Skip to content
Startseite » Privacy Policy

Privacy Policy

Table of Contents

Introduction and Overview

We have prepared this Privacy Policy (version dated August 18, 2024 -312860492) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (referred to as “data” for short) we, as the data controller—and the data processors we have commissioned (e.g., service providers)—process, will process in the future, and what legal options are available to you. The terms used are to be understood as gender-neutral.

In short: We provide you with comprehensive information about the data we process about you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is intended to explain the most important points to you as simply and transparently as possible. Where it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We thus inform you in clear and simple language that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, vague, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.

If you still have questions, please contact the responsible contact listed below or in the legal notice, follow the provided links, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.

Scope of Application

This Privacy Policy applies to all personal data processed by us within our company and to all personal data processed by companies (processors) on our behalf. By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:

  • all online platforms (websites, online stores) that we operate
  • social media platforms and email communication
  • mobile apps for smartphones and other devices

In short: This Privacy Policy applies to all areas within the company where personal data is processed in a structured manner via the channels mentioned above. Should we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.

In the following Privacy Policy, we provide you with transparent information regarding the legal principles and regulations—that is, the legal bases under the General Data Protection Regulation (GDPR)—that enable us to process personal data.

With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex. europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.

We process your data only if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be storing the data you entered in a contact form.
  2. Contract (Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, if we enter into a purchase agreement with you, we need personal information in advance.
  3. Legal obligation (Article 6(1)(c) of the GDPR): If we are subject to a legal legal obligation, we process your data. For example, we are legally required to retain invoices for accounting purposes. These typically contain personal data.
  4. Legitimate Interests (Article 6(1)(f) of the GDPR): In cases where legitimate interests do not override your fundamental rights, we reserve the right to process personal data. For example, we must process certain data to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.

Other conditions, such as processing for purposes in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate section.

In addition to the EU Regulation, national laws also apply:

  • In Austria, this is the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act), or DSG for short.
  • In Germany, the Federal Data Protection Act, or BDSG for short, applies.

If other regional or national laws apply, we will inform you of this in the following sections.

Contact Information for the Data Controller

If you have any questions regarding data protection or the processing of personal data, you will find the contact information for the responsible person or department below:

Frank-Arne Knoth

Email: info@grotte-di-catullo.com

Phone: +49176 636 50 281

Legal Notice: https://grotte-di-catullo.com/en/privacy-policy/

Retention Period

It is our general policy to store personal data only for as long as is absolutely necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are legally required to store certain data even after the original purpose has ceased to exist, for example, for accounting purposes.

If you request the deletion of your data or revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.

We provide further information below regarding the specific duration of each data processing activity, to the extent that we have additional details available.

Rights Under the General Data Protection

In accordance with Articles 13 and 14 of the GDPR, we inform you of the following rights to which you are entitled to ensure fair and transparent data processing:

  • Under Article 15 of the GDPR, you have the right to request confirmation as to whether we are processing data about you. If this is the case, you have the right to receive a copy of the data and to obtain the following information:
    • regarding the purpose for which we are processing the data;
    • the categories, i.e., the types of data being processed;
    • who receives this data and, if the data is transferred to third countries, how security is ensured;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
    • that you may lodge a complaint with a supervisory authority (links to these authorities can be found below);
    • the source of the data, if we did not collect it directly from you;
    • whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
  • You have the right to rectification of your data under Article 16 of the GDPR, which means that we must correct any data if you find errors.
  • You have the right to erasure (“right to be forgotten”) under Article 17 of the GDPR, which specifically means that you may request the erasure of your data.
  • Under Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only continue to store the data but may not use it further.
  • Under Article 20 of the GDPR, you have the right to data portability, which means that we will provide you with your data in a commonly used format upon request.
  • Under Article 21 of the GDPR, , which, once exercised, results in a change to how your data is processed.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then review as quickly as possible whether we can legally comply with this objection.
    • If data is used for direct marketing, you may object to this type of data processing at any time. We may no longer use your data for direct marketing thereafter.
    • If data is used for profiling, you may object to this type of data processing at any time. We may no longer use your data for profiling after that.
  • Under certain circumstances, you have the right under Article 22 of the GDPR not to be subject to a decision based solely on automated processing (such as profiling).
  • Under Article 77 of the GDPR, you have the right to lodge a complaint. This means you can file a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights – don’t hesitate to contact the data controller listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection commissioner for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:

Baden-Württemberg Data Protection Authority

State Commissioner for Data Protection: Prof. Dr. Tobias Keber

Address: Lautenschlagerstraße 20, 70173 Stuttgart

Phone number: 07 11/61 55 41-0

Email address: poststelle@lfdi.bwl.de

Website: https://www.baden-wuerttemberg.datenschutz.de/

Data Processing Security

To protect personal data, we have implemented both technical and organizational measures. Wherever possible, we encrypt or pseudonymize personal data. In this way, we make it as difficult as possible—within the limits of our capabilities—for third parties to infer personal information from our data.

Article 25 of the GDPR refers to “data protection by design and by default,” meaning that security must always be considered—both in software (e.g., forms) and hardware (e.g., access to the server room), security must always be a priority, and appropriate measures must be implemented. Below, we’ll discuss specific measures where necessary.

TLS Encryption with HTTPS

TLS, encryption, and HTTPS sound very technical—and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the Internet in a way that is secure against eavesdropping.

This means that the entire transmission of all data from your browser to our web server is secure—no one can “eavesdrop.”

In doing so, we have introduced an additional layer of security and comply with data protection through design (Article 25(1) of the GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.

You can recognize that this data transmission security is in use by the small padlock icon in the upper-left corner of the browser, to the left of the web address (e.g., examplepage.de), and by the use of the https (instead of http) as part of our web address.

If you’d like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.

Communication

Communication Summary 👥 Data Subjects: Anyone who communicates with us by phone, email, or online form

📓 Data Processed: e.g., phone number, name, email address, form data entered. You can find more details under the respective contact method

🤝 Purpose: Handling communication with customers, business partners, etc.

📅 Retention period: Duration of the business transaction and as required by law

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6( 1(f) GDPR (Legitimate Interests)

If you contact us and communicate via phone, email, or an online form, personal data may be processed.

The data is processed to handle and address your inquiry and the associated business transaction. The data is stored for as long as necessary or as required by law.

Data Subjects

The following individuals are anyone who contacts us via the communication channels we provide.

Phone

When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business transaction has been completed and legal requirements permit.

Email

If you communicate with us via email, data may be stored on the respective device (computer, laptop, smartphone, etc.), and data is stored on the email server. The data will be deleted as soon as the business transaction is completed and legal requirements permit.

Online Forms

If you communicate with us via an online form, data will be stored on our web server and, if necessary, forwarded to one of our email addresses. The data will be deleted as soon as the business transaction is completed and legal requirements permit.

Legal Bases

The processing of data is based on the following legal bases:

  • Art. 6(1)(a) GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
  • Art. 6(1)(b) GDPR (Contract): It is necessary to fulfill a contract with you or a processor, such as a telephone service provider, or we must process the data for pre-contractual activities, such as preparing a quote;
  • Art. 6(1)(f) GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical tools, such as email programs, Exchange servers, and mobile network operators are necessary to ensure efficient communication.

Data Processing Agreement (DPA)

In this section, we’d like to explain what a Data Processing Agreement is and why it’s needed. Since the term “Data Processing Agreement” is quite a mouthful, we’ll often use the acronym DPA in this text. Like most companies, , we do not work alone but also use the services of other companies or individuals. By involving various companies or service providers, we may need to transfer personal data for processing. These partners then act as data processors, with whom we enter into a contract known as a Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be governed by the DPA.

Who are data processors?

As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. More precisely, and according to the DSG , this means: any natural or legal person, public authority, institution, or other body that processes personal data on our behalf is considered a data processor. Data processors can therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

To help clarify the terminology, here is an overview of the three roles in the GDPR:

Data Subject (you as a customer or prospective customer) → Data Controller (we as a company and the data controller) → Data Processor (service providers such as web hosts or cloud providers)

Contents of a Data Processing Agreement

As mentioned above, we have entered into a DPA with our partners who act as data processors. First and foremost, the agreement stipulates that the data processor must process the data exclusively in accordance with the GDPR. The agreement must be concluded in writing; however, in this context, an electronic agreement is also considered “in writing.” The processing of personal data takes place only on the basis of this agreement. The agreement must include the following:

  • Obligation to comply with us as the data controller
  • Obligations and rights of the data controller
  • Categories of data subjects
  • Type of personal data
  • Nature and purpose of data processing
  • Subject matter and duration of data processing
  • Location of data processing

Furthermore, the agreement sets out all obligations of the data processor. The most important obligations are:

  • To ensure data security measures
  • to implement appropriate technical and organizational measures to protect the rights of the data subject
  • to maintain a record of processing activities
  • to cooperate with the data protection supervisory authority upon request
  • to conduct a risk assessment regarding the personal data received
  • Sub-processors may only be engaged with the written authorization of the data controller

You can see what such a data processing agreement looks like, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A sample agreement is presented there.

Cookies

Cookies Summary 👥 Data Subjects: Visitors to the website

🤝 Purpose: Depends on the specific cookie. More details can be found below or from the software provider that sets the cookie.

📓 Data Processed: Depends on the specific cookie used. More details can be found below or from the software provider that sets the cookie.

