Privacy Policy
Who we are
The controller within the meaning of the GDPR and other data protection provisions is:
NEURA Robotics GmbH
Gutenbergstraße 44
72555 Metzingen
Germany
+49 (0) 7123 879700
https://neura-robotics.com/
Contacting the Data Protection Officer
The controller’s Data Protection Officer is:
DataCo GmbH
Sandstr. 33
80335 München
Germany
+49 (0) 89 7400 45840
On this page, we inform you about the processing of your personal data on the website. How we collect and use your personal data depends on how you interact with us or which services you use. We only collect, use or share your personal data where we have a legitimate purpose and a legal basis for doing so.
What do we mean by legal basis?
• Consent (Art. 6 (1) sentence 1 lit. a GDPR) – You have given us your consent to process your personal data for the specific purpose we have explained to you. You have the right to withdraw your consent at any time. Further information on how to withdraw your consent can be found in the subsections “Exercising your rights” in the following sections of this privacy policy.
• Contract (Art. 6 (1) sentence 1 lit. b GDPR) – We need to use your data to perform a contract you have with us. Alternatively, it is necessary to use your data because we have asked you to take, or you yourself have taken, certain steps before entering into that contract.
• Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) – We need to use your data to comply with the law.
• Vital interests (Art. 6 (1) sentence 1 lit. d GDPR) – Processing your data is necessary to protect your vital interests or those of another person, for example to protect you from serious physical harm.
• Public task (Art. 6 (1) sentence 1 lit. e GDPR) – Processing your data is necessary for the performance of a task carried out in the public interest, or because it is covered by a task laid down by law, e.g. a statutory function.
• Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) – Processing your data is necessary to support a legitimate interest that we or another party have, but only where your own interests do not override it.
Please note that we may not be able to provide you with our website services if your data is processed for the performance of a contract or a legal obligation and you do not provide the requested data.
Data sharing and international transfers
As explained in this privacy policy, we use various service providers who help us deliver our services and keep your data secure. When we use these service providers, it is necessary for us to share your personal data with them.
We have entered into agreements with all service providers to whom we disclose your data, obliging them to protect your data.
Where your personal data is shared outside the EU, we ensure that your personal data receives an equivalent level of protection, either because the country to which your data is transferred has an “adequate” standard of data protection as determined by the European Commission, or by applying another safeguard, such as an enhanced contractual arrangement, i.e. the Standard Contractual Clauses (SCCs) adopted by the European Commission.
For example, where we use US service providers, we rely, depending on the provider, either on the SCCs or on the EU-US Data Privacy Framework. You can request a copy of the SCCs we have concluded with our service providers by sending an email to the email address stated in this privacy policy.
Your rights
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
1. The right of access (Art. 15 GDPR)
You have the right to obtain confirmation from us as to whether personal data concerning you is being processed. If this is the case, you have a right of access to this data and to the following information:
• Purposes of the processing
• Categories of personal data
• Recipients or categories of recipients
• The envisaged storage period or the criteria used to determine that period, and the existence of the rights to rectification, erasure, restriction of processing or objection
• The right to lodge a complaint with the competent supervisory authority
• Where applicable, the source of the data (if collected from a third party)
• Where applicable, the existence of automated decision-making, including profiling, with meaningful
• information about the logic involved, as well as the significance and the envisaged consequences
• Where applicable, the transfer of personal data to a third country or an international organisation
2. Right to rectification (Art. 16 GDPR)
If your personal data is inaccurate or incomplete, you have the right to request its immediate rectification or completion.
3. Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of the processing of your personal data where one of the following conditions applies:
• You contest the accuracy of your personal data, for a period enabling us to verify the accuracy of the personal data.
• The processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead.
• We no longer need your personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of your legal claims, or
• you have objected to the processing, pending the verification of whether our legitimate grounds override yours.
4. Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
You have the right to request the immediate erasure of your personal data where one of the following grounds applies:
• Your data is no longer necessary in relation to the purposes for which it was originally collected.
• You withdraw your consent and there is no other legal basis for the processing.
• You object to the processing and there are no overriding legitimate grounds for the processing, or you object pursuant to Art. 21 (2) GDPR.
• Your personal data has been unlawfully processed.
• Erasure is required for compliance with a legal obligation under Union or Member State law to which we are subject.
• The personal data was collected in relation to the offer of information society services referred to in Art. 8 (1) GDPR.
Please note that the above grounds do not apply to the extent that processing is necessary:
• For exercising the right of freedom of expression and information;
• For compliance with a legal obligation or for the performance of a task carried out in the public interest to which we are subject;
• For reasons of public interest in the area of public health;
• For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
• For the establishment, exercise or defence of legal claims.
5. Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
6. Right to object to certain data processing (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6 (1) sentence 1 lit. e or f GDPR. This also applies to profiling based on those provisions.
Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
7. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
A list of the locally competent supervisory authorities in Germany is available on the website of the Federal Commissioner for Data Protection at the following link: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
Provision of the website and creation of logfiles
1. Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device.
The following data is collected:
• Information about the browser type and version used
• The user’s operating system
• The user’s internet service provider
• Date and time of access
• Websites from which the user’s system reaches our website
• Websites accessed by the user’s system via our website
This data is stored in the logfiles of our system. This data is not stored together with other personal data of the user.
2. Purpose of the data processing
The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user’s device. For this purpose, the user’s IP address must remain stored for the duration of the session.
Storage in logfiles takes place to ensure the functionality of the website. In addition, the data helps us to optimise the website and to ensure the security of our IT systems. The data is not analysed for marketing purposes in this context.
3. Legal basis for the data processing
The legal basis for the temporary storage of the data and the logfiles is Art. 6 (1) sentence 1 lit. f GDPR.
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. Where data is collected for the provision of the website, this is the case when the respective session has ended. Where data is stored in logfiles, this is the case after no more than seven days. Storage beyond this period is possible. In this case, the users’ IP addresses are erased or obfuscated so that it is no longer possible to attribute them to the accessing client.
