Privacy Policy

Introduction and Overview

We have written this privacy policy (version 02.07.2026-113224532) in order to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (referred to below simply as "data") we, as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future, and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We inform you comprehensively about the data we process about you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, by contrast, is intended to describe the most important things to you as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. In this way we inform you in clear and simple language that, in the course of our business activities, we only process personal data if a corresponding legal basis exists. This is certainly not possible if you provide the most concise, unclear and legal-technical explanations possible, as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or another piece of information among them that you did not yet know.
If questions nevertheless remain, we would like to ask you to contact the responsible body named below or in the legal notice (Impressum), to follow the links provided and to look at further information on third-party sites. You will of course also find our contact details in the legal notice.

Scope

This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy policy includes:

  • all online presences (websites, online shops) that we operate
  • social media presences and email communication
  • mobile apps for smartphones and other devices

In short: The privacy policy applies to all areas in which personal data is processed within the company in a structured manner via the channels mentioned. Should we enter into legal relationships with you outside of these channels, we will inform you separately where necessary.

Legal Bases

In the following privacy policy we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, that enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this General Data Protection Regulation of the EU online on EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.

We only process your data if at least one of the following conditions applies:

  1. Consent (Article 6 paragraph 1 lit. a GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
  2. Contract (Article 6 paragraph 1 lit. b GDPR): In order to fulfil a contract or pre-contractual obligations with you, we process your data. If, for example, we conclude a purchase contract with you, we need personal information in advance.
  3. Legal obligation (Article 6 paragraph 1 lit. c GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for our accounting. These generally contain personal data.
  4. Legitimate interests (Article 6 paragraph 1 lit. f GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we have to process certain data in order to be able to operate our website securely and in an economically efficient manner. This processing is therefore a legitimate interest.

Further conditions such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, do not generally arise for us. Should such a legal basis nevertheless be relevant, it will be indicated at the appropriate place.

In addition to the EU regulation, national laws also apply:

  • In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated DSG.
  • In Germany the Federal Data Protection Act, abbreviated BDSG, applies.

Insofar as further regional or national laws apply, we will inform you about them in the following sections.

Storage Period

That we only store personal data for as long as is absolutely necessary for the provision of our services and products is a general criterion for us. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases we are legally obliged to store certain data even after the original purpose has ceased to apply, for example for accounting purposes.

Should you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.

We will inform you further below about the specific duration of the respective data processing, insofar as we have further information on this.

Rights under the General Data Protection Regulation

In accordance with Articles 13 and 14 GDPR, we inform you about the following rights to which you are entitled so that fair and transparent processing of data takes place:

  • In accordance with Article 15 GDPR, you have a right of access as to whether we process data about you. If that is the case, you have the right to receive a copy of the data and to obtain the following information:
    • for what purpose we carry out the processing;
    • the categories, i.e. the types of data, that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data is stored;
    • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
    • that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
    • the origin of the data, if we did not collect it from you;
    • whether profiling is carried out, i.e. whether data is automatically evaluated in order to arrive at a personal profile of you.
  • In accordance with Article 16 GDPR, you have a right to rectification of the data, which means that we have to correct data if you find errors.
  • In accordance with Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.
  • In accordance with Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it further.
  • In accordance with Article 20 GDPR, you have the right to data portability, which means that on request we will provide you with your data in a common format.
  • In accordance with Article 21 GDPR, you have a right to object, which, once enforced, brings about a change to the processing.
    • If the processing of your data is based on Article 6 para. 1 lit. e (public interest, exercise of official authority) or Article 6 para. 1 lit. f (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
    • If data is used to conduct direct advertising, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
    • If data is used to conduct profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
  • In accordance with Article 22 GDPR, you may under certain circumstances have the right not to be subject to a decision based solely on automated processing (for example profiling).
  • In accordance with Article 77 GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights – do not hesitate to contact the responsible body listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can lodge a complaint with the supervisory authority. For Austria this is the Data Protection Authority, whose website you can find at https://www.dsb.gv.at/. In Germany there is a data protection officer for each federal state. For further information you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:

Austria Data Protection Authority

Head: Dr. Matthias Schmidl
Address:
Barichgasse 40-42, 1030 Vienna
Phone no.:
+43 1 52 152-0
Email address:
dsb@dsb.gv.at
Website:
https://www.dsb.gv.at/

Security of Data Processing

In order to protect personal data, we have implemented both technical and organisational measures. Where possible for us, we encrypt or pseudonymise personal data. In this way we make it as difficult as possible, within the scope of our means, for third parties to infer personal information from our data.

Art. 25 GDPR speaks here of "data protection by design and by default" and means that both software (e.g. forms) and hardware (e.g. access to the server room) should always be developed with security in mind and appropriate measures taken. Below we go into specific measures where necessary.

TLS Encryption with https

TLS, encryption and https sound very technical, and they are. We use HTTPS (the Hypertext Transfer Protocol Secure stands for "secure hypertext transfer protocol") to transmit data securely on the internet, safe from eavesdropping.
This means that the complete transmission of all data from your browser to our web server is secured – no one can "listen in".

With this we have introduced an additional layer of security and fulfil data protection by design (Article 25 paragraph 1 GDPR). By using TLS (Transport Layer Security), an encryption protocol for the secure transmission of data on the internet, we can ensure the protection of confidential data.
You can recognise the use of this safeguarding of data transmission by the small padlock symbol at the top left of the browser, to the left of the internet address (e.g. examplepage.com) and the use of the https scheme (instead of http) as part of our internet address.
If you would like to know more about encryption, we recommend a Google search for "Hypertext Transfer Protocol Secure wiki" to obtain good links to further information.

Communication

Communication Summary
👥 Data subjects: All those who communicate with us by telephone, email or online form
📓 Processed data: e.g. telephone number, name, email address, entered form data. You can find more details on this under the respective type of contact used
🤝 Purpose: Handling of communication with customers, business partners, etc.
📅 Storage period: Duration of the business case and the statutory provisions
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. b GDPR (contract), Art. 6 para. 1 lit. f GDPR (legitimate interests)

When you contact us and communicate by telephone, email or online form, personal data may be processed.

The data is processed for the handling and processing of your question and the associated business transaction. The data is stored for exactly that long, or for as long as the law requires.

Data Subjects

All those who seek contact with us via the communication channels we provide are affected by the aforementioned processes.

Telephone

When you call us, the call data is stored in pseudonymised form on the respective end device and by the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by email and stored in order to answer the enquiry. The data is deleted as soon as the business case has ended and legal requirements permit.

Email

When you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted as soon as the business case has ended and legal requirements permit.

Online Forms

When you communicate with us by means of an online form, data is stored on our web server and may be forwarded to an email address of ours. The data is deleted as soon as the business case has ended and legal requirements permit.

Legal Bases

The processing of the data is based on the following legal bases:

  • Art. 6 para. 1 lit. a GDPR (consent): You give us your consent to store your data and to use it further for purposes relating to the business case;
  • Art. 6 para. 1 lit. b GDPR (contract): There is a need for the fulfilment of a contract with you or with a processor such as the telephone provider, or we have to process the data for pre-contractual activities, such as the preparation of an offer;
  • Art. 6 para. 1 lit. f GDPR (legitimate interests): We want to conduct customer enquiries and business communication in a professional setting. For this, certain technical facilities such as email programs, Exchange servers and mobile network operators are necessary in order to be able to conduct communication efficiently.

Cookies

Cookies Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: depending on the respective cookie. You can find more details on this below or from the manufacturer of the software that sets the cookie.
📓 Processed data: Depending on the respective cookie used. You can find more details on this below or from the manufacturer of the software that sets the cookie.
📅 Storage period: depending on the respective cookie, can vary from hours to years
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What are Cookies?

Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used, so that you can better understand the following privacy policy.

Whenever you surf the internet, you use a browser. Well-known browsers are, for example, Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, since there are also other cookies for other areas of application. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, effectively the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data of yours, such as language or personal page settings. When you call up our page again, your browser transmits the "user-related" information back to our page. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our page, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be assessed individually, since each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain any viruses, Trojans or other "malware". Cookies also cannot access information on your PC.

Cookie data can look like this, for example:

Name: _ga
Value: GA1.2.1326744211.152113224532-9
Purpose: Distinguishing website visitors
Expiry date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What types of cookies are there?

The question of which cookies we use specifically depends on the services used and is clarified in the following sections of the privacy policy. At this point we would like to briefly address the different types of HTTP cookies.

One can distinguish 4 types of cookies:

Essential cookies
These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user places a product in the shopping cart, then continues browsing on other pages and only later goes to the checkout. Thanks to these cookies, the shopping cart is not deleted, even if the user closes their browser window.

Functional cookies
These cookies collect info about user behaviour and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behaviour of the website in different browsers.

Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are stored.

Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually adapted advertising to the user. This can be very practical, but also very annoying.

Usually, when you visit a website for the first time, you are asked which of these types of cookies you want to allow. And of course this decision is also stored in a cookie.

If you would like to know more about cookies and do not shy away from technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called "HTTP State Management Mechanism".

Purpose of the processing via cookies

The purpose ultimately depends on the respective cookie. You can find more details on this below or from the manufacturer of the software that sets the cookie.

Which data is processed?

Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalise which data is stored in cookies, but we will inform you in the course of the following privacy policy about the data processed or stored.

Storage period of cookies

The storage period depends on the respective cookie and is specified in more detail further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.

You also have your own influence on the storage period. You can manually delete all cookies at any time via your browser (see also "Right to object" below). Furthermore, cookies that are based on consent are deleted at the latest after you revoke your consent, whereby the lawfulness of the storage up to that point remains unaffected.

Right to object – how can I delete cookies?

How and whether you want to use cookies is up to you. Regardless of which service or which website the cookies come from, you always have the option to delete, deactivate or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to determine which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, enable and manage cookies in Chrome

Safari: Manage cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have placed on your computer

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete and manage cookies

If you generally do not want any cookies, you can set up your browser so that it always informs you when a cookie is to be set. This way, you can decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It is best to search for the instructions in Google using the search term "delete cookies Chrome" or "deactivate cookies Chrome" in the case of a Chrome browser.

Legal basis

The so-called "cookie directives" have existed since 2009. They state that the storage of cookies requires your consent (Article 6 para. 1 lit. a GDPR). Within the EU countries, however, there are still very different reactions to these directives. In Austria, this directive was implemented in Section 165 para. 3 of the Telecommunications Act (2021). In Germany, the cookie directives were not implemented as national law. Instead, this directive was largely implemented in Section 15 para. 3 of the Telemedia Act (TMG), which has been replaced since May 2024 by the Digital Services Act (DDG).

For absolutely necessary cookies, even where no consent is given, there are legitimate interests (Article 6 para. 1 lit. f GDPR), which in most cases are of an economic nature. We want to give visitors to the website a pleasant user experience, and for this certain cookies are often absolutely necessary.

Insofar as cookies that are not absolutely necessary are used, this only happens in the case of your consent. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR.

In the following sections you will be informed in more detail about the use of cookies, insofar as software used employs cookies.

Web Hosting Introduction

Web Hosting Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: professional hosting of the website and securing operation
📓 Processed data: IP address, time of the website visit, browser used and further data. You can find more details on this below or from the respective web hosting provider used.
📅 Storage period: depending on the respective provider, but generally 2 weeks
⚖️ Legal bases: Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is web hosting?

When you visit websites nowadays, certain information – including personal data – is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, incidentally, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) to the very last subpage (like this one here). By domain we mean, for example, example.com or samplesite.com.

When you want to view a website on a computer, tablet or smartphone, you use a program for this called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We refer to it as browser or web browser for short.

In order to display the website, the browser has to connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and demanding task, which is why this is usually undertaken by professional providers. They offer web hosting and thereby ensure reliable and error-free storage of the data of websites. A whole lot of technical terms, but please stay tuned, it gets better!

When the browser on your computer (desktop, laptop, tablet or smartphone) establishes a connection and during the data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server also has to store data for a while in order to ensure proper operation.

Why do we process personal data?

The purposes of the data processing are:

  1. Professional hosting of the website and securing operation
  2. to maintain operational and IT security
  3. Anonymous evaluation of access behaviour to improve our offering and, where applicable, for law enforcement or the pursuit of claims

Which data is processed?

Even while you are visiting our website right now, our web server, which is the computer on which this website is stored, generally automatically stores data such as

  • the complete internet address (URL) of the web page called up
  • browser and browser version (e.g. Chrome 87)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.examplesourcesite.com/whereicamefrom/)
  • the host name and the IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
  • date and time
  • in files, the so-called web server log files

How long is data stored?

As a rule, the above data is stored for two weeks and then automatically deleted. We do not pass this data on, but cannot rule out that this data may be viewed by authorities in the event of unlawful conduct.

In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without consent!

Legal basis

The lawfulness of processing personal data in the context of web hosting results from Art. 6 para. 1 lit. f GDPR (safeguarding legitimate interests), since the use of professional hosting with a provider is necessary in order to present the company on the internet securely and in a user-friendly manner and, where applicable, to pursue attacks and claims resulting from them.

Between us and the hosting provider there is generally a contract on order processing in accordance with Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.

Website Builder Systems Introduction

Website Builder Systems Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service
📓 Processed data: Data such as technical usage information like browser activity, clickstream activities, session heatmaps as well as contact data, IP address or your geographic location. You can find more details on this below in this privacy policy and in the privacy policy of the provider.
📅 Storage period: depends on the provider
⚖️ Legal bases: Art. 6 para. 1 lit. f GDPR (legitimate interests), Art. 6 para. 1 lit. a GDPR (consent)

What are website builder systems?

For our website we use a website builder system. Builder systems are special forms of a content management system (CMS). With a builder system, website operators can create a website very easily and without programming knowledge. In many cases, web hosts also offer builder systems. Through the use of a builder system, personal data about you can also be collected, stored and processed. In this data protection text we provide you with general information about data processing by builder systems. You can find more detailed information in the privacy policies of the provider.

Why do we use website builder systems for our website?

The biggest advantage of a builder system is its ease of use. We want to offer you a clear, simple and well-arranged website that we ourselves – without external support – can operate and maintain without problems. A builder system now offers many helpful functions that we can use even without programming knowledge. This enables us to design our web presence according to our wishes and to offer you an informative and pleasant time on our website.

Which data is stored by a builder system?

Which data exactly is stored naturally depends on the website builder system used. Each provider processes and collects different data of the website visitor. But as a rule, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your website visit is collected. Tracking data (e.g. browser activity, clickstream activities, session heatmaps, etc.) may also be processed. In addition, personal data may also be recorded and stored. This is mostly contact data such as email address, telephone number (if you have provided it), IP address and geographic location data. You can find out which data exactly is stored in the provider's privacy policy.

How long and where is the data stored?

We will inform you further below about the duration of the data processing in connection with the website builder system used, insofar as we have further information on this. You can find detailed information about it in the provider's privacy policy. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. It may be that the provider stores data about you according to its own criteria, over which we have no influence.

Right to object

You always have the right to information, rectification and erasure of your personal data. If you have questions, you can also contact those responsible for the website builder system used at any time. You can find contact details either in our privacy policy or on the website of the respective provider.

Cookies that providers use for their functions can be deleted, deactivated or managed in your browser. Depending on which browser you use, this works in different ways. However, please note that then, possibly, not all functions will work as usual any more.