📅 Retention period: Depends on the specific cookie; may vary from hours to years

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.

Below, we explain what cookies are and why they are used so that you can better understand the following privacy policy.

Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing is undeniable: Cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, since there are also other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically stored in the cookie folder—essentially the “brain” of your browser— . A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser sends the “user-specific” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you’re accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following diagram illustrates a possible interaction between a web browser—such as Chrome—and the web server. The web browser requests a website and receives a cookie from the server, which the browser reuses as soon as another page is requested.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Tro or other “malware.” Cookies also cannot access information on your computer.

Here’s an example of what cookie data might look like:

Name: _ga

Value: GA1.2.1326744211.152312860492-9

Purpose: To distinguish between website visitors

Expiration date: After 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What types of cookies are there?

The specific cookies we use depend on the services employed and are explained in the following sections of the Privacy Policy. At this point, we’d like to briefly discuss the different types of HTTP cookies.

There are four distinct types of cookies:

Essential Cookies

These cookies are necessary to ensure the website’s basic functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then browses other pages, and only proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.

Functional Cookies

These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are used to measure the website’s loading time and performance across different browsers.

Targeting Cookies

These cookies enhance the user experience. For example, they store entered locations, font sizes, or form data.

Advertising Cookies

These cookies are also called targeting cookies. They are used to deliver personalized advertising to the user. This can be very convenient, but it can also be very annoying.

Usually, when you visit a website for the first time, you’ll be asked which of these cookie types you’d like to allow. And, of course, this decision is also stored in a cookie.

If you’d like to learn more about cookies and don’t mind reading technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”

Purpose of Processing via Cookies

The purpose ultimately depends on the specific cookie. You can find more details below or from the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are small tools used for many different tasks. Unfortunately, it’s not possible to generalize about what data is stored in cookies, but we will inform you about the data processed or stored in the context of the following privacy policy.

Retention period for cookies

The retention period depends on the specific cookie and is specified in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.

You also have control over the storage duration. You can manually delete all cookies at any time via your browser (see also “Right to Object” below). Furthermore, cookies based on consent will be deleted at the latest upon revocation of your consent, although the lawfulness of their storage up to that point remains unaffected.

Right to Object – How Can I Delete Cookies?

You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only certain cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can do so in your browser settings:

Chrome: Delete, enable, and manage cookies in Chrome

Safari: Manage cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have stored on your computer

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete and manage cookies

If you generally do not want to accept cookies, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It’s best to search for instructions on Google using the search terms “Delete cookies in Chrome” or “Disable cookies in Chrome” if you’re using the Chrome browser.

Legal Basis

The so-called “Cookie Directives” have been in effect since 2009. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) of the GDPR). However, reactions to these guidelines still vary widely among EU countries. In Austria, however, this directive was implemented in § 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive was not transposed into national law. Instead, it was largely implemented in § 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.

For strictly necessary cookies, even in the absence of consent has been given, there are legitimate interests (Article 6(1)(f) of the GDPR), which are of an economic nature in most cases. We aim to provide website visitors with a pleasant user experience, and certain cookies are often strictly necessary to achieve this.

To the extent that non-strictly necessary cookies are used, this occurs only with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.

The following sections provide more detailed information about the use of cookies, provided that the software in use employs cookies.

Web Hosting Introduction

Web Hosting Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Professional hosting of the website and ensuring its operation

📓 Data Processed: IP address, time of the website visit, browser used, and other data. You can find more details below or with the respective web hosting provider.

📅 Retention period: Depends on the respective provider, but generally 2 weeks

⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate Interests)

What is Web Hosting?

When you visit websites today, certain information —including personal data—is automatically generated and stored, including on this website. This data should be processed as sparingly as possible and only for valid reasons. By “website,” we mean the entirety of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By “domain,” we mean, for example, example.de or sampleexample.com.

If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You’re probably familiar with some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as browsers or web browsers.

To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and resource-intensive task, which is why it’s usually handled by professional providers. These providers offer web hosting and ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!

When the browser on your computer (desktop, laptop, tablet, or smartphone) and during data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.

A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the Internet, and the hosting provider.

Why do we process personal data?

The purposes of data processing are:

  1. Professional website hosting and ensuring operational reliability
  2. to maintain operational and IT security
  3. Anonymous analysis of user behavior to improve our services and, if necessary, for law enforcement or the pursuit of legal claims

What data is processed?

Even as you visit our website right now, our web server—that is, the computer on which this website is hosted—typically automatically stores data such as

  • the complete web address (URL) of the page you’re viewing
  • browser and browser version (e.g., Chrome 87)
  • the operating system used (e.g., Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g., https://www.beispielquellsite.de/vondabinichgekommen/)
  • the hostname and IP address of the device from which the site is accessed (e.g., COMPUTERNAME and 194.23.43.121)
  • date and time
  • in files known as web server log files

How long is data stored?

As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that this data may be accessed by authorities in the event of unlawful conduct.

In short: Your visit is logged by our provider (the company that runs our website on dedicated computers (servers)), but we do not share your data without your consent!

Legal Basis

The lawfulness of processing personal data in the context of web hosting is based on Art. 6(1)(f) f of the GDPR (protection of legitimate interests), as the use of professional hosting services from a provider is necessary to present the company securely and in a user-friendly manner on the Internet and, if necessary, to be able to investigate attacks and related claims.

As a rule, there is a contract between us and the hosting provider regarding data processing in accordance with Art. 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security .

Web Analytics Introduction

Web Analytics Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Analysis of visitor information to optimize the website.

📓 Data Processed: Access statistics, which include data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. You can find more details on this for each web analytics tool used.

📅 Retention period: Depends on the web analytics tool used

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Web Analytics?

We use software on our website to analyze the behavior of website visitors, known as web analytics or web analysis for short. In the process, data is collected, which the respective analytics tool provider (also known as a tracking tool) stores, manages, and processes. This data is used to generate analyses of user behavior on our website, which are then made available to us as the website operator. In addition, most tools offer various testing options. For example, this allows us to test which offers or content resonate best with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles may be created and the data stored in cookies.

Why do we use web analytics?

With our website, we have a clear goal in mind: we want to provide the best website in our industry on the market. To achieve this goal, we aim to offer the best and most engaging content while also ensuring that you feel completely at ease on our website. With the help of web analytics tools, we can take a closer look at the behavior of our website visitors and then improve our website for both you and us accordingly. For example, we can determine the average age of our visitors, where they come from, when our website receives the most traffic, and which content or products are particularly popular. All of this information helps us optimize the website and tailor it as closely as possible to your needs, interests, and preferences.

What data is processed?

Exactly which data is stored naturally depends on the analytics tools used. However, as a general rule, the tools may store information such as which content you view on our website, which buttons or links you click, when you visit a page, which browser you use, what device (PC, tablet, smartphone, etc.) you use to visit the website, or what operating system you use. If you have consented to the collection of location data, this data may also be processed by the web analytics tool provider.

In addition, your IP address is also stored. According to the General Data Protection Regulation (GDPR), IP addresses are personal data. However, your IP address is generally stored in a pseudonymized form (i.e., in an unrecognizable and truncated form). For the purposes of testing, web analytics, and web optimization, no direct data—such as your name, age, address, or email address, is generally not stored for the purposes of testing, web analytics, and web optimization. All such data, if collected, is stored in a pseudonymized form. This means you cannot be identified as an individual.

The following example schematically illustrates how Google Analytics works as an example of client-based web tracking using JavaScript code.

How long the respective data is stored always depends on the provider. Some cookies store data for only a few minutes or until you leave the website; other cookies can store data for several years.

Duration of Data Processing

We provide information on the duration of data processing below, provided we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. If, as in the case of accounting, for example, it is required by law required by law, this retention period may be exceeded.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.

Legal Basis

The use of web analytics requires your consent, which we have obtained via our cookie pop-up. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by web analytics tools.

In addition to consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our offerings both technically and economically. With the help of web analytics, we detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools if you have given your consent.

Since web analytics tools use cookies, we also recommend that you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should review the privacy policies of the respective tools.

Information on specific web analytics tools, can be found—where available—in the following sections.

Facebook Conversions API Privacy Policy

We use the Facebook Conversions API on our website, a server-side event tracking tool. The service provider is the U.S. company Meta Platforms Inc. For the European region, Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is responsible.

Facebook processes your data in the U.S., among other places. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Facebook uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed . These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

Facebook’s Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/legal/terms/dataprocessing.

You can learn more about the data processed through the use of the Facebook Conversions API in the Privacy Policy at https://www.facebook.com/about/privacy.

Google Analytics Privacy Policy

Google Analytics Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Analysis of visitor information to optimize the website.

📓 Data Processed: Access statistics, which include data such as access locations, device data, duration and time of access, navigation behavior, and click behavior. More details can be found further down in this privacy policy.

📅 Retention Period: Customizable; by default, Google Analytics 4 stores data for 14 months

⚖️ Legal Basis: Art. 6(1)( a GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Google Analytics?

We use the Google Analytics tracking tool, specifically the Google Analytics 4 (GA4) version, provided by the U.S. company Google Inc., on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services . Google Analytics collects data about your activities on our website. Through the combination of various technologies such as cookies, device IDs, and login information, you, as a user, can be identified across different devices. This allows your activities to be analyzed across platforms.