The collection of data for the provision of the website and the storage of the data in logfiles is strictly necessary for the operation of the website. The user may object to this. Whether the objection is successful is to be determined as part of a balancing of interests.
Use of cookies
1. Description and scope of data processing
When you visit our website, we use technical tools for various functions, in particular cookies, which can be stored on your device. When you access our website, and at any time thereafter, you can choose whether to allow the setting of cookies in general or which individual additional functions you wish to select. You can make changes in your browser settings or via our consent manager.
Cookies are text files or information in a database that are stored on your hard drive and assigned to the browser you are using, so that certain information can flow to the entity setting the cookie. Below we describe the types of cookies we use:
We use technically necessary cookies, which are required for the technical operation of the website. Without these cookies, our website cannot be displayed (fully and correctly) or the support functions are not available.
The following data is stored and transmitted by the technically necessary cookies:
• Language settings
• Log-in information
• Search terms entered
• Frequency of page views
• Use of website functions
We also use cookies on our website that are not technically necessary. Cookies that are not technically necessary are text files that do not serve solely to ensure the functionality of the website but also collect other data.
The following data is processed by setting cookies that are not technically necessary:
• IP address
• Location of the internet user
• Date and time of the visit to the website
• Adaptation of advertisements to the user
• Tracking of browsing behaviour
• Linking of the website visit to other social media platforms
2. Purpose of the data processing
The purpose of using technically necessary cookies is to ensure the functionality of our website. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary for the browser to be recognised again after a page change.
We require technically necessary cookies for the following applications:
• Applying language settings
• Remembering search terms
• Functionality of the website
Cookies that are not technically necessary are used for the purpose of improving the quality of our website, its content and thus our reach and profitability. By setting these cookies, we learn how the website is used and can continuously optimise our offering. In particular, these cookies serve the following purposes:
We use cookies that are not technically necessary to optimise our website for you and to offer you the best possible user experience. Specifically, these cookies serve the following purposes: The cookies enable us to analyse and understand your browsing behaviour on our website in order to tailor our content and offers to demand. In addition, your IP address and your approximate location are processed in order to offer you regionalised content and location-based services.
We also use cookies to adapt advertisements to your interests and usage behaviour and thus to show you more relevant advertising content. The date and time of your website visit are recorded in order to compile usage statistics and improve the performance of our website. Finally, certain cookies enable your website visit to be linked to other social media platforms, for example to make it easier for you to share content or to carry out cross-platform analyses. This processing only takes place with your express consent, which you can withdraw at any time via our cookie consent mechanism.
3. Legal basis for the data processing
The storage of information on the end user’s terminal equipment and/or access to information already stored on the end user’s terminal equipment is governed by the provisions of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where the setting and reading of cookies is technically necessary, this is done to ensure the functionality of our website. In this case, the storage of and access to cookies on your terminal equipment is based on Section 25 (2) no. 2 TDDDG. This storage of and access to information on your terminal equipment serves to make it easier for you to use our website and to enable us to offer you our services as requested by you. Some functions of our website do not work without the use of these cookies and could therefore not be offered. Cookies are generally deleted at the end of the session (e.g. logging out or closing the browser) or after a predefined period has expired. Information on differing storage periods for cookies can be found in the following sections of this privacy policy.
Where cookies are used that are not technically necessary, this is done on the basis of your express consent, which you can give via the cookie banner. In this case, the basis for the storage of and access to information is Section 25 (1) TDDDG in conjunction with Art. 6 (1) lit. a), Art. 7 GDPR. You can withdraw your consent at any time with effect for the future, or grant it again subsequently, by configuring your cookie settings accordingly. Alternatively, you can prevent the storage of cookies by adjusting the settings of your browser software. Please note that browser settings only ever apply to the browser used in each case. If personal data is processed following the storage of and access to information on your terminal equipment, the provisions of the GDPR apply. Information on this can be found in the following sections of this privacy policy.
You can withdraw your consent to the use of cookies at any time and adjust your consent preferences via the consent manager, which you can access via the “Cookie settings” link in the footer of our website.
Newsletter
1. Description and scope of data processing
On our website, you can subscribe to a free newsletter. When you sign up for the newsletter, the data from the input form is transmitted to us.
To provide this service, we collect the following data from you:
• Email address
• Surname
• First name
• IP address of the accessing device
• Date and time of registration
• Salutation
Your consent is obtained for the processing of the data as part of the registration process, and reference is made to this privacy policy.
In connection with the data processing for sending newsletters, no data is passed on to third parties. The data is used exclusively for sending the newsletter.
2. Purpose of the data processing
The collection of the user’s email address serves to deliver the newsletter.
The collection of other personal data during the registration process serves to prevent misuse of the services or of the email address used.
3. Legal basis for the data processing
The legal basis for the processing of data after the user has signed up for the newsletter, where the user has given consent, is Art. 6 (1) sentence 1 lit. a GDPR.
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. The user’s email address is therefore stored for as long as the newsletter subscription is active.
Other personal data collected during the registration process is generally erased after a period of seven days.
The newsletter subscription can be cancelled by the user concerned at any time. Each newsletter contains a corresponding link for this purpose. This also enables the user to withdraw consent to the storage of the personal data collected during the registration process.
Email contact
1. Description and scope of data processing
You can contact us via the email address provided on our website. In this case, the user’s personal data transmitted with the email is stored. The data is used exclusively for handling the conversation.
2. Purpose of the data processing
Where contact is made by email, this also constitutes the necessary legitimate interest in processing the data.
3. Legal basis for the data processing
The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in responding optimally to the enquiry you send us by email.
If the email contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
4. Storage period
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is deemed to have ended when it can be inferred from the circumstances that the matter concerned has been conclusively resolved. Personal data additionally collected during the sending process is erased no later than after a period of seven days.