Legal basis

We have a legitimate interest in using a website builder system in order to optimise our online service and to present it to you efficiently and in a user-friendly way. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use the builder system insofar as you have given consent.

Insofar as the processing of data is not absolutely necessary for the operation of the website, the data is only processed on the basis of your consent. This particularly concerns tracking activities. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR.

With this privacy policy we have brought you the most important general information regarding data processing. If you would like to inform yourself more precisely in this respect, you can find further information – where available – in the following section or in the provider's privacy policy.

WordPress.com Privacy Policy

WordPress.com Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service
📓 Processed data: Data such as technical usage information like browser activity, clickstream activities, session heatmaps as well as contact data, IP address or your geographic location. You can find more details on this below in this privacy policy.
📅 Storage period: It depends above all on the type of data stored and the specific settings.
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is WordPress?

For our website we use the well-known content management system WordPress.com. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

In 2003 the company saw the light of day and developed in a relatively short time into one of the best-known content management systems (CMS) worldwide. A CMS is software that supports us in designing our website and displaying content nicely and in an orderly manner. The content can be text, audio and video.
Through the use of WordPress, personal data about you can also be collected, stored and processed. As a rule, mainly technical data such as operating system, browser, screen resolution or hosting provider is stored. However, personal data such as IP address, geographic data or contact data may also be processed.

Why do we use WordPress on our website?

We have many strengths, but real programming is simply not one of our core competencies.

Nevertheless, we want to have a powerful and attractive website that we can also manage and maintain ourselves. With a website builder system or a content management system such as WordPress, exactly that is possible. With WordPress we do not have to be programming aces in order to be able to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without prior technical knowledge. If technical problems ever arise or we have special requirements for our website, there are still our specialists who feel at home in HTML, PHP, CSS and the like.

Through the ease of use and the comprehensive functions of WordPress, we can design our web presence according to our wishes and offer you good user-friendliness.

Which data is processed by WordPress?

The non-personal data includes, for example, technical usage information such as browser activity, clickstream activities, session heatmaps and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet provider and date of the page visit.

In addition, personal data is also recorded. This is primarily contact data (email address or telephone number, if you provide it), IP address or your geographic location.

WordPress can also use cookies to collect data. These frequently record data about your behaviour on our website. For example, it can be recorded which subpages you particularly like to view, how long you stay on individual pages, when you leave a page again (bounce rate) or which presettings (e.g. language selection) you have made. On the basis of this data, WordPress can also better adapt its own marketing measures to your interests and your user behaviour. The next time you visit our website, our website will consequently be displayed to you as you set it up beforehand.

WordPress can also use technologies such as pixel tags (web beacons), for example to clearly identify you as a user and possibly be able to offer interest-based advertising.

How long and where is the data stored?

How long the data is stored depends on various factors. So it depends above all on the type of data stored and the specific settings of the website. In principle, the data at WordPress is deleted when it is no longer needed for its own purposes. There are of course exceptions, especially when legal obligations require a longer retention of the data. Web server logs, which contain your IP address and technical data, are deleted by WordPress or Automattic after 30 days. For that long, Automattic uses the data to analyse the traffic on its own websites (for example all WordPress pages) and to remedy possible problems. Deleted content on WordPress websites is also kept in the trash for 30 days to enable recovery; after that it can remain in backups and caches until they are deleted. The data is stored on American servers of Automattic.

How can I delete my data or prevent data storage?

You have the right and the possibility at any time to access your personal data and to object to the use and processing of it. You can also lodge a complaint with a state supervisory authority at any time.

In your browser you also have the possibility to manage, delete or deactivate cookies individually. However, please take note that deactivated or deleted cookies have possible negative effects on the functions of our WordPress page. Depending on which browser you use, managing cookies works somewhat differently. Under the section "Cookies" you can find the corresponding links to the respective instructions of the best-known browsers.

Legal basis

If you have consented to WordPress being used, the legal basis of the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by WordPress.

On our part there is also a legitimate interest in using WordPress in order to optimise our online service and present it nicely for you. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use WordPress insofar as you have given consent.

WordPress or Automattic processes data about you, among other places, also in the USA. Automattic is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called standard contractual clauses (= Art. 46 paras. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Automattic undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=en

You can find more details about the privacy policy and which data is processed in what way by WordPress at https://automattic.com/privacy/.

Web Analytics Introduction

Web Analytics Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Evaluation of visitor information to optimise the web offering.
📓 Processed data: Access statistics that contain data such as locations of accesses, device data, access duration and time, navigation behaviour, click behaviour and IP addresses. You can find more details on this at the respective web analytics tool used.
📅 Storage period: depending on the web analytics tool used
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is web analytics?

On our website we use software to evaluate the behaviour of website visitors, called web analytics for short. In doing so, data is collected which the respective analytics tool provider (also called tracking tool) stores, manages and processes. With the help of the data, analyses of user behaviour on our website are created and made available to us as the website operator. In addition, most tools offer various testing options. For example, we can test which offers or content go down best with our visitors. For this, we show you two different offers for a limited period of time. After the test (so-called A/B test) we know which product or which content our website visitors find more interesting. For such test procedures, as well as for other analytics procedures, user profiles can also be created and the data stored in cookies.

Why do we conduct web analytics?

With our website we have a clear goal in mind: we want to deliver the best web offering on the market for our industry. To achieve this goal, we want on the one hand to offer the best and most interesting offer and on the other hand to ensure that you feel completely comfortable on our website. With the help of web analysis tools, we can take a closer look at the behaviour of our website visitors and then improve our web offering accordingly for you and us. For example, we can recognise how old our visitors are on average, where they come from, when our website is most visited or which content or products are particularly popular. All this information helps us to optimise the website and thus to best adapt it to your needs, interests and wishes.

Which data is processed?

Which data exactly is stored naturally depends on the analysis tools used. But as a rule it is stored, for example, which content you view on our website, which buttons or links you click, when you call up a page, which browser you use, with which device (PC, tablet, smartphone, etc.) you visit the website or which computer system you use. If you agreed that location data may also be collected, this too can be processed by the web analysis tool provider.

In addition, your IP address is also stored. In accordance with the General Data Protection Regulation (GDPR), IP addresses are personal data. Your IP address, however, is generally stored in pseudonymised form (i.e. in an unrecognisable and shortened form). For the purpose of the tests, the web analysis and the web optimisation, no direct data, such as your name, your age, your address or your email address, is generally stored. All this data, if it is collected, is stored in pseudonymised form. This way, you cannot be identified as a person.

How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website again, other cookies can store data over several years.

Duration of data processing

We will inform you about the duration of the data processing further below, insofar as we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. If, as for example in the case of accounting, it is legally required, this storage period can also be exceeded.

Right to object

You also have the right and the possibility at any time to revoke your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent the collection of data by cookies by managing, deactivating or deleting the cookies in your browser.

Legal basis

The use of web analytics requires your consent, which we have obtained with our cookie pop-up. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by web analytics tools.

In addition to consent, there is on our part a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of web analytics we recognise errors of the website, can identify attacks and improve profitability. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use the tools insofar as you have given consent.

Since cookies are used with web analytics tools, we also recommend that you read our general privacy policy on cookies. To find out which data about you exactly is stored and processed, you should read through the privacy policies of the respective tools.

Information on specific web analytics tools you will receive – where available – in the following sections.

Google Analytics Privacy Policy

Google Analytics Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Evaluation of visitor information to optimise the web offering.
📓 Processed data: Access statistics that contain data such as locations of accesses, device data, access duration and time, navigation behaviour and click behaviour. You can find more details on this below in this privacy policy.
📅 Storage period: individually adjustable; by default Google Analytics 4 stores data for 14 months
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is Google Analytics?