For example, when you click a link, this event is stored in a cookie and sent to Google Analytics. Using the reports we receive from Google Analytics, we can better tailor our website and our services to your needs. Below, we’ll discuss the tracking tool in more detail and, most importantly, explain what data is processed and how you can prevent this.

Google Analytics is a tracking tool used to analyze traffic on our website. These measurements and analyses are based on a pseudonymous user identification number. This number does not contain any personal data such as your name or address; rather, it is used to associate events with a specific device. GA4 uses an event-based model that captures detailed information about user interactions, such as page views , clicks, scrolling, and conversion events. In addition, various machine learning features have been built into GA4 to better understand user behavior and certain trends. GA4 relies on modeling through machine learning functions. This means that, based on the collected data, missing data can also be extrapolated to optimize the analysis and enable forecasts.

For Google Analytics to function, a tracking code is embedded in our website’s code. When you visit our website, this code records various events that you perform on our website . With GA4’s event-based data model, we as website operators can define and track specific events to analyze user interactions. This allows us to track not only general information such as clicks or page views but also specific events that are important to our business. Such specific events might include, for example, submitting a contact form or purchasing a product.

As soon as you leave our website, this data is sent to Google Analytics servers and stored there.

Google processes the data, and we receive reports on your user behavior. These reports may include, among others, the following:

  • Audience reports: Audience reports help us get to know our users better and understand more precisely who is interested in our service.
  • Ad reports: Ad reports make it easier for us to analyze and improve our online advertising.
  • Acquisition reports: Acquisition reports provide us with helpful information on how we can attract more people to our service.
  • Behavioral reports: Here we learn how you interact with our website. We can track the path you take on our site and which links you click.
  • Conversion reports: A conversion is a process in which you perform a desired action in response to a marketing message. For example, when you go from being a mere website visitor to a buyer or newsletter subscriber. These reports help us learn more about how our marketing efforts are resonating with you. This is how we aim to increase our conversion rate.
  • Real-Time Reports: These reports let us know immediately what’s happening on our website right now. For example, we can see how many users are currently reading this text.

In addition to the analytics reports mentioned above, Google Analytics 4 also offers the following features, among others:

  • Event-based data model: This model tracks very specific events that can occur on our website. For example, playing a video, purchasing a product, or signing up for our newsletter.
  • Advanced analytics features: These features allow us to better understand your behavior on our website or certain general trends. For example, we can segment user groups, perform comparative analyses of target audiences, or track your journey or path on our website.
  • Predictive modeling: Based on collected data, machine learning can extrapolate missing data, predict future events and trends. This can help us develop better marketing strategies.
  • Cross-platform analysis: Data can be collected and analyzed from both websites and apps. This allows us to analyze user behavior across platforms, provided, of course, that you have consented to data processing.

Why do we use Google Analytics on our website?

Our goal with this website is clear: We want to offer you the best possible service. The statistics and data from Google Analytics help us achieve this goal.

The statistically analyzed data gives us a clear picture of our website’s strengths and weaknesses. On the one hand, we can optimize our site so that interested people can find it more easily on Google. On the other hand, the data helps us as a visitor. This allows us to know exactly what we need to improve on our website to offer you the best possible service. The data also helps us tailor our advertising and marketing efforts to be more personalized and cost-effective. After all, it only makes sense to show our products and services to people who are interested in them.

What data is stored by Google Analytics?

Google Analytics uses a tracking code to generate a random unique ID, which is linked to your browser cookie. This allows Google Analytics to recognize you as a new user and assign you a user ID. The next time you visit our site, you’ll be recognized as a “returning” user. All collected data is stored together with this user ID. This is what makes it possible to analyze pseudonymous user profiles.

To analyze our website with Google Analytics, a property ID must be included in the tracking code . The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is set by default. Depending on the property used, data is stored for varying lengths of time.

Through identifiers such as cookies, app instance IDs, user IDs, or custom event parameters, your interactions—provided you have given your consent—are measured across platforms. Interactions include all types of actions that you perform on our website. If you also use other Google systems (such as, a Google Account), data generated via Google Analytics may be linked to third-party cookies. Google does not share Google Analytics data unless we, as the website operator, authorize it. Exceptions may apply if required by law.

According to Google, IP addresses are not logged or stored in Google Analytics 4. However, Google uses IP address data to derive location data and deletes it immediately afterward. All IP addresses collected from users in the EU are therefore deleted before the data is stored in a data center or on a server.

Since Google Analytics 4 focuses on event-based data, the tool uses significantly fewer cookies compared to earlier versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies used by GA4. These include, for example:

Name: _ga

W ert: 2.1326744211.152312860492-5

Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Essentially, it is used to distinguish between website visitors.

Expiration date: after 2 years

Name: _gid

Value: 2.1687193234.152312860492-1

Purpose: This cookie is also used to distinguish between website visitors

Expiration date: after 24 hours

Name: _gat_gtag_UA_<property-id>

Value: 1

Purpose: Used to reduce the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie is named _dc_gtm_<property-id>.

Expiration date: after 1 minute

Note: This list is not exhaustive, as Google frequently updates its cookie settings. One of GA4’s goals is to improve data protection. Therefore, the tool offers several options for controlling data collection. For example, we can set the storage duration ourselves and also control data collection.

Here is an overview of the most important types of data collected by Google Analytics:

Heatmaps: Google creates so-called heatmaps. Heatmaps show exactly which areas you click on. This gives us information about where you’re “navigating” on our site.

Session duration: Google defines session duration as the time you spend on our site without leaving it. If you’ve been inactive for 20 minutes, the session ends automatically.

Bounce rate: A bounce occurs when you view only one page on our website and then leave our website.

Account creation: When you create an account or place an order on our website, Google Analytics collects this data.

Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, it is used to infer location data.

Technical Information: Technical information includes, among other things, your browser type, your internet service provider, and your screen resolution.

Referral Source: Google Analytics—and, of course, we—are also interested in knowing which website or advertisement led you to our site .

Additional data includes contact information, any reviews, media playback (e.g., when you play a video on our site), sharing content via social media, or adding items to your favorites. This list is not exhaustive and is intended only as a general guide to data storage by Google Analytics.

How long and where is the data stored?

Google has servers located all over the world. You can find out exactly where Google’s data centers are located: https://www.google.com/about/datacenters/locations/?hl=de

Your data is distributed across various physical storage media. This has the advantage of making the data more quickly accessible and better protected against tampering. Every Google data center has appropriate contingency plans in place for your data. For example, even if Google’s hardware fails or natural disasters cripple servers, the risk of a service interruption at Google remains low.

The data retention period depends on the properties used. The retention period is always set individually for each property. Google Analytics offers us four options for controlling the retention period:

  • 2 months: This is the shortest retention period.
  • 1 4 months: By default, data is stored in GA4 for 14 months.
  • 26 months: You can also store the data for 26 months.
  • Data is only deleted when we delete it manually

Additionally, there is an option to have data deleted only if you do not visit our website again within the time period we’ve selected. In this case, the retention period is reset each time whenever you visit our website again within the specified period.

Once the specified period has expired, the data is deleted once a month. This retention period applies to your data linked to cookies, user identification, and advertising IDs (e.g., cookies from the DoubleClick domain). Report results are based on aggregated data and are stored separately from user data. Aggregated data is the combination of individual data points into a larger unit.

How can I delete my data or prevent it from being stored?

Under European Union data protection law, you have the right to access, update, delete, or restrict your data. By using the browser add-on to disable Google Analytics JavaScript (analytics.js, gtag .js), you can prevent Google Analytics 4 from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de. Please note that this add-on only disables data collection by Google Analytics.

If you wish to disable cookies in general, delete, or manage cookies in general, you’ll find the corresponding links to the respective guides for the most popular browsers in the “Cookies” section.

Legal Basis

The use of Google Analytics requires your consent, which we have obtained via our cookie pop-up. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by web analytics tools.

In addition to your consent, we have a legitimate interest in analyzing the behavior of website visitors in order to improve our offerings both technically and economically. With the help of Google Analytics, we detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Analytics to the extent that you have given your consent.

Google processes your data, , among other places, in the United States. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684 -ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even even when it is transferred to and stored in third countries (such as the United States). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/ 2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

We hope we’ve been able to provide you with the most important information regarding data processing by Google Analytics. If you’d like to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245? hl=de.

If you’d like to learn more about data processing, please refer to Google’s Privacy Policy at https://policies.google.com/privacy?hl=de.

Google Analytics Data Processing Agreement (DPA)

In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with Google. You can read more about what exactly a DPA is and, most importantly, what must be included in a DPA in our general section titled “Data Processing Agreement (DPA).”

This agreement is required by law because Google processes personal data on our behalf. It clarifies that Google may only process data it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the data processing terms at https://business.safety.google/intl/de/adsprocessorterms/

Google Analytics Reports on Demographic Characteristics and Interests

We have enabled the advertising reporting features in Google Analytics. The reports on demographic characteristics and interests contain information on age, gender, and interests. This allows us to gain a better understanding of our users—without being able to link this data to specific individuals. You can learn more about the advertising features at https:// support.google.com/analytics/answer/3450482?hl=de_AT&utm_id=ad.

You can opt out of the use of your Google Account activity and information under “Ad Settings” at https://adssettings.google.com/authenticated by checking the appropriate box.