If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.
You have the right at any time to withdraw your consent to the processing of your personal data and to object to the storage of your data. The withdrawal or objection can be made in the following ways:
• Contact form: https://neura-robotics.com/en/
• By email to: [email protected]
• By post to: NEURA Robotics GmbH, Gutenbergstraße 44, 72555 Metzingen
If you have subscribed to our newsletter, you can unsubscribe at any time via the unsubscribe link at the end of each newsletter message. The withdrawal of consent does not affect the lawfulness of the processing carried out up to the time of withdrawal. Upon receipt of your withdrawal or objection, the data concerned will be erased without undue delay, unless statutory retention obligations prevent erasure.
All personal data stored in the course of the contact will be erased in this case.
Contact form
1. Description and scope of data processing
Our website contains a contact form which can be used for electronic contact. If a user makes use of this option, the data entered in the input form is transmitted to us and stored.
At the time the message is sent, the following data is stored:
• Email address
• Surname
• First name
• Address
• Telephone / mobile number
• Salutation
• Company name and type
• Message content
• IP address of the accessing device
• Date and time
2. Purpose of the data processing
The processing of the personal data from the contact form input screen or via the email address provided serves solely to handle the contact. The other personal data processed during the sending process serves to prevent misuse of the contact form and to ensure the security of our IT systems.
3. Legal basis for the data processing
The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in responding optimally to the enquiry you send us via the contact form. If the contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) sentence 1 lit. b GDPR.
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the contact form input screen and data sent by email, this is the case when the respective conversation with the user has ended. The conversation is deemed to have ended when it can be inferred from the circumstances that the matter concerned has been conclusively resolved. Personal data additionally collected during the sending process is erased no later than after a period of seven days.
If the user contacts us via the input screen in the contact form, they may object to the storage of their personal data at any time, as follows:
You have the right at any time to withdraw your consent to the processing of your personal data and to object to the storage of your data. The withdrawal or objection can be made in the following ways:
• Contact form: https://neura-robotics.com/en/
• By email to: [email protected]
• By post to: NEURA Robotics GmbH, Gutenbergstraße 44, 72555 Metzingen
If you have subscribed to our newsletter, you can unsubscribe at any time via the unsubscribe link at the end of each newsletter message.
The withdrawal of consent does not affect the lawfulness of the processing carried out up to the time of withdrawal. Upon receipt of your withdrawal or objection, the data concerned will be erased without undue delay, unless statutory retention obligations prevent erasure.
All personal data stored in the course of the contact will be erased in this case.
Company social media presences
Instagram, part of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
On our company page, we provide information and offer Instagram users the opportunity to communicate with us. If you carry out an action on our Instagram company presence (e.g. comments, posts, likes etc.), you may make personal data (e.g. your real name or a photo of your user profile) public.
However, as we generally or largely have no influence on the processing of your personal data by Instagram, we cannot make any binding statements about the purpose and scope of the processing of your data.
We use our company presence on social networks to communicate and exchange information with (potential) customers.
Publications via the company presence may include the following content:
• Information about products
• Information about services
• Competitions and prize draws
• Advertising
• Customer contact
Every user is free to publish personal data through their activities.
Where we process your personal data to analyse your online behaviour, to offer you competitions or to run lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) sentence 1 lit. a, Art. 7 GDPR.
The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in responding optimally to your enquiry and in being able to provide the information requested. If the contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
We store your activities and personal data published via our Instagram company presence until you withdraw your consent. In addition, we comply with statutory retention periods.
For the processing of your personal data in third countries, we have put in place appropriate safeguards in the form of standard data protection clauses pursuant to Art. 46 (2) lit. c GDPR. A copy of the standard data protection clauses can be requested from us.
You can object at any time to the processing of your personal data that we collect in the course of your use of our company presence, and assert your rights as a data subject as set out in the section “Your rights” in this privacy policy. To do so, send us an informal email to: [email protected].
Further information on the processing of your personal data by Instagram and the corresponding objection options can be found here:
Instagram: https://help.instagram.com/519522125107875
YouTube
YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, United States
On our company page, we provide information and offer YouTube users the opportunity to communicate with us. If you carry out an action on our YouTube company presence (e.g. comments, posts, likes etc.), you may make personal data (e.g. your real name or a photo of your user profile) public. However, as we generally or largely have no influence on the processing of your personal data by YouTube, we cannot make any binding statements about the purpose and scope of the processing of your data.
We use our company presence on social networks to communicate and exchange information with (potential) customers.
Publications via the company presence may include the following content:
• Information about products
• Information about services
• Competitions and prize draws
• Advertising
• Customer contact
Every user is free to publish personal data through their activities.
Where we process your personal data to analyse your online behaviour, to offer you competitions or to run lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) sentence 1 lit. a, Art. 7 GDPR.
The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in responding optimally to your enquiry and in being able to provide the information requested. If the contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
We store your activities and personal data published via our YouTube company presence until you withdraw your consent. In addition, we comply with statutory retention periods.
The data generated by the company presence is not stored in our own systems.
For the processing of your personal data in third countries, we have put in place appropriate safeguards in the form of standard data protection clauses pursuant to Art. 46 (2) lit. c GDPR. A copy of the standard data protection clauses can be requested from us.
You can object at any time to the processing of your personal data that we collect in the course of your use of our company presence, and assert your rights as a data subject as set out in the section “Your rights” in this privacy policy. To do so, send us an informal email to: [email protected]. Further information on the processing of your personal data by YouTube and the corresponding objection options can be found here:
X (formerly Twitter)
X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland
On our company page, we provide information and offer X users the opportunity to communicate with us. If you carry out an action on our X company presence (e.g. comments, posts, likes etc.), you may make personal data (e.g. your real name or a photo of your user profile) public. However, as we generally or largely have no influence on the processing of your personal data by X, we cannot make any binding statements about the purpose and scope of the processing of your data.