On our website we use the analysis tracking tool Google Analytics in the version Google Analytics 4 (GA4) of the American company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. Through the combination of various technologies such as cookies, device IDs and login information, you can be identified as a user across different devices. This means your actions can also be analysed across platforms.

If, for example, you click a link, this event is stored in a cookie and sent to Google Analytics. With the help of the reports we receive from Google Analytics, we can better adapt our website and our service to your wishes. Below we go into the tracking tool in more detail and inform you above all about which data is processed and how you can prevent this.

Google Analytics is a tracking tool that serves the traffic analysis of our website. The basis of these measurements and analyses is a pseudonymous user identification number. This number does not contain any personal data such as name or address, but serves to assign events to an end device. GA4 uses an event-based model that records detailed information about user interactions such as page views, clicks, scrolling, conversion events. In addition, various machine learning functions have been built into GA4 in order to better understand user behaviour and certain trends. With the help of machine learning functions, GA4 relies on modelling. This means that on the basis of the collected data, missing data can also be extrapolated in order to optimise the analysis and also to be able to give forecasts.

In order for Google Analytics to work at all, a tracking code is built into the code of our website. When you visit our website, this code records various events that you carry out on our website. With the event-based data model of GA4, we as the website operator can define and track specific events in order to obtain analyses of user interactions. Thus, in addition to general information such as clicks or page views, special events that are important for our business can also be tracked. Such special events can be, for example, the submission of a contact form or the purchase of a product.

As soon as you leave our website, this data is sent to the Google Analytics servers and stored there.

Google processes the data and we receive reports about your user behaviour. These can include, among others, the following reports:

  • Audience reports: Through audience reports we get to know our users better and know more precisely who is interested in our service.
  • Advertising reports: Through advertising reports we can more easily analyse and improve our online advertising.
  • Acquisition reports: Acquisition reports give us helpful information about how we can inspire more people for our service.
  • Behaviour reports: Here we learn how you interact with our website. We can understand which path you take on our page and which links you click.
  • Conversion reports: A conversion is a process in which you carry out a desired action as a result of a marketing message. For example, when you go from being a mere website visitor to a buyer or newsletter subscriber. With the help of these reports we learn more about how our marketing measures go down with you. In this way we want to increase our conversion rate.
  • Real-time reports: Here we always learn immediately what is happening on our website right now. For example, we see how many users are reading this text right now.

In addition to the analysis reports mentioned above, Google Analytics 4 also offers, among others, the following functions:

  • Event-based data model: This model records very specific events that can take place on our website. For example, the playing of a video, the purchase of a product or signing up for our newsletter.
  • Advanced analysis functions: With these functions we can understand your behaviour on our website or certain general trends even better. For example, we can segment user groups, make comparative analyses of audiences or trace your path or route on our website.
  • Predictive modelling: On the basis of collected data, missing data can be extrapolated through machine learning, predicting future events and trends. This can help us to develop better marketing strategies.
  • Cross-platform analysis: The collection and analysis of data is possible from both websites and apps. This gives us the possibility to analyse user behaviour across platforms, provided of course that you have consented to the data processing.

Why do we use Google Analytics on our website?

Our goal with this website is clear: We want to offer you the best possible service. The statistics and data from Google Analytics help us to achieve this goal.

The statistically evaluated data shows us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimise our page so that it is more easily found by interested people on Google. On the other hand, the data helps us to understand you as a visitor better. We thus know very precisely what we have to improve on our website in order to offer you the best possible service. The data also serves us to carry out our advertising and marketing measures more individually and more cost-effectively. After all, it only makes sense to show our products and services to people who are interested in them.

Which data is stored by Google Analytics?

With the help of a tracking code, Google Analytics creates a random, unique ID that is connected to your browser cookie. This way, Google Analytics recognises you as a new user and a user ID is assigned to you. The next time you visit our page, you are recognised as a "returning" user. All collected data is stored together with this user ID. This is what first makes it possible to evaluate pseudonymous user profiles.

In order to be able to analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For every newly created property, the Google Analytics 4 property is the default. Depending on the property used, data is stored for different lengths of time.

Through markers such as cookies, app instance IDs, user IDs or custom event parameters, your interactions are measured across platforms, provided you have consented. Interactions are all types of actions that you carry out on our website. If you also use other Google systems (such as a Google account), data generated via Google Analytics can be linked with third-party cookies. Google does not pass on any Google Analytics data, unless we as the website operator approve it. Exceptions can occur if it is legally required.

According to Google, no IP addresses are logged or stored in Google Analytics 4. Google does, however, use the IP address data for deriving location data and deletes it immediately afterwards. All IP addresses collected from users in the EU are therefore deleted before the data is stored in a data centre or on a server.

Since with Google Analytics 4 the focus is on event-based data, the tool uses significantly fewer cookies compared to earlier versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies that are used by GA4. These include, for example:

Name: _ga
Value: 2.1326744211.152113224532-5
Purpose: By default, analytics.js uses the cookie _ga to store the user ID. In principle it serves to distinguish website visitors.
Expiry date: after 2 years

Name: _gid
Value: 2.1687193234.152113224532-1
Purpose: The cookie also serves to distinguish website visitors
Expiry date: after 24 hours

Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: Used to lower the request rate. If Google Analytics is provided via Google Tag Manager, this cookie is given the name _dc_gtm_ <property-id>.
Expiry date: after 1 minute

Note: This list cannot claim to be complete, as Google keeps changing its choice of cookies. The aim of GA4 is also to improve data protection. Therefore, the tool offers some possibilities for controlling data collection. For example, we can set the storage period ourselves and also control the data collection.

Here we show you an overview of the most important types of data that are collected with Google Analytics:

Heatmaps: Google creates so-called heatmaps. Through heatmaps you can see exactly the areas that you click. This way we get information about where you are "moving around" on our page.

Session duration: Google refers to session duration as the time you spend on our page without leaving the page. If you were inactive for 20 minutes, the session ends automatically.

Bounce rate: A bounce is when you view only one page on our website and then leave our website again.

Account creation: When you create an account or place an order on our website, Google Analytics collects this data.

Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, derivations for location data are used.

Technical information: Technical information includes, among other things, your browser type, your internet provider or your screen resolution.

Source of origin: Google Analytics, and of course us, is naturally also interested in which website or which advertising you came to our page through.

Further data are contact data, any ratings, the playing of media (e.g. when you play a video via our page), the sharing of content via social media or the adding to your favourites. The list does not claim to be complete and serves only as a general orientation of the data storage by Google Analytics.

How long and where is the data stored?

Google has its servers distributed all over the world. Here you can read exactly where the Google data centres are located: https://datacenters.google/

Your data is distributed across various physical data carriers. This has the advantage that the data can be retrieved faster and is better protected against manipulation. In every Google data centre there are corresponding emergency programs for your data. If, for example, the hardware at Google fails or natural disasters paralyse servers, the risk of a service interruption at Google nevertheless remains low.

The retention period of the data depends on the properties used. The storage period is always set individually for each single property. Google Analytics offers us four options for controlling the storage period:

  • 2 months: that is the shortest storage period.
  • 14 months: by default, the data at GA4 remains stored for 14 months.
  • 26 months: one can also store the data for 26 months.
  • Data is only deleted when we delete it manually

In addition, there is also the option that data is only deleted when you no longer visit our website within the period we have chosen. In this case, the retention period is reset each time you visit our website again within the specified period.

When the specified period has elapsed, the data is deleted once a month. This retention period applies to your data that is linked with cookies, user identification and advertising IDs (e.g. cookies of the DoubleClick domain). Report results are based on aggregated data and are stored independently of user data. Aggregated data is a merging of individual data into a larger unit.

How can I delete my data or prevent data storage?