Google Analytics E-Commerce Tracking

We also use the e-commerce tracking feature of the Google Analytics web analytics tool for our website. This allows us to analyze in great detail how you and all our other customers interact with our website. E-commerce tracking focuses primarily on purchasing behavior. Based on the data collected, we can tailor and optimize our service to meet your needs and expectations. We can also target our online advertising efforts more effectively, ensuring that our ads are seen only by people who are actually interested in our products or services. E-commerce measurement tracks, for example, which orders were placed, how long it took you to purchase the product, what the average order value is, and how much the shipping costs are. All of this data can be collected and stored under a specific ID.

Google Site Kit Privacy Policy

Google Site Kit Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Analysis of visitor information to optimize the website.

📓 Data Processed: Access statistics, including data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. More details can be found below and in the Google Analytics Privacy Policy.

📅 Retention period: Depends on the properties used

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Google Site Kit?

We have integrated the WordPress plugin Google Site Kit, developed by the U.S. company Google Inc., into our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. With Google Site Kit, we can quickly and easily view statistics from various Google products, such as Google Analytics, directly in our WordPress dashboard. The tool—or rather, the tools integrated into Google Site Kit—also collect personal data from you, among other things. In this privacy policy, we explain why we use Google Site Kit, how long and where data is stored, and which other privacy policies are relevant to you in this context.

Google Site Kit is a plugin for the WordPress content management system. With this plugin, we can view important statistics for website analysis directly in our dashboard. This includes statistics collected by other Google products, primarily Google Analytics. In addition to Google Analytics, services such as Google Search Console, Page Speed Insights, Google AdSense, Google Optimize, and Google Tag Manager can also be linked to Google Site Kit.

Why do we use Google Site Kit on our website?

As a service provider, it is our mission to offer you the best possible experience on our website. We want you to feel comfortable on our website and to find exactly what you’re looking for quickly and easily. Statistical analyses help us get to know you better and tailor our offerings to your preferences and interests. We use various Google tools for these analyses. Site Kit makes our work much easier in this regard because we can view and analyze the statistics from Google products directly in the dashboard. This means we no longer have to log in separately for each tool. Site Kit thus always provides a good overview of the most important analytics data.

What data is stored by Google Site Kit?

If you have actively consented to tracking tools in the cookie notice (also known as a script or banner), Google products such as Google Analytics will set cookies and send data about you—such as your user behavior—to Google, where it is stored and processed. This includes personal data such as your IP address.

For more detailed information on the individual services, we have dedicated sections in this privacy policy. For example, take a look at our privacy policy for Google Analytics. There, we go into great detail about the data collected. You’ll learn how long Google Analytics stores, manages, and processes data, which cookies may be used, and how you can prevent data storage. We also have separate privacy policies with comprehensive information for other Google services such as Google Tag Manager or Google AdSense.

Below, we provide examples of Google Analytics cookies that may be set in your browser, provided you have generally consented to data processing by Google. Please note that these cookies are merely a selection:

Name: _ga

Value:2.13267442 11.152312860492-2

Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Its primary purpose is to distinguish between website visitors.

Expiration date: after 2 years

Name: _gid

Value:2.1687193234.152312860492-7

Purpose: This cookie is also used to distinguish between website visitors.

Expiration date: after 24 hours

Name: _gat_gtag_UA_<property-id>

Value: 1

Purpose: This cookie is used to reduce the request rate.

Expiration date: after 1 minute

How long and where is the data stored?

Google stores collected data on its own Google servers, which are distributed worldwide. Most servers are located in the United States, so it is quite possible that your data will also be stored there . At https://www.google.com/about/datacenters/locations/?hl=de, you can see exactly where the company operates servers.

Data collected by Google Analytics is retained for a standard period of 26 months. After that, your user data is deleted. The retention period applies to all data linked to cookies, user identification, and advertising IDs.

How can I delete my data or prevent it from being stored?

You always have the right to access your data, as well as to have it deleted, corrected, or restricted. You can also disable, delete, or manage cookies in your browser at any time.

If you wish to disable, delete, or manage cookies in general, you’ll find the relevant links to the respective guides for the most popular browsers in the “Cookies” section.

Legal Basis

The use of Google Site Kit requires your consent, which we have obtained via our cookie pop-up. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur when data is collected by web analytics tools.

In addition to your consent, we have a legitimate interest in analyzing the behavior of website visitors to improve our offerings both technically and economically. With the help of Google Site Kit, we detect website errors, identify attacks, and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) of the GDPR GDPR (Legitimate Interests). However, we only use Google Site Kit to the extent that you have given your consent.

Google also processes your data in the U.S., among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https:/ /commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR) . Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to maintaining the European level of data protection , even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/ dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/ de/adsprocessorterms/.

To learn more about data processing by Google, we recommend reviewing Google’s comprehensive Privacy Policy at https://policies.google.com/privacy?hl=de.

TikTok Pixel Privacy Policy

We use TikTok Pixel on our website, a conversion tracking tool for advertisers. The service provider is the Chinese company TikTok. For the European region, the responsible entity is TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland).

TikTok processes your data in the U.S., among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.

As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the United States) or for data transfers to there, TikTok uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through these clauses, TikTok commits to maintaining the European level of data protection when processing your relevant data , even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/ oj?locale=de

You can learn more about the Standard Contractual Clauses and the data processed through the use of TikTok Pixel in the Privacy Policy at https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE or at https://ads.tiktok.com/i18n/ official/policy/controller-to-controller.

Social Media Introduction

Social Media Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Presenting and optimizing our services, contacting visitors, prospective customers, and others, advertising

📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.

You can find more details on this in the respective social media tool.

📅 Retention Period: Depends on the social media platforms used

⚖️ Legal Basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is social media?

In addition to our website, we are also active on various social media platforms. In this context, user data may be processed so that we can specifically target users who are interested in us via social networks. In addition, elements of a social media platform may also be embedded directly into our website. This is the case, for example, when you click on a so-called social button on our website and are redirected directly to our social media presence. “Social media” refers to websites and apps through which registered members can create content, share content publicly or within specific groups, and connect with other members.

Why do we use social media?

For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to interested parties. The social media elements integrated into our website help you quickly and easily navigate to our social media content.

The data stored and processed through your use of a social media channel is primarily intended to enable web analytics. The goal of these analyses is to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, the analyzed data can be used to draw relevant conclusions about your interests and so-called user profiles can be created. This also enables the platforms to present you with tailored advertisements. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.

We generally assume that we remain responsible under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Article 26 of the GDPR. To the extent that this is the case, we will indicate this separately and operate on the basis of a relevant agreement. The key terms of the agreement are then outlined below for the respective platform.

Please note that when using social media platforms or our embedded features, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are U.S. companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.

What data is processed?

Exactly what data is stored and processed depends on the respective social media platform provider. However, it typically includes data such as phone numbers, e- mail addresses, data you enter into a contact form, user data such as which buttons you click, who you “like” or follow, when you visited which pages, information about your device, and your IP address. Most of this data is stored in cookies. Specifically, if you have a profile on the social channel and are logged in, data may be linked to your profile.

All data collected via a social media platform is also stored on the providers’ servers. Consequently, only the providers have access to the data and can provide you with the relevant information or make changes.

If you want to know exactly what data is stored and processed by the social media providers and how you can object to data processing, you should carefully read the respective company’s privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the provider directly.

Duration of Data Processing

We provide information on the duration of data processing below, to the extent that we have further details. For example, the social media platform Facebook stores data until it is no longer needed for its own purposes. However, customer data that is matched with a user’s own data is deleted within two days. In general, we process personal data only for as long as is absolutely necessary to provide our services and products . If required by law—as is the case with accounting, for example—this retention period may be extended.

Right to Object

You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers, such as embedded social media elements. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since social media tools may use cookies , we also recommend that you review our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, provided consent has been given, your data is also stored and processed on the basis of our legitimate interest (Art. 6( 1(f) GDPR) to ensure fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

Information on specific social media platforms—where available—can be found in the following sections.

Facebook Privacy Policy

Facebook Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: To optimize our services

📓 Data Processed: Data such as customer data, user behavior data, information about your device, and your IP address.

You can find more details below in the privacy policy.

📅 Retention Period: Until the data is no longer useful for Facebook’s purposes

⚖️ Legal Basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are Facebook Tools?

We use selected Facebook tools on our website. Facebook is a social media network operated by Meta Platforms Inc. or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. These tools enable us to provide you and others interested in our products and services with the best possible experience.

If data is collected from you and transmitted via our embedded Facebook elements or through our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook bears sole responsibility for the further processing of this data. Our joint obligations are also set forth in a publicly available agreement at https://www.facebook.com/legal/controller_addendum. This agreement stipulates, for example, that we must clearly inform you about the use of Facebook tools on our site. Furthermore, we are also responsible for ensuring that the tools are integrated into our website in a manner that complies with data protection laws. Facebook, on the other hand, is responsible, for example, for the data security of Facebook products. If you have any questions regarding data collection and processing by Facebook, you can contact the company directly. If you direct your question to us, we are obligated to forward it to Facebook.

Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.

In addition to many other products, Facebook also offers what are known as “Facebook Business Tools.” This is Facebook’s official term. However, since the term is not widely known, we have decided to simply refer to them as Facebook tools. These include, among others:

  • Facebook Pixel
  • Social plugins (such as the “Like” or “Share” button)
  • Facebook Login
  • Account Kit
  • APIs (Application Programming Interfaces)
  • SDKs (Software Development Kits)
  • Platform integrations
  • Plugins
  • Codes
  • Specifications
  • Documentation
  • Technologies and services

Through these tools, Facebook expands its services and is able to obtain information about user activities outside of Facebook.