We use our company presence on social networks to communicate and exchange information with (potential) customers.
Publications via the company presence may include the following content:
• Information about products
• Information about services
• Competitions and prize draws
• Advertising
• Customer contact
Every user is free to publish personal data through their activities.
Where we process your personal data to analyse your online behaviour, to offer you competitions or to run lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) sentence 1 lit. a, Art. 7 GDPR.
The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in responding optimally to your enquiry and in being able to provide the information requested. If the contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
We store your activities and personal data published via our X company presence until you withdraw your consent. In addition, we comply with statutory retention periods.
For the processing of your personal data in third countries, we have put in place appropriate safeguards in the form of standard data protection clauses pursuant to Art. 46 (2) lit. c GDPR. A copy of the standard data protection clauses can be requested from us.
You can object at any time to the processing of your personal data that we collect in the course of your use of our company presence, and assert your rights as a data subject as set out in the section “Your rights” in this privacy policy. To do so, send us an informal email to: [email protected]. Further information on the processing of your personal data by X and the corresponding objection options can be found here:
Use of company presences in professional networks
The company presence is used for job applications, information/PR and active sourcing.
We have no information regarding the processing of your personal data by the companies jointly responsible for the company presence. Further information can be found in the privacy policies of:
LinkedIn:
https://www.linkedin.com/legal/privacy-policy
XING:
On our page, we provide information and offer users the opportunity to communicate with us.
If you carry out an action on our company presence (e.g. comments, posts, likes etc.), you may make personal data (e.g. your real name or a photo of your user profile) public.
2. Legal basis for the data processing
The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in responding optimally to your enquiry and in being able to provide the information requested. If the contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.
3. Purpose of the data processing
Our company presence serves to inform users about our services. Every user is free to publish personal data through their activities.
We store your activities and personal data published via our company presence until you withdraw your consent. In addition, we comply with statutory retention periods.
You can object at any time to the processing of your personal data that we collect in the course of your use of our company presence, and assert your rights as a data subject as set out in the section “Your rights” in this privacy policy. To do so, send us an informal email to the email address stated in this privacy policy.
Further information on exercising your rights can be found here:
LinkedIn:
https://www.linkedin.com/legal/privacy-policy
XING:
Hosting
The website is hosted on servers of a service provider commissioned by us.
Our service provider is:
IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
Further information on the processing of personal data by IONOS can be found at: https://www.ionos.com/terms-gtc/privacy-policy/
The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The information stored is:
• Information about the browser type and version used
• The user’s operating system
• The user’s internet service provider
• Date and time of access
• Websites from which the user’s system reaches our website
• Websites accessed by the user’s system via our website
This data is not merged with other data sources. This data is collected on the basis of Art. 6 (1) lit. f GDPR. Our legitimate interest in processing this data lies in displaying our website without errors and optimising its functions.
The server hosting the website is geographically located in Germany.
Geotargeting
We use the IP address and other information provided by the user (in particular postcode provided during registration or ordering) for regional audience targeting (so-called “geotargeting”).
Regional audience targeting serves, for example, to automatically show you regional offers or advertising that is often more relevant to users. The legal basis for the use of the IP address and, where applicable, other information provided by the user (in particular postcode) is Art. 6 (1) lit. f GDPR, based on our interest in ensuring more precise audience targeting and thus providing offers and advertising with greater relevance for users.
Part of the IP address and the additional information provided by the user (in particular postcode) are only read and are not stored separately.
You can prevent geotargeting by, for example, using a VPN or proxy server that prevents precise localisation. In addition, depending on the browser used, you can also deactivate location detection in the corresponding browser settings (where the browser supports this).
We use geotargeting on our website for the following purposes:
• Customer targeting
• Advertising purposes
Content delivery networks
CloudFlare
1. Description and scope of data processing
We use functions of the content delivery network CloudFlare provided by CloudFlare Germany GmbH, Rosental 7, 80331 München, Germany (hereinafter: CloudFlare). A content delivery network (CDN) is a network of regionally distributed servers connected via the internet, used to deliver content — in particular large media files such as videos. CloudFlare offers web optimisation and security services, which we use to improve the loading times of our website and to protect it against misuse. When you access our website, a connection is established to CloudFlare’s servers, e.g. to retrieve content. As a result, personal data may be stored and analysed in server log files, in particular the user’s activity (especially which pages have been visited) and device and browser information (especially the IP address and the operating system).
Further information on the collection and storage of data by CloudFlare can be found here: https://www.cloudflare.com/de-de/privacypolicy/
2. Purpose of the data processing
The use of CloudFlare’s functions serves the delivery and acceleration of online applications and content.
3. Legal basis for the data processing
This data is collected on the basis of Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this purpose, the server log files must be collected.
4. Storage period
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law.
5. Exercising your rights
Information on exercising your rights vis-à-vis CloudFlare can be found at:
https://www.cloudflare.com/de-de/privacypolicy/
Integrated third-party services
We use various service providers to deliver the services offered by us on the website.
In general, we have a legitimate interest in sharing your data with the relevant service providers where these services are essential for the provision of the basic service offered on the website, in order to provide the relevant website service.
Where such services are required for additional services, extended functions or additional purposes, your personal data is only shared with service providers if you give your consent.
You can withdraw your consent to the use of integrated third-party services and manage your consent settings at any time here: via the consent manager (“Cookie settings” in the footer of our website).
1. Description and scope of data processing
Via the contact form provided on our website and via the newsletter sign-up form, we collect personal data that you actively enter. The processing is carried out technically and organisationally via Microsoft Dynamics 365, which is used both as a customer relationship management (CRM) system and as a marketing system. In addition to the initial collection, the processing also includes the ongoing storage, maintenance, updating and use of the data in the context of managing communication and business relationships.
