sorted alphabetically.
- Affiliate tracking: As part of affiliate tracking, links are logged with the help of which the linking websites refer users to websites with product or other offers. The operators of the respective linked websites can receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g. buy goods or use services). To this end, it is necessary for providers to be able to track whether users who are interested in certain offers subsequently perceive them at the instigation of the affiliate links. It is therefore necessary for the functionality of affiliate links that they are supplemented by certain values that become part of the link or are otherwise stored, e.g. in a cookie. The values include in particular the source website (referrer), the time, an online identification of the operator of the website on which the affiliate link was located, an online identification of the respective offer, an online identification of the user as well as tracking specific values, such as advertising material ID, partner ID and categorizations.
- Conversion Tracking: The term "Conversion Tracking" refers to a process by which the effectiveness of marketing measures can be determined. As a rule, a cookie is stored on the devices of the users within the websites on which the marketing measures take place and then called up again on the target website. For example, we can track whether the ads we placed on other websites were successful).
- Cross-Device Tracking: Cross-Device Tracking is a form of tracking in which the behavior and interest information of users is recorded across all devices in so-called profiles by assigning an online identifier to the users. This means that user information can usually be analysed for marketing purposes regardless of the browser or device used (e.g. mobile phone or desktop computer). With most providers, the online identifier is not linked to plain data such as names, postal addresses or e-mail addresses.
- IP masking: IP masking is a method by which the last octet, i.e. the last two numbers of an IP address, is deleted so that the IP address can no longer be used to uniquely identify a person. IP masking is therefore a means of pseudonymizing processing methods, especially in online marketing.
- Interest-based and behavioral marketing: Interest-based and/or behavioral marketing is the term used when potential interests of users in ads and other content are determined as precisely as possible. This is done on the basis of information on their previous behaviour (e.g. visiting certain websites and staying on them, purchasing behaviour or interaction with other users), which is stored in a so-called profile. Cookies are generally used for these purposes.
- Click tracking: Clicktracking makes it possible to keep track of the movements of users within an entire online offering. Since the results of these tests are more accurate if the interaction of the users can be tracked over a period of time (e.g. to find out if a user would like to return), cookies are usually stored on the user's computer for these test purposes.
- Conversion measurement: Conversion measurement is a method by which the effectiveness of marketing measures can be determined. As a rule, a cookie is stored on the devices of the users within the websites on which the marketing measures take place and then called up again on the target website. For example, we can track whether the ads we placed on other websites were successful.
- Personal data: 'personal data' means any information relating to an identified or identifiable natural person (hereinafter 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more particular characteristics which express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
- Profiling: "Profiling" means any automated processing of personal data consisting of the use of such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (including, depending on the type of profiling, information relating to age, gender, location and movement data, interaction with websites and their content, shopping behaviour, social interactions with other people) (e.g. interest in certain content or products, click behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Range measurement: Range measurement (also known as web analytics) is used to evaluate the flow of visitors to an online offering and may include the behaviour or interests of visitors in certain information, such as the content of websites. With the help of reach analysis, website owners can recognize, for example, at what time visitors visit their website and what content they are interested in. This allows them, for example, to better adapt the content of the website to the needs of their visitors. For purposes of range analysis, pseudonymous cookies and web beacons are frequently used in order to recognise returning visitors and thus obtain more precise analyses of the use of an online offer.
- Remarketing: Remarketing or retargeting is the term used, for example, to indicate for advertising purposes which products a user is interested in on a website in order to remind the user of these products on other websites, e.g. in advertisements.
- Tracking: The term "tracking" is used when the behaviour of users can be traced across several online offers. As a rule, with regard to the online offers used, behavioural and interest information is stored in cookies or on the servers of the tracking technology providers (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to match their interests.
- Data controller: a "data controller" is a natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
- Processing: "processing" means any operation or set of operations which is carried out with or without the aid of automated processes and which is related to personal data. The term reaches far and covers practically every handling of data, be it collection, evaluation, storage, transmission or deletion.
- Target group formation: Target group formation (or "Custom Audiences") is the term used when target groups are determined for advertising purposes, e.g. insertion of advertisements. For example, a user's interest in certain products or topics on the Internet may be used to infer that that user is interested in advertisements for similar products or the online store in which they viewed the products. Lookalike audiences" (or similar target groups) are those content that is considered suitable is displayed to users whose profiles or interests presumably correspond to the users for whom the profiles were created. Cookies and web beacons are generally used for the purpose of creating custom audiences and lookalike audiences.