Why do we use Facebook tools on our website?

We want to show our services and products only to people who are genuinely interested in them. With the help of ads (Facebook Ads), we can reach exactly these people. However, in order to show users relevant ads, Facebook needs information about their preferences and needs. Thus, information about user behavior (and contact information) on our website. This allows Facebook to collect more accurate user data and display relevant ads about our products and services to interested people. The tools thus enable tailored advertising campaigns on Facebook.

Facebook refers to data about your behavior on our website as “event data.” This data is also used for measurement and analytics services. This allows Facebook to create “campaign reports” on our behalf regarding the effectiveness of our advertising campaigns. Furthermore, analytics provide us with better insight into how you use our services, website, or products. We use some of these tools to optimize your user experience on our website. For example, you can use the social plug , you can share content from our site directly on Facebook.

What data is stored by Facebook tools?

When you use certain Facebook tools, personal data (customer data) may be sent to Facebook. Depending on the tools used, customer data such as name, address, phone number, and IP address may be transmitted.

Facebook uses this information to match the data with the information it already has about you (provided you are a Facebook member). Before customer data is transmitted to Facebook, a process known as “hashing” takes place. This means that a data set of any size is transformed into a string of characters. This also serves to encrypt the data.

In addition to contact information, “event data” is also transmitted. “Event data” refers to the information we collect about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information it receives with third parties (such as advertisers) unless the company has explicit permission or is legally required to do so. “Event data” can also be linked to contact information. This allows Facebook to offer better personalized advertising. After the aforementioned matching process, Facebook deletes the contact information.

To deliver optimized ads, Facebook uses event data only when it has been aggregated with other data (collected by Facebook through other means). Facebook also uses this event data for security, protection, development, and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, a varying number of cookies are stored in your browser. We discuss individual Facebook cookies in more detail in the descriptions of the various Facebook tools. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.

How long and where is the data stored?

Generally, Facebook stores data until it is no longer needed for its own services and Facebook products. Facebook has servers located around the world where its data is stored. However, customer data is deleted within 48 hours.

How can I delete my data or prevent it from being stored?

In accordance with the General Data Protection Regulation (GDPR), you have the right to access, correct, transfer, and delete your data.

Your data will only be completely deleted if you account completely. Here’s how to delete your Facebook account:

1) Click “Settings” on the right side of Facebook.

2) Then click “Your Facebook Information” in the left column.

3) Now click “Deactivation and Deletion.”

4) Now select “Delete Account” and then click “Continue and Delete Account”

5) Now enter your password, click “Continue,” and then click “Delete Account”

The data that Facebook receives through our site is stored, among other things, via cookies (e.g., in social plugins). In your browser, you can disable, delete, or manage individual or all cookies. Depending on which browser you use, this works in different ways. Under the “Cookies” section, you’ll find the corresponding links to the respective instructions for the most popular browsers.

If you do not want to accept cookies at all, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.

Legal Basis

If you have consented to the processing and storage of your data by integrated Facebook tools, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed based on our legitimate interest (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review Facebook’s privacy policy or cookie guidelines.

Facebook processes your data, among other places, in the United States. Facebook, or Meta Platforms, is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. You can find more information on this at https: //commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Facebook uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Facebook commits to adhering to relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/ 914/oj?locale=de

The Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/legal/terms/ dataprocessing.

We hope we’ve provided you with the most important information about the use and processing of data by Facebook tools. If you’d like to learn more about how Facebook uses your data, we recommend reviewing the privacy policy at https://www.facebook.com/privacy/policy/.

Facebook Login Privacy Policy

We have integrated the convenient Facebook Login feature on our site. This allows you to easily log in to our site using your Facebook account, without having to create another user account. If you decide to register via Facebook Login, you will be redirected to the Facebook social media network. There, you will log in using your Facebook credentials. Through this login process, data about you and your user behavior is stored and transmitted to Facebook.

To store this data, Facebook uses various cookies. Below, we list the most important cookies that are set in your browser or already exist when you log in to our site via the Facebook login:

Name: fr

Value: 0jieyh4c2GnlufEJ9..Bde09j…1.0.Bde09j

Purpose: This cookie is used to ensure that the social plugin on our website functions as effectively as possible .

Expiration date: after 3 months

Name: datr

Value: 4Jh7XUA2312860492SEmPsSfzCOO4JFFl

Purpose: Facebook sets the “datr” cookie when a web browser accesses facebook.com; the cookie helps identify login activities and protect users.

Expiration date: after 2 years

Name: _js_datr

Value: deleted

Purpose: Facebook sets this session cookie for tracking purposes, even if you do not have a Facebook account or are logged out.

Expiration date: at the end of the session

Note: The cookies listed here are only a small selection of the cookies available to Facebook. Other cookies include, for example, _fbp, sb, or wd. A complete list is not possible, as Facebook uses a large number of cookies and deploys them in varying ways.

The Facebook login not only offers you a quick and easy registration process, but it also allows us to share data with Facebook. This enables us to better tailor our offerings and promotional campaigns to your interests and needs. Data we receive from Facebook in this way includes public data such as

  • your Facebook name
  • your profile picture
  • a stored email address
  • friend lists
  • button interactions (e.g., “Like” button)
  • birthday
  • language
  • location

In return, we provide Facebook with information about your activities on our website. This includes, among other things, information about the device you’re using, which pages you visit on our site, and which products you’ve purchased from us.

By using Facebook Login, you consent to the processing of your data. You can revoke this consent at any time. If you would like to learn more about Facebook’s data processing, we recommend reviewing Facebook’s Privacy Policy at https://www.facebook.com/privacy/policy/.

If you are logged into Facebook, you can adjust your ad settings yourself at https://www.facebook.com/adpreferences/advertisers/?entry_product=ad_settings_screen.

Facebook Social Plug-ins Privacy Policy

Our website incorporates so-called social plug-ins from Meta Platforms Inc. You can recognize these buttons by the classic Facebook logo, such as the “Like” button (the hand with a thumbs-up) or by a distinct “Facebook Plug-in ” label. A social plugin is a small component of Facebook that is integrated into our site. Each plugin has its own function. The most commonly used functions are the well-known “ “Like” and “Share” buttons.

Facebook offers the following social plugins:

  • “Save” button
  • “Like” button, Share, Send, and Quote
  • Page plugin
  • Comments
  • Messenger plugin
  • Embedded posts and video players
  • Groups plugin

You can find more detailed information on how the individual plugins are used at https://developers.facebook.com/docs/plugins. We use social plugins both to offer you a better user experience on our site and to allow Facebook to optimize our ads.

If you have a Facebook account or have ever visited https://www.facebook.com/, Facebook has already placed at least one cookie in your browser. In this case, your browser sends information to Facebook via this cookie as soon as you visit our site or interact with social plugins (e.g., the “Like” button).

The information collected is deleted or anonymized within 90 days. According to Facebook, this data includes your IP address, the website you visited, the date, the time, and other information related to your browser.

To prevent Facebook from collecting a large amount of data during your visit to our website and linking it to your Facebook data, you must log out of Facebook while visiting the website.

If you are not logged in to Facebook or do not have a Facebook account, your browser will send less information to Facebook because you have fewer Facebook cookies. However, data such as your IP address or the websites you visit may still be transmitted to Facebook. We would like to expressly point out that we do not know the exact contents of this data. However, we strive to inform you as best as possible about data processing based on our current knowledge. You can also read about how Facebook uses this data in the company’s Privacy Policy at https://www.facebook.com/about/privacy/update.

At a minimum, the following cookies are set in your browser when you visit a website with Facebook social plugins:

Name: dpr

Value: Not specified

Purpose: This cookie is used to ensure that the social plugins on our website function properly.

Expiration date: at the end of the session

Name: fr

Value: 0jieyh4312860492c2GnlufEJ9..Bde09j…1.0.Bde09j

Purpose: This cookie is also necessary for the plugins to function properly.

Expiration date: after 3 months

Note: These cookies were set following a test, even if you are not a Facebook member.

If you are logged into Facebook, you can change your ad settings yourself at https://www.facebook.com/adpreferences/advertisers/. If you are not a Facebook user, you can generally manage your usage-based online advertising at https://www.youronlinechoices.com/de/ preference-management/?tid=312860492 to manage your usage-based online advertising. There, you have the option to disable or enable specific providers.

If you would like to learn more about Facebook’s data protection practices, we recommend reviewing the company’s own privacy policy at https://www.facebook.com/privacy/policy/.

Instagram Privacy Policy

Instagram Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: To optimize our services

📓 Data Processed: Data such as user behavior data, information about your device, and your IP address.

You can find more details below in the privacy policy.

📅 Retention Period: until Instagram no longer needs the data for its purposes

⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Instagram?

We have integrated Instagram features into our website. Instagram is a social media platform operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and is part of the Facebook family of products. The inclusion of Instagram content on our website is referred to as “embedding.” This allows us to display content such as buttons, photos, or videos from Instagram directly on our website. When you visit pages on our website that have an Instagram feature integrated, data is transmitted to Instagram, where it is stored and processed. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed across all Facebook companies.