In particular, the following personal data is processed (depending on the specific use):
• Contact and identification data: first name and surname; email address; telephone number; company
• Content data of the communication: free-text entries in the contact form; content of subsequent correspondence
• Consent and log data (newsletter): time of sign-up; confirmation status (double opt-in); time of withdrawal or unsubscription
The data is stored in Microsoft Dynamics 365 and used for the structured handling of enquiries, for the maintenance and management of contacts and communication histories and — where consent has been given — for sending newsletters.
2. Purpose of the data processing
Your personal data is processed for the following purposes:
• Handling and responding to contact enquiries
• Maintaining and managing communication relationships
• Sending newsletters and information
• Managing and evidencing consents given
• Documenting communication with you
3. Legal basis for the data processing
Your personal data is processed on the following legal bases:
• Art. 6 (1) lit. b GDPR: handling of contact enquiries in the context of pre-contractual/contractual measures
• Art. 6 (1) lit. a GDPR: sending of newsletters on the basis of your freely given consent
• Art. 6 (1) lit. c GDPR: fulfilment of legal evidencing obligations, in particular documentation of consent
• Art. 6 (1) lit. f GDPR: legitimate interest in traceable and proper documentation of communication
4. Storage period
Your personal data is stored only for as long as is necessary for the respective purposes:
• Contact and CRM data: stored for the duration of the existing communication or business relationship; period begins with the last documented contact; erasure once the processing purpose no longer applies, at the latest upon expiry of statutory retention and limitation periods; legal basis: Art. 5 (1) lit. e GDPR
• Newsletter data: stored until you withdraw your consent or unsubscribe from the newsletter; period begins upon withdrawal or unsubscription; legal basis: Art. 5 (1) lit. e GDPR
• Records of consent: stored until expiry of the regular statutory limitation periods; period begins upon withdrawal of consent; legal basis: Art. 5 (1) lit. e GDPR in conjunction with Section 195 of the German Civil Code (BGB)
5. Exercising your rights
Where the processing is based on your consent, you can withdraw it at any time with effect for the future. You also have the right to object to the processing of your personal data where it is based on Art. 6 (1) lit. f GDPR. In addition, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.
Operation of an online shop based on WooCommerce
1. Description and scope of data processing
When operating the online shop based on WordPress with the WooCommerce plugin, personal data is processed that is necessary for the use of the shop, for the establishment, performance and settlement of purchase contracts, and for compliance with legal obligations. In particular, data is processed that users provide during the ordering process, when setting up a customer account or in the course of communicating with the shop, as well as technically necessary access data when visiting the website.
The types of data processed include:
• Master data (e.g. name, address, contact details)
• Contract and order data (e.g. products ordered, order status, invoicing data)
• Payment information in the form of payment status and transaction data (no complete payment data)
• Customer account data (e.g. username, password in encrypted form, order history)
• Technical usage and access data (e.g. IP address, timestamps)
2. Purpose of the data processing
Personal data is processed for the following purposes:
• Provision and technical operation of the online shop
• Initiation, conclusion and settlement of purchase contracts
• Payment and shipping processing
• Management of customer accounts
• Communication with customers in connection with orders
• Compliance with statutory retention and evidencing obligations
• Ensuring IT security and preventing misuse
3. Legal basis for the data processing
Personal data is processed on the following legal bases:
• Art. 6 (1) lit. b GDPR — processing for the performance of a contract / implementation of pre-contractual measures
• Art. 6 (1) lit. c GDPR — processing for compliance with legal obligations (in particular retention obligations under commercial and tax law)
• Art. 6 (1) lit. f GDPR — processing on the basis of legitimate interests in a secure, functional and economically operated online shop
Personal data is stored only for as long as is necessary for the respective processing purposes:
• Contract and accounting-related data is stored in accordance with statutory retention obligations (6 or 10 years pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO)), with the period commencing at the end of the calendar year of the last relevant entry
• Customer account data is stored until the customer account is deleted, unless statutory retention obligations prevent this
• Technical log and access data is erased once the purpose no longer applies, generally after a few days, unless there is a security-related necessity
Data subjects can contact the controller at any time to exercise these rights. In addition, there is a right to lodge a complaint with a competent data protection supervisory authority pursuant to Art. 77 GDPR.
Use of Google Analytics 4 (GA4)
1. Scope of the processing of personal data
We use Google Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: Google).
Google Analytics examines, among other things, how visitors use our website. Google sets cookies on your device for this purpose. During the visit, user behaviour is recorded in the form of “events”. As a result, personal data may be stored and analysed, including:
• First visit to the website
• Interaction with the website, usage path
• Clicks on external links
• Video usage
• File downloads
• Ad impressions and clicks
• Scroll behaviour (when scrolling to the end of a page)
• Searches on the website
• Language selection
• Page visits
• Location (region)
• Your IP address (in truncated form)
• Technical information about your browser and the devices you use (e.g. language setting, screen resolution)
• Your internet provider
• Referrer URL
We use the User-ID function. Using the User ID, we can assign a unique, persistent ID to one or more sessions (and the activities within those sessions) and analyse user behaviour across devices.
We use Google Signals. This means that Google Analytics collects additional information about users who have activated personalised ads (interests and demographic data), and ads can be delivered to these users in cross-device remarketing campaigns.
IP address anonymisation is activated by default in GA4. This means that your IP address is truncated by Google within the member states of the European Union or other contracting states of the Agreement on the European Economic Area. Only in rare, exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. According to Google, the IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.
Further information on the processing of data by Google can be found here:
https://policies.google.com/privacy
2. Purpose of the processing of personal data
We use GA4 to analyse the use of our online presence and to generate reports on the activities on our website. The reports serve to analyse the performance of our website and to deliver targeted advertising to people who have already shown initial interest through their visit to the site.
3. Legal basis for the processing of personal data
The legal basis for the processing of users’ personal data is, as a rule, the user’s consent pursuant to Section 25 (1) TDDDG in conjunction with Art. 6 (1) sentence 1 lit. a) GDPR.