Under the data protection law of the European Union, you have the right to obtain information about your data, to update it, to delete it or to restrict it. With the help of the browser add-on for deactivating Google Analytics JavaScript (analytics.js, gtag.js) you prevent Google Analytics 4 from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=en. Please note that this add-on only deactivates the data collection by Google Analytics.

If you generally want to deactivate, delete or manage cookies, you can find under the section "Cookies" the corresponding links to the respective instructions of the best-known browsers.

Legal basis

The use of Google Analytics requires your consent, which we have obtained with our cookie pop-up. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by web analytics tools.

In addition to consent, there is on our part a legitimate interest in analysing the behaviour of website visitors and thus improving our offering technically and economically. With the help of Google Analytics we recognise errors of the website, can identify attacks and improve profitability. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use Google Analytics insofar as you have given consent.

Google processes data about you, among other places, also in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 paras. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=en

You can find the Google Ads Data Processing Terms, which refer to the standard contractual clauses, at https://business.safety.google/intl/en/adsprocessorterms/.

We hope we were able to bring you the most important information regarding the data processing of Google Analytics. If you want to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/us/ and https://support.google.com/analytics/answer/6004245?hl=en.

If you want to learn more about the data processing, use the Google privacy policy at https://policies.google.com/privacy?hl=en.

Cookie Consent Management Platform Summary
👥 Data subjects: Website visitors
🤝 Purpose: Obtaining and managing consent to certain cookies and thus the use of certain tools
📓 Processed data: Data for managing the set cookie settings such as IP address, time of consent, type of consent, individual consents. You can find more details on this at the respective tool used.
📅 Storage period: Depends on the tool used; one must expect periods of several years
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is a Cookie Consent Management Platform?

On our website we use a Consent Management Platform (CMP) software that makes it easier for us and for you to handle the scripts and cookies used correctly and securely. The software automatically creates a cookie pop-up, scans and controls all scripts and cookies, offers a cookie consent that is necessary under data protection law for you, and helps us and you to keep an overview of all cookies. With most cookie consent management tools, all existing cookies are identified and categorised. You as the website visitor then decide yourself whether and which scripts and cookies you allow or do not allow.

Why do we use a cookie management tool?

Our goal is to offer you the best possible transparency in the area of data protection. We are also legally obliged to do so. We want to inform you as well as possible about all tools and all cookies that can store and process data about you. It is also your right to decide yourself which cookies you accept and which not. In order to grant you this right, we first have to know exactly which cookies have ended up on our website at all. Thanks to a cookie management tool, which regularly scans the website for all existing cookies, we know about all cookies and can provide you with information about them in compliance with the GDPR. Via the consent system, you can then accept or reject cookies.

Which data is processed?

Within the framework of our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. The declaration of your consent is stored so that we do not have to ask you on every new visit to our website and so that we can also prove your consent if legally necessary. This is stored either in an opt-in cookie or on a server. Depending on the provider of the cookie management tool, the storage period of your cookie consent varies. Usually this data (e.g. pseudonymous user ID, time of consent, details on the cookie categories or tools, browser, device information) is stored for up to two years.

Duration of data processing

We will inform you about the duration of the data processing further below, insofar as we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. Data that is stored in cookies is stored for different lengths of time. Some cookies are already deleted after leaving the website, others can be stored in your browser over several years. The exact duration of the data processing depends on the tool used; usually you should expect a storage period of several years. In the respective privacy policies of the individual providers you will generally receive exact information about the duration of the data processing.

Right to object

You also have the right and the possibility at any time to revoke your consent to the use of cookies. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent the collection of data by cookies by managing, deactivating or deleting the cookies in your browser.

Information on specific cookie management tools you will receive – where available – in the following sections.

Legal basis

If you consent to cookies, personal data about you is processed and stored via these cookies. If we are allowed to use cookies through your consent (Article 6 para. 1 lit. a GDPR), this consent is at the same time the legal basis for the use of cookies or the processing of your data. In order to be able to manage the consent to cookies and to be able to enable you to give consent, a cookie consent management platform software is used. The use of this software enables us to operate the website in a legally compliant manner in an efficient way, which represents a legitimate interest (Article 6 para. 1 lit. f GDPR).

Security & Anti-Spam

Security & Anti-Spam Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Cybersecurity
📓 Processed data: Data such as your IP address, name or technical data such as browser version
You can find more details on this below and in the individual data protection texts.
📅 Storage period: mostly the data is stored until it is no longer needed for the fulfilment of the service
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is security & anti-spam software?

With so-called security & anti-spam software, you and we can protect ourselves against various spam or phishing mails and possible other cyberattacks. By spam, one understands advertising mails from a mass mailing that one did not request oneself. Such mails are also called data junk and can also cause costs. Phishing mails, in turn, are messages that aim to build trust through fake messages or websites in order to obtain personal data. Anti-spam software generally protects against unwanted spam messages or malicious mails that could, for example, smuggle viruses into our system. We also use general firewall and security systems that protect our computers against unwanted network attacks.

Why do we use security & anti-spam software?

On our website we place particularly great value on security. After all, it is not only about our security but above all also about your security. Unfortunately, in the world of IT and the internet, cyber threats are now part of everyday life. Hackers often try, with the help of a cyberattack, to steal personal data from an IT system. And therefore a good defence system is absolutely necessary. A security system monitors all incoming and outgoing connections to our network or computer. So that we achieve even greater security against cyberattacks, we use, in addition to the standardised security systems on our computer, further external security services. Unauthorised traffic of data is thereby better prevented, and thus we protect ourselves against cybercrime.

Which data is processed by security & anti-spam software?

Which data exactly is collected and stored naturally depends on the respective service. We are, however, always endeavouring to use only programs that collect data very sparingly or store only data that is necessary for the fulfilment of the offered service. In principle, the service can store data such as name, address, IP address, email address and technical data such as browser type or browser version. Any performance and log data may also be collected in order to detect possible incoming threats in good time. This data is processed within the framework of the services and in compliance with the applicable laws. This also includes, in the case of US American providers (via the standard contractual clauses), the GDPR. These security services in some cases also cooperate with third-party providers who, under instruction and in accordance with the privacy policies and further security measures, can store and/or process data. The data storage mostly takes place via cookies.

Duration of data processing

We will inform you about the duration of the data processing further below, insofar as we have further information on this. For example, security programs store data until you or we revoke the data storage. In general, personal data is only stored for as long as is absolutely necessary for the provision of the services. In many cases we unfortunately lack precise information from the providers about the length of the storage.

Right to object

You also have the right and the possibility at any time to revoke your consent to the use of cookies or third-party providers of security software. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent the collection of data by cookies by managing, deactivating or deleting the cookies in your browser.

Since cookies may also be used with such security services, we recommend our general privacy policy on cookies. To find out which data about you exactly is stored and processed, you should read through the privacy policies of the respective tools.

Legal basis

We use the security services mainly on the basis of our legitimate interests (Art. 6 para. 1 lit. f GDPR) in a good security system against various cyberattacks.

Certain processing, in particular the use of cookies as well as the use of security functions, requires your consent. If you have consented that data about you may be processed and stored by embedded security services, this consent counts as the legal basis of the data processing (Art. 6 para. 1 lit. a GDPR). Most of the services we use set cookies in your browser in order to store data. For this reason, we recommend that you read our data protection text on cookies carefully and look at the privacy policy or the cookie policies of the respective service provider.

Information on specific tools you will receive – where available – in the following sections.

Google reCAPTCHA Privacy Policy

Google reCAPTCHA Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service and protection against cyberattacks
📓 Processed data: Data such as IP address, browser information, your operating system, limited location and usage data
You can find more details on this below in this privacy policy.
📅 Storage period: depending on the data stored
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is reCAPTCHA?