Below, we’d like to provide you with a more detailed explanation of why Instagram collects data, what types of data are involved, and how you can largely control data processing. Since Instagram is owned by Meta Platforms Inc., we base our information on both the Instagram Terms of Service and the Meta Privacy Policy itself.

Instagram is one of the most well-known social media networks worldwide. Instagram combines the benefits of a blog with those of audiovisual platforms like YouTube or Vimeo. On “Insta” (as many users colloquially call the platform), you can upload photos and short videos, edit them with various filters, and share them on other social networks. And if you don’t want to be active yourself, you can simply follow other interesting users.

Why do we use Instagram on our website?

Instagram is the social media platform that has really taken off in recent years. And, of course, we’ve responded to this boom as well. We want you to feel as comfortable as possible on our website. That’s why presenting our content in a variety of ways is a given for us. Thanks to the embedded Instagram features, we can enrich our content with helpful, funny, or exciting material from the world of Instagram. Since Instagram is a subsidiary of Facebook, the data collected can also be used for personalized advertising on Facebook . This ensures that our ads reach only people who are genuinely interested in our products or services.

Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics, which give us more insight into your preferences and interests. It’s important to note that these reports do not personally identify you.

What data does Instagram store?

When you visit one of our pages that incorporates Instagram features (such as Instagram images or plug-ins), your browser automatically connects to Instagram’s servers. In the process, data is sent to Instagram, where it is stored and processed. This happens regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases you’ve made, the ads you see, and how you use our services. Additionally, the date and time of your interaction with Instagram are stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.

Facebook distinguishes between customer data and event data. We assume that this is also the case with Instagram. Customer data includes, for example, your name, address, phone number, and IP address. This customer data will only be transmitted to Instagram after it has been “hashed.” Hashing means that a data record is converted into a string of characters. This allows contact data to be encrypted. In addition, the “event data” mentioned above is also transmitted. By “event data,” Facebook—and consequently Instagram as well—means data about your user behavior. Contact data may also be combined with event data. The collected contact data is matched with the data Instagram already has about you.

Via small text files (cookies), which are usually set in your browser, the collected data is transmitted to Facebook. Depending on the Instagram features you use and whether you have an Instagram account yourself, varying amounts of data are stored.

We assume that data processing on Instagram works the same way as on Facebook. This means: if you have an Instagram account or have visited www.instagram.com, Instagram has set at least one cookie. If that is the case, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram feature. No later than 90 days (after reconciliation), this data is deleted or anonymized. Although we’ve looked closely at Instagram’s data processing practices, we can’t say with complete certainty exactly what data Instagram collects and stores.

Below, we’ll show you the cookies that are set in your browser at a minimum when you click on an Instagram feature (such as a button or an Instagram image). For the purposes of our test, we’re assuming that you do not have an Instagram account. If you are logged into Instagram, significantly more cookies will, of course, be set in your browser.

The following cookies were used in our test:

Name: csrftoken

Value: “”

Purpose: This cookie is most likely set for security reasons to prevent forged requests. However, we were unable to determine this with greater precision.

Expiration date: after one year

Name: mid

Value: “”

Purpose: Instagram sets this cookie to optimize its own services and offerings both on and off Instagram. The cookie assigns a unique user ID.

Expiration date: at the end of the session

Name: fbsr_312860492124024

Value: not specified

Purpose: This cookie stores the login request for users of the Instagram app.

Expiration date: at the end of the session

Name: rur

Value: ATN

Purpose: This is an Instagram cookie that ensures functionality on Instagram.

Expiration date: at the end of the session

Name: urlgen

Value: “{”194.96. 75.33”: 1901}:1iEtYv:Y833k2_UjKvXgYe312860492”

Purpose: This cookie is used for Instagram’s marketing purposes.

Expiration date: at the end of the session

Note: We cannot guarantee that this list is exhaustive. Which cookies are set in each individual case depends on the embedded features and your use of Instagram.

How long and where is the data stored?

Instagram shares the information it receives with other Facebook companies, external partners, and people you connect with worldwide. Data processing is carried out in accordance with Instagram’s own privacy policy. Your data is distributed across Facebook servers worldwide, in part for security reasons. Most of these servers are located in the United States.

How can I delete my data or prevent it from being stored?

Under the General Data Protection Regulation (GDPR), you have the right to access, portability, rectification, and erasure of your data. You can manage your data in the Instagram settings. If you want to completely delete your data from Instagram, you must permanently delete your Instagram account.

Here’s how to delete your Instagram account:

First, open the Instagram app. On your profile page, scroll down and click “Help Center.” This will take you to the company’s website. On the website, click “Manage Your Account” and then “Delete Your Account.”

If you delete your account completely, Instagram will delete posts such as your photos and status updates. Information that other people have shared about you is not part of your account and will therefore not be deleted.

As mentioned above, Instagram primarily stores your data using cookies. You can manage, disable, or delete these cookies in your browser. The process varies slightly depending on your browser. Under the “Cookies,” you’ll find links to the instructions for the most popular browsers.

You can also configure your browser to always notify you when a cookie is about to be set. This allows you to decide on a case-by-case basis whether to accept the cookie or not.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR) . In general, your data is also stored and processed based on our legitimate interest (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

Instagram processes your data, among other places, in the United States. Instagram, or rather Meta Platforms is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data of EU citizens to the U.S. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Instagram uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Instagram commits to maintaining the European level of data protection , even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

We have tried to provide you with the most important information about data processing by Instagram. At https://privacycenter.instagram.com/policy/ you can learn more about Instagram’s data policies.

TikTok Privacy Policy

TikTok Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: To optimize our services

📓 Data Processed: Information such as your IP address, browser data, and the date and time of your visit may be stored

You can find more details further down in the privacy policy.

📅 Retention period: Varies depending on settings

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is TikTok?

We use TikTok integration on our website. The service provider is the Chinese company Beijing Bytedance Technology Ltd. For the European region, the Irish company TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. TikTok is a popular social media platform, especially among young people, where users can create, share, and watch short video clips.

In this privacy policy, we inform you about what data is processed by TikTok, how long the data is stored, and how you can manage your privacy settings.

Why do we use TikTok on our website?

We’ve integrated TikTok into our website so that, if you’d like, you can watch TikTok videos and interact with them. TikTok is particularly known for its funny and creative content, and of course we don’t want to deprive you of such content. After all, we also enjoy watching the occasional creative TikTok video ourselves.

What data does TikTok process?

When you watch or interact with TikTok videos on our website, TikTok may collect information about your usage behavior and your device. This may include data such as your IP address, browser type, operating system, location, and other technical information. TikTok may also use cookies and similar technologies to collect information and personalize your user experience.

If you have a TikTok account yourself, additional information may also be collected and processed. This includes, for example, user information (such as your name, date of birth, or email address) and data about your communication with other TikTok users.

How long and where is the data stored?

The retention period and storage locations of the data collected by TikTok can vary significantly and are subject to TikTok’s privacy policy. TikTok may also store data on servers in the U.S. and other countries. The storage period is generally determined by applicable legal requirements and internal policies. However, we have not yet been able to determine exactly how long data is stored. As soon as we have more detailed information, we will of course let you know.

How can I delete my data or prevent it from being stored?

If you have a TikTok account , you can manage your privacy settings directly on TikTok. For example, in your TikTok account settings, you can specify which information may be shared and which may not. In addition, you can manage and disable cookies in your web browser to limit data collection. Of course, this is also possible without a TikTok account. Please note, however, that this may affect the functionality of our website and your TikTok experience.

Legal Basis

If you have consented to TikTok processing and storing your data, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed based on our legitimate interest (Art. 6(1)(f) GDPR) in maintaining prompt and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have given your consent. TikTok may also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

TikTok processes your data and a. in the United States as well. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.

As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the U.S.) or for data transfers to those countries, TikTok uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs – SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, TikTok commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more information on TikTok’s privacy policy and its data collection practices, please visit the TikTok website at https://www.tiktok.com/legal/page/eea/privacy-policy/en and review the general information about TikTok at https://www.tiktok.com/en/.

X (formerly: Twitter) Privacy Policy

X (formerly: Twitter) Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: To optimize our services

📓 Data Processed: Data such as user behavior data, information about your device, and your IP address.

You can find more details below in the privacy policy.

📅 Retention period: X deletes data collected from other websites after 30 days at the latest

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is X?

On our website , we have integrated features from X. These include, for example, embedded tweets, timelines, buttons, or hashtags. X is a short-form messaging service and social media platform operated by the American company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For the European region, the company is Twitter International Unlimited Company (One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland) is responsible for the processing of personal data.

To the best of our knowledge, simply embedding X features does not result in the transfer of any personal data or data regarding your web activities to X within the European Economic Area or Switzerland. Only when you interact with the X features—such as by clicking a button—can data be sent to X, where it is stored and processed. We have no control over this data processing and we bear no responsibility for it. In this Privacy Policy, we aim to provide you with an overview of what data X stores, what X does with this data, and how you can largely protect yourself against data transmission.

For some, X is a messaging service; for others, a social media platform; and still others refer to it as a microblogging service. All of these terms are valid and mean more or less the same thing.

Both individuals individuals and companies alike use X to communicate with interested people via short messages. X allows only 280 characters per message. These messages are called “tweets.” Unlike Facebook, for example, the service does not focus on building a network of “friends” , but aims to be seen as a global and open messaging platform. On X, you can also maintain an anonymous account, and tweets can be deleted either by the company or by the users themselves.