Your personal data is erased after 14 months. This erasure takes place automatically once a month.
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the time of withdrawal. You can withdraw your consent via our cookie consent tool.
You can prevent the collection and processing of your personal data by Google by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
Further information on objection and removal options vis-à-vis Google can be found at: https://policies.google.com/technologies/partner-sites
You can also prevent the collection of the data generated by the cookie and relating to your use of the online presence (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
You can deactivate the use of your personal data by Google via the following link: https://adssettings.google.de
Use of Google reCAPTCHA
1. Scope of the processing of personal data
We use Google reCAPTCHA provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and its representative in the Union, Google Ireland Ltd., Gordon House, Barrow Street, D04 E5W5, Dublin, Ireland. This tool is intended to check whether data entry is legitimate and has not been carried out by a bot. For this purpose, Google reCAPTCHA analyses and authenticates the behaviour of a visitor to the online presence with regard to a wide variety of characteristics. As a result, personal data may be stored and analysed, in particular the user’s activity (especially mouse movements and which elements have been clicked) and device and browser information (especially the time, the IP address and the operating system).
The data is not linked to data that may be collected or used in connection with the parallel use of authenticated Google services such as Gmail.
Further information on the processing of data by Google can be found here:
https://policies.google.com/privacy?gl=DE&hl=de
2. Purpose of the processing of personal data
The use of Google reCAPTCHA serves to protect our online presence against misuse.
3. Legal basis for the processing of personal data
The legal basis for the processing of users’ personal data is, as a rule, the user’s consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR.
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes.
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the time of withdrawal.
You can prevent the collection and processing of your personal data by Google by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
You can deactivate the use of your personal data by Google via the following link:
Further information on objection and removal options vis-à-vis Google can be found at:
Use of Google Web Fonts
1. Scope of the processing of personal data
We use Google Web Fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and its representative in the Union, Google Ireland Ltd., Gordon House, Barrow Street, D04 E5W5, Dublin, Ireland (hereinafter: Google). The web fonts are transferred to the browser’s cache when the page is accessed, so that they can be used for the visually enhanced display of various information. If the browser does not support Google Web Fonts or blocks access, the text is displayed in a standard font. No cookies are stored on the visitor’s device when the page is accessed. Data transmitted in connection with the page view is sent to resource-specific domains such as https://fonts.googleapis.com or https://fonts.gstatic.com.
As a result, personal data may be stored and analysed, in particular the user’s activity (especially which pages have been visited and which elements have been clicked) and device and browser information (especially the IP address and the operating system).
The data is not linked to data that may be collected or used in connection with the parallel use of authenticated Google services such as Gmail.
Further information on the processing of data by Google can be found here:
https://policies.google.com/privacy?gl=DE&hl=de
2. Purpose of the processing of personal data
The use of Google Web Fonts serves the appealing presentation of our texts. If your browser does not support this function, a standard font from your computer is used for display.
3. Legal basis for the processing of personal data
The legal basis for the processing of users’ personal data is, as a rule, the user’s consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR.
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes.
You can prevent the collection and processing of your personal data by Google by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
You can deactivate the use of your personal data by Google via the following link:
Further information on objection and removal options vis-à-vis Google can be found at: https://policies.google.com/privacy?gl=DE&hl=de
Use of Wordfence Security
1. Scope of the processing of personal data
Our online presence uses functions of Defiant Inc., 800 5th Ave., Suite 4100, Seattle, WA 98104, USA (hereinafter: Defiant). Wordfence Security secures our online presence and thereby protects visitors to the online presence against viruses and malware. When you visit a page with the plugin, a direct connection is established between your computer and the Defiant server. To detect whether the visitor is a human or a bot, the plugin sets cookies. As a result, further personal data may be stored and analysed, in particular device and browser information (especially the IP address and the operating system).
It is possible to analyse behaviour based on the notifications sent (e.g. how often a page is accessed). For the purpose of protection against brute-force and DDoS attacks or comment spam, IP addresses are stored on the Wordfence servers. IP addresses classified as harmless are placed on a whitelist.
Further information on the processing of data by Defiant can be found here:
https://www.wordfence.com/privacy-policy/
2. Purpose of the processing of personal data
The online presence uses the plugin to protect against viruses and malware and to defend against attacks by cyber criminals.
3. Legal basis for the processing of personal data
The legal basis for the processing of users’ personal data is, as a rule, the user’s consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR.
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes.
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the time of withdrawal.
You can prevent the collection and processing of your personal data by Wordfence Security by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
Further information on objection and removal options vis-à-vis Wordfence Security can be found at:
Use of WPML
1. Scope of the processing of personal data
We use WPML provided by OnTheGoSystems Limited, 22/F 3 Lockhart Road, Wanchai, Hong Kong (hereinafter: WPML). WPML is a multilingual plugin for WordPress. We use WPML to display our online presence in different languages. When you visit our online presence, WPML stores a cookie on your device to save the language setting you have selected. As a result, personal data may be stored and analysed, in particular the user’s activity (especially which pages have been visited and which elements have been clicked) and device and browser information (especially the IP address and the operating system).
Further information on the processing of data by WPML can be found here: https://wpml.org/de/documentation-3/privacy-policy-and-gdpr-compliance/
2. Purpose of the processing of personal data
The use of WPML serves to display our online presence in multiple languages.
3. Legal basis for the processing of personal data
The legal basis for the data processing is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in addressing visitors to our online presence in their native language.
WPML stores cookies on your device. Information on the storage duration of the cookies can be found at: https://wpml.org/documentation/privacy-policy-and-DSGVO-compliance
You can prevent the collection and processing of your personal data by WPML by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
Further information on objection and removal options vis-à-vis WPML can be found at: https://wpml.org/de/documentation-3/privacy-policy-and-gdpr-compliance/
Use of Google Tag Manager
1. Scope of the processing of personal data
We use Google Tag Manager (https://www.google.com/intl/de/tagmanager/) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and its representative in the Union, Google Ireland Ltd., Gordon House, Barrow Street, D04 E5W5, Dublin, Ireland (hereinafter: Google).