Our top priority is to secure and protect our website as best as possible for you and for us. To ensure this, we use Google reCAPTCHA of the company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With reCAPTCHA we can determine whether you really are a human being of flesh and blood and not a robot or other spam software. By spam we understand any, by electronic means, unwanted information that reaches us without being asked for. With the classic CAPTCHAs, you usually had to solve text or image puzzles for verification. With reCAPTCHA from Google, we mostly do not have to bother you with such puzzles. Here it is enough in most cases if you simply place a tick and thus confirm that you are not a bot. With the new Invisible reCAPTCHA version, you do not even have to place a tick any more. How exactly this works and above all which data is used for it, you will learn in the course of this privacy policy.

reCAPTCHA is a free captcha service from Google that protects websites against spam software and misuse by non-human visitors. This service is most frequently used when you fill out forms on the internet. A captcha service is a type of automatic Turing test that is intended to ensure that an action on the internet is carried out by a human and not by a bot. In the classic Turing test (named after the computer scientist Alan Turing), a human determines the distinction between bot and human. With captchas, the computer or a software program also takes this over. Classic captchas work with small tasks that are easy for humans to solve but present considerable difficulties for machines. With reCAPTCHA, you no longer have to actively solve puzzles. The tool uses modern risk techniques to distinguish humans from bots. Here you only have to tick the text field "I am not a robot", or with Invisible reCAPTCHA even that is no longer necessary. With reCAPTCHA, a JavaScript element is embedded in the source text and then the tool runs in the background and analyses your user behaviour. From these user actions, the software calculates a so-called captcha score. Google uses this score to calculate, even before the captcha input, how high the probability is that you are a human. reCAPTCHA, or captchas in general, are always used when bots could manipulate or misuse certain actions (such as registrations, surveys, etc.).

Why do we use reCAPTCHA on our website?

We only want to welcome humans of flesh and blood on our page. Bots or spam software of all kinds may confidently stay at home. Therefore we set all levers in motion to protect ourselves and to offer you the best possible user-friendliness. For this reason we use Google reCAPTCHA of the company Google. This way we can be pretty sure that we remain a "bot-free" website. Through the use of reCAPTCHA, data is transmitted to Google in order to determine whether you really are a human. reCAPTCHA thus serves the security of our website and consequently also your security. For example, without reCAPTCHA it could happen that during a registration a bot registers as many email addresses as possible in order to subsequently "spam" forums or blogs with unwanted advertising content. With reCAPTCHA we can avoid such bot attacks.

Which data is stored by reCAPTCHA?

reCAPTCHA collects personal data of users in order to determine whether the actions on our website really originate from humans. So the IP address and other data that Google needs for the reCAPTCHA service can be sent to Google. IP addresses are almost always previously shortened within the member states of the EU or other contracting states of the Agreement on the European Economic Area before the data ends up on a server in the USA. The IP address is not combined with other data from Google, provided you are not logged in with your Google account during the use of reCAPTCHA. First, the reCAPTCHA algorithm checks whether Google cookies from other Google services (YouTube, Gmail, etc.) are already placed on your browser. Subsequently, reCAPTCHA sets an additional cookie in your browser and captures a snapshot of your browser window.

The following list of collected browser and user data does not claim to be complete. Rather, they are examples of data that, to our knowledge, are processed by Google.

  • Referrer URL (the address of the page from which the visitor comes)
  • IP address (e.g. 256.123.123.1)
  • Info about the operating system (the software that enables the operation of your computer. Well-known operating systems are Windows, Mac OS X or Linux)
  • Cookies (small text files that store data in your browser)
  • Mouse and keyboard behaviour (every action that you carry out with the mouse or the keyboard is stored)
  • Date and language settings (which language or which date you have preset on your PC is stored)
  • All JavaScript objects (JavaScript is a programming language that enables web pages to adapt to the user. JavaScript objects can collect all kinds of data under one name)
  • Screen resolution (indicates how many pixels the image display consists of)

It is undisputed that Google uses and analyses this data even before you click on the "I am not a robot" tick. With the Invisible reCAPTCHA version, even the ticking is omitted and the entire recognition process runs in the background. How much and which data Google stores exactly, one does not learn from Google in detail.

The following cookies are used by reCAPTCHA: Here we refer to the reCAPTCHA demo version of Google at https://www.google.com/recaptcha/api2/demo. All these cookies require a unique identifier for tracking purposes. Here is a list of cookies that Google reCAPTCHA has set on the demo version:

Name: IDE
Value: WqTUmlnmv_qXyi_DGNPLESKnRNrpgXoy1K-pAZtAkMbHI-113224532-8
Purpose: This cookie is set by the company DoubleClick (also belongs to Google) in order to register and report the actions of a user on the website in dealing with advertisements. This way, advertising effectiveness can be measured and corresponding optimisation measures taken. IDE is stored in browsers under the domain doubleclick.net.
Expiry date: after one year

Name: 1P_JAR
Value: 2019-5-14-12
Purpose: This cookie collects statistics on website use and measures conversions. A conversion arises, for example, when a user becomes a buyer. The cookie is also used to display relevant advertisements to users. Furthermore, with the cookie one can avoid a user getting to see the same advertisement more than once.
Expiry date: after one month

Name: ANID
Value: U7j1v3dZa1132245320xgZFmiqWppRWKOr
Purpose: We were not able to find out much info about this cookie. In Google's privacy policy the cookie is mentioned in connection with "advertising cookies" such as "DSID", "FLC", "AID", "TAID". ANID is stored under the domain google.com.
Expiry date: after 9 months

Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: The cookie stores the status of a user's consent to the use of different Google services. CONSENT also serves security, in order to verify users, to prevent fraudulent use of login information and to protect user data against unauthorised attacks.
Expiry date: after 19 years

Name: NID
Value: 0WmuWqy113224532zILzqV_nmt3sDXwPeM5Q
Purpose: NID is used by Google to adapt advertisements to your Google search. With the help of the cookie, Google "remembers" your most frequently entered search queries or your earlier interaction with advertisements. This way you always get tailor-made advertisements. The cookie contains a unique ID in order to collect a user's personal settings for advertising purposes.
Expiry date: after 6 months

Name: DV
Value: gEAABBCjJMXcI0dSAAAANbqc113224532-4
Purpose: As soon as you have ticked the "I am not a robot" tick, this cookie is set. The cookie is used by Google Analytics for personalised advertising. DV collects information in anonymised form and is furthermore used to make user distinctions.
Expiry date: after 10 minutes

Note: This list cannot claim to be complete, as Google, from experience, keeps changing its choice of cookies.

How long and where is the data stored?

Through the embedding of reCAPTCHA, data about you is transmitted to the Google server. Where exactly this data is stored, Google does not make clear, even after repeated enquiries. Without having received confirmation from Google, it is to be assumed that data such as mouse interaction, dwell time on the website or language settings are stored on the European or American Google servers. The IP address that your browser transmits to Google is in principle not merged with other Google data from further Google services. If, however, you are logged in to your Google account during the use of the reCAPTCHA plug-in, the data is merged. For this, the differing data protection provisions of the company Google apply.

How can I delete my data or prevent data storage?

If you want no data about you and about your behaviour to be transmitted to Google, you have to log out of Google completely and delete all Google cookies before you visit our website or use the reCAPTCHA software. In principle, the data is automatically transmitted to Google as soon as you call up our page. To delete this data again, you have to contact Google support at https://support.google.com/?hl=en&tid=113224532.

So if you use our website, you agree that Google LLC and its representatives automatically collect, process and use data.

Please note that when using this tool, data about you can also be stored and processed outside the EU. Most third countries (including the USA) are, under current European data protection law, considered not secure. Data may therefore not simply be transferred to insecure third countries, stored and processed there, unless there are suitable safeguards (such as EU standard contractual clauses) between us and the non-European service provider.