Why do we use X on our website?

Like many other websites and companies, we strive to offer our services through various channels and to communicate with our customers. X in particular—which many people probably know better than Twitter—has become a favorite of ours as a useful “small” messaging service. We frequently tweet or retweet exciting, funny, or interesting content. We realize that you can’t follow every channel separately—after all, you have other things to do as well. That’s why we’ve also integrated X features on our website. You can follow our X activity “right here” or access our X page via a direct link. By integrating these features, we aim to enhance our service and improve the user experience on our website.

What data does X store?

You’ll find the embedded X features on some of our subpages. When you interact with X content—such as clicking a button—X may collect and store data, even if you don’t have an X account yourself. X refers to this data as “log data.” This includes demographic data, browser cookie IDs, your smartphone’s ID, hashed email addresses, and information about which pages you’ve visited on X and what actions you’ve taken. Of course, X stores more data if you have an X account and are logged in. Until now, this data was stored using cookies. Cookies are small text files, which are usually set in your browser and transmit various types of information to X.

We’ll now show you which cookies are set when you’re not logged in to X but visit a website with built-in X features. Please consider this list an example. We cannot guarantee that it is exhaustive, as the selection of cookies is constantly changing and depends on your individual interactions with X content.

These cookies were used in our test:

Name: personalization_id

Value: “v1_cSJIsogU51SeE312860492”

Purpose: This cookie stores information about how you use the website and which advertisements may have led you to X.

Expiration date: after 2 years

Name: lang

Value: de

Purpose: This cookie stores your default or preferred language.

Expiration date: at the end of the session

Name: guest_id

Value: 312860492v1%3A157132626

Purpose: This cookie is set to identify you as a guest.

Expiration date: after 2 years

Name: fm

Value: 0

Purpose: Unfortunately, we were unable to determine the purpose of this cookie.

Expiration date: at the end of the session

Name: external_referer

Value: 3128604922beTA0sf5lkMrlGt

Purpose: This cookie collects anonymous data, such as how often you visit X and how long you stay on X.

Expiration date: After 6 days

Name: eu_cn

Value: 1

Purpose: This cookie stores user activity and is used for various advertising purposes by X.

Expiration date: After one year

Name: ct0

Value: c1179f07163a365d2ed7aad84c99d966

Purpose: Unfortunately, we were unable to find any information about this cookie.

Expiration date: After 6 hours

Name: _twitter_sess

Value: 53D%253D–dd0248312860492-

Purpose: This cookie allows you to use features on the X website.

Expiration date: at the end of the session

Note: X also works with third-party providers. That is why we also detected the three Google Analytics cookies _ga, _gat, _gid.

X uses the collected data, on the one hand, to better understand user behavior and thereby improve its own services and advertising offerings, and, on the other hand, the data also serves internal security measures.

How long and where is the data stored?

If X collects data from other websites, this data is deleted, aggregated, or otherwise anonymized after a maximum of 30 days. X’s servers are located in various data centers in the United States. Accordingly, it can be assumed that the collected data is gathered and stored in the United States. Based on our research, we were unable to determine conclusively whether X also has its own servers in Europe. In principle, X may store the collected data until it is no longer useful to the company, until you delete the data, or until a statutory retention period expires.

How can I delete my data or prevent it from being stored?

X repeatedly emphasizes in its privacy policy that it does not store data from visits to external websites if you or your browser are located in the European Economic Area or Switzerland . However, if you interact directly with X, X will of course also store data about you.

If you have an X account, you can manage your data by clicking “More” under the “Profile” button. Then click “Settings and Privacy.” Here, you can customize your data processing settings.

If you do not have an X account, you can go to twitter.com and then click “Personalization.” Under “Personalization and Data,” you can manage the data collected about you.

As mentioned above, most data is stored via cookies, which you can manage, disable, or delete in your browser. Please note that you can only “manage” cookies in the browser you’ve selected. This means that if you use a different browser in the future, you’ll need to manage your cookies there again according to your preferences. Under the “Cookies” section, you’ll find links to the relevant guides for the most popular browsers.

You can also configure your browser to notify you about each individual cookie. This allows you to decide on a case-by-case basis whether to accept a cookie or not.

X also uses the data for personalized advertising both on and off X. In the settings, under “Personalization and Data,” you can disable personalized advertising. If you use X in a browser, you can disable personalized advertising at https://optout. aboutads.info/?c=2&lang=EN.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have provided your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and to review the privacy policy or cookie guidelines of the respective service provider.

X also processes your data in the U.S., among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.

As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, in the United States) or for data transfers to there, X uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, X commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/ 2021/914/oj?locale=de

For more information on the standard contractual clauses at X, please visit https://gdpr.twitter.com/en/controller-to-controller-transfers.html.

We hope we have provided you with a basic overview of data processing by X. We do not receive any data from X and bear no responsibility for what X does with your data. If you have any further questions on this topic, we recommend reviewing X’s privacy policy at https://twitter.com/de/privacy.

Blogs and Publications Introduction

Blogs and Publications Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Presenting and optimizing our services, as well as facilitating communication among website visitors, implementing security measures, and administrative purposes

📓 Data Processed: Data such as contact information, IP address, and published content.

You can find more details in the sections on the tools used.

📅 Retention Period: Depends on the tools used

⚖️ Legal Bases: Art. 6( 1(a) of the GDPR (consent), Art. 6(1)(f) of the GDPR (legitimate interests), Art. 6(1)(b) of the GDPR (contract)

What are blogs and publication platforms?

We use blogs and other communication tools on our website, that allow us to communicate with you and you to communicate with us. In doing so, we may also store and process data from you. This may be necessary so that we can display content appropriately, ensure communication works properly, and enhance security. In our privacy policy, we generally explain what data from you may be processed. Specific details regarding data processing always depend on the tools and features used. You can find detailed information about data processing in the privacy policies of the individual providers.

Why do we use blogs and publishing platforms?

Our primary goal with our website is to offer you interesting and engaging content, and at the same time, your opinions and contributions are important to us. That’s why we want to foster a meaningful interactive exchange between us and you. With various blogs and publishing options, we can achieve exactly that. For example, you can write comments on our content, respond to other comments, or, in some cases, write posts yourself.

What data is processed?

Exactly what data is processed always depends on the communication features we use. Very often, your IP address, username, and the published content are stored. This is done primarily to ensure security, prevent spam, and take action against illegal content. Cookies may also be used for data storage. These are small text files that are stored in your browser along with information. You can find more details about the data collected and stored in our individual sections and in the privacy policy of the respective provider.

Duration of Data Processing

We provide further information about the duration of data processing below, provided we have further information on this. For example, post and comment features store data until you revoke your consent to data storage. In general, personal data is stored only for as long as is absolutely necessary to provide our services.

Right to Object

You also have the right and the option at any time to revoke your consent to the use of cookies or third-party communication tools. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.

Since cookies may also be used by publishing platforms may be used, we also recommend that you review our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

We use these communication tools primarily based on our legitimate interests (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers, business partners, and visitors. To the extent that the use serves the fulfillment of contractual relationships or the initiation thereof, the legal basis is also Art. 6( 1(1)(b) GDPR.

Certain processing activities, in particular the use of cookies as well as the use of comment or messaging features, require your consent. If and to the extent that you have consented to the processing and storage of your data through integrated publishing media, this consent serves as the legal basis for data processing (Article 6(1)(a) of the GDPR). Most of the communication features we use set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

Information on specific tools—if available—can be found in the following sections.

Blog Posts and Comment Features Privacy Policy

There are various online communication tools that we may use on our website. For example, we use blog posts and comment features. This gives you the opportunity to comment on content or write posts. If you use this feature, your IP address may be stored for security reasons. This helps us protect against unlawful content such as insults, unauthorized advertising, or prohibited political propaganda. To determine whether comments are spam, we may also store and process user data based on our legitimate interest. If we launch a survey, we also store your IP address for the duration of the survey to ensure that all participants vote only once. Cookies may also be used for storage purposes. All data we store from you (such as content or personal information) will remain stored until you object.

Blogger.com Privacy Policy

We also use the hosting and blogging platform Blogger.com on our website. The service provider is the U.S. company Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

Google processes your data, among other places, in the U.S. Google is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https:/ /commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/ oj?locale=de

You can learn more about the data processed through the use of Google in the Privacy Policy at https://policies.google.com/privacy?hl=de.

WordPress Emojis Privacy Policy

We also use so-called emojis and smileys on our blog. We probably don’t need to explain exactly what emojis are here. You’re familiar with these smiling, angry, or sad faces. They are graphical elements or files that we make available and that are loaded from another server. The service provider for retrieving WordPress emojis and smileys is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. This third-party provider stores your IP address in order to transmit the emoji files to your browser.

Automattic processes your data, including in the U.S. Automattic is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called Standard Contractual Clauses (= Art. 46. paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU -US Data Privacy Framework and the Standard Contractual Clauses, Automattic commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex. europa.eu/eli/dec_impl/2021/914/oj?locale=de.

The Data Processing Agreements, which correspond to the Standard Contractual Clauses, can be found at https://wordpress.com/support/data-processing-agreements/.

You can learn more about the data processed through the use of WordPress emojis in the Privacy Policy at https://automattic.com/privacy/.