Google Tag Manager allows tags from Google services and third-party providers to be managed and embedded in a bundled manner on an online presence. Tags are small code elements on an online presence that serve, among other things, to measure visitor numbers and behaviour, to record the impact of online advertising and social channels, to use remarketing and audience targeting, and to test and optimise online presences. When a user visits the online presence, the current tag configuration is sent to the user’s browser. It contains instructions as to which tags are to be triggered. Google Tag Manager triggers other tags, which may in turn collect data. Information on this can be found in the passages on the use of the corresponding services in this privacy policy. Google Tag Manager does not access this data.
Further information on Google Tag Manager can be found at https://www.google.com/intl/de/tagmanager/faq.html and in Google’s privacy policy: https://policies.google.com/privacy?hl=de
2. Purpose of the data processing
The purpose of the processing of personal data lies in the consolidated and clear management and efficient integration of third-party services.
3. Legal basis for the processing of personal data
The legal basis for the processing of users’ personal data is, as a rule, the user’s consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR.
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law. According to Google, advertising data in server logs is anonymised by deleting parts of the IP address and cookie information after 9 and 18 months respectively.
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the time of withdrawal.
You can prevent the collection and processing of your personal data by Google by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
You can also prevent the collection of the data generated by the cookie and relating to your use of the online presence (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=de
You can deactivate the use of your personal data by Google via the following link: https://adssettings.google.de
Further information on objection and removal options vis-à-vis Google can be found at: https://policies.google.com/privacy?gl=DE&hl=de
Use of Cookiebot
1. Scope of the processing of personal data
We use functionalities of the cookie consent solution Cookiebot provided by Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter: Cybot). Cookiebot provides a software solution that handles the obtaining of consent for cookie use and the tracking of online users. Cookiebot informs the users of our website about the cookies used on our website. Users also have the option of deactivating cookie groups, with the exception of functional cookies (which are necessary for the smooth display of our website). We are obliged to document your consent or refusal in accordance with Art. 7 (1) GDPR.
In particular, the following personal data is processed by Cybot:
• The end user’s IP number in anonymised form (the last three digits are set to ‘0’)
• Date and time of consent
• The end user’s browser
• The URL for which consent was given
• An anonymous, random and encrypted key
• The end user’s consent status, which serves as proof of consent
Cookies from Cybot are stored on your device. The key and the consent status are also stored in the end user’s browser in the “CookieConsent” cookie, so that the website can automatically read and respect the end user’s consent for all subsequent page requests and future end-user sessions for up to 12 months. The key is used as proof of consent and for an option to verify that the consent status stored in the end user’s browser is unchanged compared to the original consent submitted to Cybot.
If the “bulk consent” function is activated to manage consent for multiple websites through a single end-user consent, Cybot also stores a further separate, random, unique ID with the end user’s consent. If all of the following criteria are met, this key is stored in encrypted form in the “CookieConsentBulkTicket” cookie in the end user’s browser.
All data is hosted in an Azure data centre of the cloud provider Microsoft Ireland Operations Ltd, South County Business Park, One Microsoft Court, Carmanhall and Leopardstown, Dublin, D18 P521, Ireland.
Further information on the processing of data by Cybot can be found here:
https://www.cookiebot.com/de/privacy-policy/
2. Purpose of the data processing
We use Cookiebot to create and display cookie declarations for end users and to store and display cookie scan reports in the privacy policy. This enables us to comply with our information obligations towards the users of our website under Art. 13, 14 GDPR and to obtain and document consent to the use of cookies in a manner compliant with data protection law.
Furthermore, we use Cookiebot to obtain aggregated information about end users’ choices regarding accepted cookie types and a graphical representation thereof in the service manager.
3. Legal basis for the processing of personal data
The legal basis for the data processing is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in the purposes of the data processing set out under 2. The interests and rights of users are appropriately taken into account through the anonymisation of the IP address.
Your personal information is stored by Cybot for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes. The cookies used by Cookiebot are stored on the user’s device for up to 12 months.
You can prevent the collection and processing of your personal data by Cybot by blocking the storage of third-party cookies on your computer, using the “Do Not Track” function of a supporting browser, deactivating the execution of script code in your browser, or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com/) in your browser.
Further information on objection and removal options vis-à-vis Cybot can be found at: https://www.cookiebot.com/de/privacy-policy/
Integration of plugins via external service providers
1. Description and scope of data processing
We integrate certain plugins on our website via external service providers in the form of content delivery networks. When you access our website, a connection is established to the servers of the providers we use in order to retrieve content and store it in the cache of the user’s browser. As a result, personal data may be stored and analysed in server log files, in particular device and browser information (especially the IP address and the operating system). We use the following services: Automattic Inc.
2. Purpose of the data processing
The use of the functions of these services serves the delivery and acceleration of online applications and content.
3. Legal basis for the data processing
This data is collected on the basis of Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website.
Your personal information is stored for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law.
Information on exercising your rights vis-à-vis Automattic Inc. can be found at: https://automattic.com/de/privacy/
Use of Stripe (payment processing)
1. Description and scope of data processing
For the processing of payments in our online shop, we use the payment service provider Stripe, operated by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (hereinafter: Stripe). If you select a payment method offered via Stripe (e.g. credit card) when placing an order, the data you enter during the payment process is transmitted directly to Stripe. The transmission is encrypted; complete payment data (e.g. full credit card numbers) is not stored on our systems.