Legal basis

If you have consented to Google reCAPTCHA being used, the legal basis of the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by Google reCAPTCHA.

On our part there is also a legitimate interest in using Google reCAPTCHA in order to optimise our online service and make it more secure. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use Google reCAPTCHA insofar as you have given consent.

Google processes data about you, among other places, also in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 paras. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=en

You can find the Google Ads Data Processing Terms, which refer to the standard contractual clauses, at https://business.safety.google/intl/en/adsprocessorterms/.

You can find out a little more about reCAPTCHA on the Google web developer page at https://developers.google.com/recaptcha/. Google does go into the technical development of reCAPTCHA in more detail here, but you will look in vain there too for precise information about data storage and data protection-relevant topics. A good overview of the fundamental use of data at Google can be found in the in-house privacy policy at https://policies.google.com/privacy.

Web Design Introduction

Web Design Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Improvement of the user experience
📓 Processed data: Which data is processed depends strongly on the services used. Mostly it is, for example, IP address, technical data, language settings, browser version, screen resolution and name of the browser. You can find more details on this at the respective web design tools used.
📅 Storage period: depending on the tools used
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is web design?

On our website we use various tools that serve our web design. Web design is not, as is often assumed, only about our website looking pretty, but also about functionality and performance. But of course, the appropriate appearance of a website is also one of the great goals of professional web design. Web design is a sub-area of media design and deals with both the visual and the structural and functional design of a website. The goal is to improve your experience on our website with the help of web design. In web design jargon, one speaks in this context of user experience (UX) and usability. User experience means all impressions and experiences that the website visitor has on a website. A sub-point of user experience is usability. This is about the user-friendliness of a website. Value is placed here above all on ensuring that content, subpages or products are clearly structured and that you easily and quickly find what you are looking for. In order to offer you the best possible experience on our website, we also use so-called web design tools from third-party providers. Under the category "web design", in this privacy policy, fall all services that improve our website in terms of design. These can be, for example, fonts, various plugins or other embedded web design functions.

Why do we use web design tools?

How you take in information on a website depends very strongly on the structure, the functionality and the visual perception of the website. Therefore, good and professional web design became ever more important for us too. We work constantly on the improvement of our website and see this also as an extended service for you as a website visitor. Furthermore, a beautiful and functioning website also has economic advantages for us. After all, you will only visit us and make use of our offers if you feel completely comfortable.

Which data is stored by web design tools?

When you visit our website, web design elements can be embedded in our pages that can also process data. Which data exactly is involved depends of course strongly on the tools used. Further below you can see exactly which tools we use for our website. We recommend that, for more detailed information about the data processing, you also read through the respective privacy policy of the tools used. There you mostly learn which data is processed, whether cookies are used and how long the data is kept. Through fonts such as Google Fonts, for example, information such as language settings, IP address, version of the browser, screen resolution of the browser and name of the browser is also automatically transmitted to the Google servers.

Duration of data processing

How long data is processed is very individual and depends on the web design elements used. If cookies are used, for example, the retention period can be only one minute, but also a few years. Please inform yourself about this. For this we recommend, on the one hand, our general text section on cookies as well as the privacy policies of the tools used. There you generally learn which cookies exactly are used and which information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve the loading time of a website. In principle, data is always only kept for as long as is necessary for the provision of the service. In the case of legal requirements, data can also be stored for longer.

Right to object

You also have the right and the possibility at any time to revoke your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. You can also prevent the collection of data by cookies by managing, deactivating or deleting the cookies in your browser. Under web design elements (mostly with fonts), however, there is also data that cannot be deleted quite so easily. That is the case when data is automatically collected directly upon a page call and transmitted to a third-party provider (such as Google). In that case, please contact the support of the respective provider. In the case of Google, you can reach support at https://support.google.com/?hl=en.

Legal basis

If you have consented to web design tools being used, the legal basis of the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by web design tools. On our part there is also a legitimate interest in improving the web design on our website. After all, only then can we deliver you a beautiful and professional web offering. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use web design tools insofar as you have given consent. We want to emphasise this here once again in any case.

Information on specific web design tools you will receive – where available – in the following sections.

Google Fonts Local Privacy Policy

On our website we use Google Fonts of the company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible. We have embedded the Google fonts locally, i.e. on our web server – not on the servers of Google. As a result, there is no connection to Google servers and thus also no data transmission or storage.

What is Google Fonts?

Earlier, Google Fonts was also called Google Web Fonts. It is an interactive directory with over 800 fonts that Google provides free of charge. With Google Fonts one could use fonts without uploading them to one's own server. But in order to prevent any information transmission to Google servers in this respect, we have downloaded the fonts to our server. In this way we act in compliance with data protection and do not pass on any data to Google Fonts.

Online Map Services Introduction

Online Map Services Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Improvement of the user experience
📓 Processed data: Which data is processed depends strongly on the services used. Mostly it is IP address, location data, search objects and/or technical data. You can find more details on this at the respective tools used.
📅 Storage period: depending on the tools used
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What are online map services?

For our website we also use online map services as an extended service. Google Maps is probably the service that is most familiar to you, but there are also other providers that have specialised in creating digital maps. Such services make it possible to have locations, route plans or other geographic information displayed directly via our website. Through an embedded map service, you no longer have to leave our website in order, for example, to look at the route to a location. So that the online map also works on our website, sections of the map are embedded by means of HTML code. The services can then display street maps, the earth's surface or aerial or satellite images. When you use the built-in map offering, data is also transmitted to the tool used and stored there. Among this data there may also be personal data.

Why do we use online map services on our website?

Quite generally speaking, it is our concern to offer you a pleasant time on our website. And your time is of course only pleasant if you find your way around easily on our website and find all the information you need quickly and easily. Therefore we thought that an online map system could be a significant optimisation of our service on the website. Without leaving our website, you can look at route descriptions, locations or also sights without problems with the help of the map system. It is of course also super practical that this way you see at a glance where we have our company headquarters, so that you find your way to us quickly and safely. You see, there are simply many advantages and we clearly regard online map services on our website as part of our customer service.

Which data is stored by online map services?

When you open a page on our website that has an online map function built in, personal data can be transmitted to the respective service and stored there. Mostly this is your IP address, through which your approximate location can also be determined. In addition to the IP address, data such as entered search terms as well as longitude and latitude coordinates are also stored. If, for example, you enter an address for route planning, this data is also stored. The data is not stored with us but on the servers of the embedded tools. You can imagine it roughly like this: you are indeed on our website, but when you interact with a map service, this interaction actually happens on their website. So that the service works flawlessly, generally at least one cookie is also set in your browser. Google Maps, for example, also uses cookies in order to record user behaviour and thus optimise its own service and be able to display personalised advertising. You can learn more about cookies in our section "Cookies".

How long and where is the data stored?

Every online map service processes different user data. Insofar as we have further information, we will inform you about the duration of the data processing further below in the corresponding sections on the individual tools. In principle, personal data is always only kept for as long as is necessary for the provision of the service. Google Maps, for example, stores certain data for a specified period; other data you in turn have to delete yourself. With Mapbox, for example, the IP address is kept for 30 days and then deleted. You see, every tool stores data for different lengths of time. Therefore we recommend that you look at the privacy policies of the tools used carefully.

The providers also use cookies in order to store data about your user behaviour with the map service. You can find more general information on cookies in our section "Cookies", but also in the data protection texts of the individual providers you learn which cookies may be used. Mostly, however, this is only an exemplary list and is not complete.

Right to object

You always have the possibility and also the right to access your personal data and also to object to the use and processing. You can also revoke at any time the consent that you have given us. As a rule, this works most easily via the cookie consent tool. But there are also further opt-out tools that you can use. Possible cookies that are set by the providers used, you can also manage, delete or deactivate yourself with a few mouse clicks. It can then, however, happen that some functions of the service no longer work as usual. How you manage cookies in your browser also depends on your browser used. In the section "Cookies" you can also find links to the instructions of the most important browsers.

Legal basis

If you have consented to an online map service being used, the legal basis of the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by an online map service.

We also have a legitimate interest in using an online map service in order to optimise our service on our website. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). However, we only use an online map service when you have given consent. We definitely want to have recorded this once again at this point.

Information on specific online map services you will receive – where available – in the following sections.

Google Maps Privacy Policy

Google Maps Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service
📓 Processed data: Data such as entered search terms, your IP address and also the latitude or longitude coordinates.
You can find more details on this below in this privacy policy.
📅 Storage period: depending on the data stored
⚖️ Legal bases: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is Google Maps?

On our website we use Google Maps of the company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Maps we can show you locations better and thereby adapt our service to your needs. Through the use of Google Maps, data is transmitted to Google and stored on the Google servers. Here we now want to go into more detail about what Google Maps is, why we make use of this Google service, which data is stored and how you can prevent this.

Google Maps is an internet map service of the company Google. With Google Maps you can search online via a PC, a tablet or an app for exact locations of cities, sights, accommodation or companies. If companies are represented on Google My Business, further information about the company is displayed in addition to the location. In order to display the travel option, sections of a map of a location can be embedded in a website by means of HTML code. Google Maps displays the earth's surface as a street map or as an aerial or satellite image. Thanks to the Street View images and the high-quality satellite images, very precise representations are possible.

Why do we use Google Maps on our website?

All our efforts on this page pursue the goal of offering you a useful and meaningful time on our website. Through the embedding of Google Maps, we can deliver you the most important information on various locations. You see at a glance where we have our company headquarters. The route description always shows you the best or fastest way to us. You can retrieve the travel route for routes by car, by public transport, on foot or by bicycle. For us, the provision of Google Maps is part of our customer service.

Which data is stored by Google Maps?

So that Google Maps can offer its service fully, the company has to record and store data about you. These include, among other things, the entered search terms, your IP address and also the latitude or longitude coordinates. If you use the route planner function, the entered start address is also stored. This data storage, however, happens on the web pages of Google Maps. We can only inform you about this, but cannot exert any influence. Since we have embedded Google Maps in our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behaviour. Google uses this data primarily in order to optimise its own services and to provide individual, personalised advertising for you.

The following cookie is set in your browser due to the embedding of Google Maps:

Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ113224532-5
Purpose: NID is used by Google to adapt advertisements to your Google search. With the help of the cookie, Google "remembers" your most frequently entered search queries or your earlier interaction with advertisements. This way you always get tailor-made advertisements. The cookie contains a unique ID that Google uses to collect your personal settings for advertising purposes.
Expiry date: after 6 months

Note: We cannot guarantee completeness in the information on the stored data. Especially with the use of cookies, changes can never be ruled out. In order to identify the cookie NID, a separate test page was created where exclusively Google Maps was embedded.

How long and where is the data stored?

The Google servers are located in data centres all over the world. Most servers, however, are located in America. For this reason, your data is also increasingly stored in the USA. Here you can read exactly where the Google data centres are located: https://datacenters.google/

Google distributes the data across various data carriers. As a result, the data can be retrieved faster and is better protected against any manipulation attempts. Every data centre also has special emergency programs. If, for example, there are problems with the Google hardware or a natural disaster paralyses the servers, the data nevertheless remains pretty securely protected.

Google stores some data for a specified period. For other data, Google merely offers the possibility to delete it manually. Furthermore, the company also anonymises information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months.

How can I delete my data or prevent data storage?

With the automatic deletion function of location and activity data introduced in 2019, information on location determination and web/app activity is – depending on your decision – either stored for 3 or 18 months and then deleted. In addition, one can also delete this data at any time manually from the history via the Google account. If you want to completely prevent your location recording, you have to pause the section "Web & App Activity" in the Google account. Click "Data & Personalisation" and then the option "Activity Settings". Here you can switch the activities on or off.

In your browser you can also deactivate, delete or manage individual cookies. Depending on which browser you use, this always works somewhat differently. Under the section "Cookies" you can find the corresponding links to the respective instructions of the best-known browsers.

If you generally do not want any cookies, you can set up your browser so that it always informs you when a cookie is to be set. This way, you can decide for each individual cookie whether to allow it or not.

Legal basis

If you have consented to Google Maps being used, the legal basis of the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent represents the legal basis for the processing of personal data, as can occur during collection by Google Maps.

On our part there is also a legitimate interest in using Google Maps in order to optimise our online service. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use Google Maps insofar as you have given consent.

Google processes data about you, among other places, also in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called standard contractual clauses (= Art. 46 paras. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=en

You can find the Google Ads Data Processing Terms, which refer to the standard contractual clauses, at https://business.safety.google/intl/en/adsprocessorterms/.

If you want to learn more about the data processing of Google, we recommend the in-house privacy policy of the company at https://policies.google.com/privacy?hl=en.

Explanation of Terms Used

We are always endeavouring to write our privacy policy as clearly and understandably as possible. Especially with technical and legal topics, however, this is not always quite easy. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). We do not, however, want to use these without explanation. Below you will now find an alphabetical list of important terms used that we may not yet have addressed sufficiently in the privacy policy so far. If these terms are taken from the GDPR and are definitions, we will also cite the GDPR texts here and, where applicable, add our own explanations.

Processor

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to the controllers, there can also be so-called processors. This includes every company or every person that processes personal data on our behalf. Processors can consequently be, in addition to service providers such as tax advisers, for example also hosting or cloud providers, payment or newsletter providers or large companies such as, for example, Google or Microsoft.

Consent

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

Explanation: As a rule, with websites such consent takes place via a cookie consent tool. You surely know this. Whenever you visit a website for the first time, you are mostly asked via a banner whether you agree to or consent to the data processing. Mostly you can also make individual settings and thus decide yourself which data processing you allow and which not. If you do not consent, no personal data about you may be processed either. In principle, consent can of course also take place in writing, i.e. not via a tool.

Personal Data

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Explanation: Personal data is therefore all that data which can identify you as a person. This is, as a rule, data such as:

  • Name
  • Address
  • Email address
  • Postal address
  • Telephone number
  • Date of birth
  • Identification numbers such as social security number, tax identification number, identity card number or matriculation number
  • Bank data such as account number, credit information, account balances and much more

According to the European Court of Justice (ECJ), your IP address is also among the personal data. IT experts can, on the basis of your IP address, at least determine the approximate location of your device and subsequently you as the connection owner. Therefore, the storage of an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called "special categories" of personal data that are also particularly worthy of protection. These include:

  • racial and ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic data such as, for example, data taken from blood or saliva samples
  • biometric data (this is information on mental, physical or behavioural characteristics that can identify a person).
    Health data
  • Data on sexual orientation or sex life

Profiling

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

Explanation: With profiling, various pieces of information about a person are gathered together in order to learn more about this person from them. In the web area, profiling is frequently applied for advertising purposes or also for creditworthiness checks. Web or advertising analysis programs, for example, collect data about your behaviour and your interests on a website. From this results a special user profile with the help of which advertising can be delivered in a targeted way to a target group.

 

Controller

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

Explanation: In our case, we are responsible for the processing of your personal data and consequently the "controller". If we pass on collected data for processing to other service providers, these are "processors". For this, a "data processing agreement (DPA)" must be signed.

 

Processing

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term:

"processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

Note: When we speak of processing in our privacy policy, we mean by this any type of data processing. This includes, as mentioned above in the original GDPR explanation, not only the collection but also the storage and processing of data.

All texts are protected by copyright.

Source: Privacy Policy created with the Privacy Policy Generator for Austria by AdSimple