In particular, the following personal data may be processed:
• Name and contact details
• Billing and delivery address
• Payment data (e.g. credit card details, IBAN — processed directly by Stripe)
• Transaction data (amount, currency, time, order reference, payment status)
• Device and browser information (in particular IP address), which Stripe processes for fraud prevention
Stripe also processes data in part as a controller in its own right, in particular for fraud prevention and to comply with its own legal obligations (e.g. anti-money-laundering requirements). A transfer to Stripe, Inc. in the USA is possible; Stripe bases this transfer on an adequacy decision (EU-US Data Privacy Framework) or on Standard Contractual Clauses.
Further information on the processing of data by Stripe can be found here: https://stripe.com/de/privacy
2. Purpose of the data processing
The processing serves the secure handling of payments for orders in our online shop, fraud prevention and compliance with legal obligations relating to payment transactions.
3. Legal basis for the data processing
The legal basis for the processing is Art. 6 (1) sentence 1 lit. b GDPR (performance of a contract or implementation of pre-contractual measures). Where the processing serves compliance with legal obligations, the legal basis is Art. 6 (1) sentence 1 lit. c GDPR. Where data is processed for fraud prevention, the legal basis is Art. 6 (1) sentence 1 lit. f GDPR; our legitimate interest lies in the security of payment transactions.
Transaction-related data is stored in accordance with statutory retention obligations under commercial and tax law (6 or 10 years pursuant to Section 257 HGB and Section 147 AO); the period commences at the end of the calendar year of the last relevant entry. For the storage period at Stripe itself, please refer to Stripe’s privacy policy.
You can assert your data subject rights vis-à-vis us as the controller at any time (see the section “Your rights”). Where Stripe acts as a controller in its own right, you can also exercise your rights directly vis-à-vis Stripe. Information on this can be found at: https://stripe.com/de/privacy
Use of Meta Pixel (formerly Facebook Pixel)
1. Description and scope of data processing
We use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter: Meta) on our website. The Meta Pixel is a code snippet embedded on our website with which Meta can set cookies on your device and read information from it, provided you have given your consent.
In particular, the following personal data may be processed:
• HTTP header information (in particular IP address, browser type, page location, referrer URL)
• Pixel-specific data (pixel ID and cookie data, including Meta cookies)
• Usage data (in particular pages visited, buttons clicked, events performed such as submitting a form or completing a purchase)
• Hashed contact data such as email address or telephone number (“Advanced Matching”). This hashed data is discarded by Meta promptly after it has been matched against an existing Facebook or Instagram profile and is not stored long-term.
If you are logged into your Meta account (Facebook/Instagram) at the same time, Meta can attribute your visit to our website to your user account. For the collection and transmission of data via the Meta Pixel, we and Meta are joint controllers within the meaning of Art. 26 GDPR; the essential contents of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. Meta is solely responsible for the subsequent processing of the data.
A transfer of data to the USA is possible. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are used in addition. Further information: https://www.facebook.com/privacy/policy
2. Purpose of the data processing
The Meta Pixel is used to measure the effectiveness of our advertisements on Meta platforms (conversion tracking), to build audiences for ad delivery (Custom Audiences / Lookalike Audiences) and to show you interest-based advertising (remarketing).
3. Legal basis for the data processing
The storage of information on your device and access to it take place on the basis of Section 25 (1) TDDDG; the subsequent processing of your personal data takes place on the basis of your consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR. You give your consent via our consent manager (cookie banner). Without your consent, the Meta Pixel is not loaded.
The cookies set by the Meta Pixel — in particular the first-party cookie “_fbp” and third-party cookies set by Meta domains — are stored on your device for up to 90 days. For the storage period at Meta, please refer to Meta’s privacy policy.
You have the right to withdraw your consent at any time with effect for the future. You can withdraw your consent at any time via our consent manager, which you can access via the “Cookie settings” link in the footer of our website. You can also manage settings for usage-based advertising directly in your Meta account: https://www.facebook.com/adpreferences
Use of LinkedIn Insight Tag
1. Description and scope of data processing
We use the LinkedIn Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter: LinkedIn) on our website. The Insight Tag is a code snippet which — subject to your consent — sets a cookie on your device and transmits data about your visit to our website to LinkedIn.
In particular, the following personal data may be processed:
• IP address (truncated or hashed)
• Device and browser information
• Timestamp and pages visited (referrer URL, URL)
• LinkedIn member data, if you are logged into your LinkedIn account at the same time (demographic reports are provided exclusively in aggregated, anonymised form)
For the collection and transmission of data via the Insight Tag, we and LinkedIn are joint controllers within the meaning of Art. 26 GDPR; for this purpose, we have concluded an agreement on joint controllership with LinkedIn (the “Page Insights Joint Controller Addendum”). LinkedIn is solely responsible for the subsequent processing. A transfer of data to the USA is possible; LinkedIn bases this on Standard Contractual Clauses or the EU-US Data Privacy Framework.
Further information on the processing of data by LinkedIn can be found here: https://www.linkedin.com/legal/privacy-policy
2. Purpose of the data processing
The LinkedIn Insight Tag is used to measure the success of our advertising campaigns on LinkedIn (conversion tracking), to build audiences for ad delivery (Matched Audiences / retargeting) and to create aggregated demographic reports about the visitors to our website.
3. Legal basis for the data processing
The storage of information on your device and access to it take place on the basis of Section 25 (1) TDDDG; the subsequent processing of your personal data takes place on the basis of your consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR. You give your consent via our consent manager (cookie banner).
According to LinkedIn, members’ direct identifiers are removed within seven days (pseudonymisation); the remaining pseudonymised data is deleted within 180 days. The cookies set by the Insight Tag are stored on your device for up to 180 days (see LinkedIn’s cookie table: https://www.linkedin.com/legal/l/cookie-table).
You have the right to withdraw your consent at any time with effect for the future. You can withdraw your consent at any time via our consent manager, which you can access via the “Cookie settings” link in the footer of our website. LinkedIn members can also control the use of their data for advertising purposes in their account settings: https://www.linkedin.com/psettings/advertising
This privacy policy was created with the support of DataGuard.