Online Marketing Introduction

Online Marketing Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Analysis of visitor information to optimize the website.

📓 Data Processed: Access statistics, which include data such as access locations, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or e- mail addresses may also be processed. You can find more details on this for each online marketing tool used.

📅 Retention period: Depends on the online marketing tools used

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Online marketing?

Online marketing refers to all measures carried out online to achieve marketing goals such as increasing brand awareness or closing a business deal. Furthermore, our online marketing measures aim to draw people’s attention to our website. In order to showcase our offerings to many interested people, we engage in online marketing. This typically involves online advertising, content marketing, or search engine optimization. To ensure we can use online marketing efficiently and effectively, we also store and process personal data. On the one hand, this data helps us show our content only to those who are genuinely interested in it; on the other hand, it allows us to measure the advertising success of our online marketing efforts.

Why do we use online marketing tools?

We want to show our website to everyone who is interested in what we have to offer. We realize that this isn’t possible without taking deliberate action. That’s why we do online marketing. There are various tools that make it easier for us to carry out our online marketing efforts and also provide suggestions for improvement based on data. This allows us to tailor our campaigns more precisely to our target audience. Ultimately, the purpose of these online marketing tools is to optimize our offerings.

What data is processed?

To ensure our online marketing is effective and to measure the success of our efforts, user profiles are created and data is stored, for example, in cookies (which are small text files). With the help of this data, we can not only display ads in the traditional sense but also present our content on our website in a way that best suits your preferences. There are various third-party tools that offer these functions and, accordingly, collect and store data from you. For example, the cookies mentioned store information such as which pages you visited on our website, how long you viewed those pages, which links or buttons you clicked, or which website referred you to us. Additionally, technical information may also be stored—such as your IP address, the browser you’re using, the device you use to visit our website, and the time you accessed our website and when you left it. If you have consented to allow us to determine your location, we may also store and process this information.

Your IP address is stored in pseudonymized form (i.e., truncated). Unique data that directly identifies you as an individual—such as your name, address, or email address— are also stored only in pseudonymized form as part of our advertising and online marketing processes. This means we cannot identify you as an individual; instead, we only have the pseudonymized information stored in the user profiles.

Under certain circumstances, cookies may also be deployed, analyzed, and used for advertising purposes on other websites that utilize the same advertising tools. The data may then also be stored on the servers of the advertising tool providers.

In exceptional cases, unique data (names, email addresses, etc.) may also be stored in user profiles. This occurs, for example, if you are a member of a social media platform that we use for our online marketing activities and the network links previously collected data to your user profile.

For all advertising tools we use that store your data on their servers, we always receive only aggregated information and never data that identifies you as an individual. The data merely shows how effective specific advertising campaigns were. For example, we see which campaigns prompted you or other users to visit our website and purchase a service or product there. Based on these analyses, we can improve our advertising offerings in the future and tailor them even more precisely to the needs and preferences of interested individuals.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details available. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. You can usually find detailed information about the specific cookies used by each provider in their respective privacy policies.

Right to Object

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. The lawfulness of the processing up until the time of revocation remains unaffected.

Since online marketing tools typically use cookies, we also recommend that you review our general privacy policy regarding cookies. To find out exactly which of your data exactly is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

If you have consented to the use of third-party providers, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by online marketing tools.

We also have a legitimate interest in measuring online marketing measures in an anonymized form in order to optimize our offerings and initiatives using the data obtained. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use these tools if you have given your consent.

Information on specific online marketing tools—where available—can be found in the following sections.

Audio & Video Introduction

Audio & Video Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Optimization of our services

📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.

You can find more details on this below in the relevant privacy policy sections.

📅 Retention Period: Data is generally stored for as long as it is necessary for the purpose of the service

⚖️ Legal Basis: Article 6(1)(a) of the GDPR (Consent) , Art. 6(1)(f) GDPR (Legitimate Interests)

What are audio and video elements?

We have embedded audio and video elements on our website so that you can, for example, watch videos or listen to music/ podcasts directly through our website. The content is provided by service providers. All content is therefore also retrieved from the providers’ respective servers.

These are embedded functional elements from platforms such as YouTube, Vimeo, or Spotify. Use of these platforms is generally free of charge, but paid content may also be published. With the help of these embedded elements, you can listen to or watch the respective content via our website.

When you use audio or video elements on our website, your personal data may also be transmitted to, processed by, and stored by the service providers.

Why do we use audio and video elements on our website?

Of course, we want to provide you with the best possible experience on our website. And we’re aware that content is no longer conveyed solely through text and static images. Instead of simply providing you with a link to a video, we offer audio and video formats directly on our website that are entertaining or informative—and ideally, both. This enhances our service and makes it easier for you to access interesting content. Thus, in addition to our text and images, we also offer video and/or audio content.

What data is stored through audio & video elements?

When you visit a page on our website that contains, for example, an embedded video, your server connects to the service provider’s server. In the process, data about you is also transmitted to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system, and other general information about your device. Furthermore, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which buttons you clicked, or which website you used to access the service. All of this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymized data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.

Duration of Data Processing

You can find out exactly how long the data is stored on the third-party providers’ servers either further down in the privacy text for the respective tool or in the provider’s privacy policy. As a general rule, personal data is processed only for as long as is strictly necessary to provide our services or products. This generally applies to third-party providers as well. In most cases, you can assume that certain data will be stored on the third-party providers’ servers for several years. Data stored in cookies, in particular, can be retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years .

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. The lawfulness of the processing up until the time of revocation remains unaffected affected.

Since cookies are usually also used by the embedded audio and video features on our site, you should also read our general privacy policy regarding cookies. You can find more detailed information about how your data is handled and stored in the privacy policies of the respective third-party providers.

Legal Basis

If you have consented to the processing and stored, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed based on our legitimate interest (Art. 6(1)(f) GDPR) in ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded audio and video elements to the extent that you have given your consent.

YouTube Privacy Policy

YouTube Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Optimizing our services

📓 Data Processed: Data such as contact information, user behavior data, information about your device, and your IP address may be stored.

You can find more details on this further down in this privacy policy.

📅 Retention Period: Data is generally stored for as long as it is necessary for the purpose of the service

⚖️ Legal Basis: Art. 6(1)(a) GDPR (Consent) , Art. 6(1)(f) GDPR (Legitimate Interests)

What is YouTube?

We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video platform that has been a subsidiary of Google since 2006. The video platform is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. In the process, (depending on your settings) various data is transmitted. Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing within Europe.

Below, we’ll explain in more detail what data is processed, why we’ve embedded YouTube videos, and how you can manage or delete your data.

On YouTube, users can watch, rate, comment on, and upload videos for free. Over the past few years, YouTube has become one of the most important social media channels worldwide. To enable us to display videos on our website, YouTube provides a code snippet that we have embedded on our site.

Why do we use YouTube videos on our website?

YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our website. And, of course, interesting videos are a must. With our embedded videos, we provide you with additional helpful content alongside our text and images. In addition, our website is more easily found on the Google search engine. Even though we run ads through Google Ads, Google—thanks to the data it collects—can show these ads only to people who are genuinely interested in our offerings.

What data does YouTube store?

As soon as you visit one of our pages that has a YouTube video, YouTube sets at least one cookie that stores your IP address and our URL. If you’re logged into your YouTube account, YouTube can usually associate your interactions on our website with your profile using cookies. This includes data such as session duration, bounce rate, approximate location, and technical information like browser type, screen resolution, or your internet service provider. Additional data may include contact information, any ratings , sharing content via social media, or adding it to your favorites on YouTube.

If you are not signed in to a Google or YouTube account, Google stores data using a unique identifier linked to your device, browser, or app. This ensures, for example, that your preferred language setting is retained. However, much of your interaction data cannot be stored because fewer cookies are set.

In the following list, we show cookies that were set in a browser test. We show, on the one hand, cookies that are set without a signed-in YouTube account. On the other hand, we show cookies that are set with a signed-in account. The list does not claim to be exhaustive, because user data always depends on interactions on YouTube.

Name: YSC

Value: b9-CV6ojI5Y312860492-1

Purpose: This cookie records a unique ID to store statistics about the video you watched.

Expiration date: at the end of the session

Name: PREF

Value: f1=50000000

Purpose: This cookie also records your unique ID. Google uses PREF to collect statistics on how you use YouTube videos on our website.

Expiration date: after 8 months

Name: GPS

Value: 1

Purpose: This cookie stores your unique ID on mobile devices to track your GPS location.

Expiration date: after 30 minutes

Name: VISITOR_INFO1_LIVE

Value: 95Chz8bagyU

Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).

Expiration date: after 8 months

Additional cookies that are set when you are logged in to your YouTube account:

Name: APISID

Value: zILlvClZSkqGsSwI/AU1aZI6HY7312860492-

Purpose: This cookie is used to create a profile based on your interests. The data is used for personalized advertisements.

Expiration date: after 2 years

Name: CONSENT

Value: YES+AT.de+20150628-20-0

Purpose: This cookie stores the status of a user’s consent to use various Google services. CONSENT also serves security purposes to verify users and protect user data from unauthorized attacks.

Expiration date: after 19 years

Name: HSID

Value: AcRwpgUik9Dveht0I

Purpose: This cookie is used to create a profile of your interests. This data helps display personalized advertising.

Expiration date: after 2 years

Name: LOGIN_INFO

Value: AFmmF2swRQIhALl6aL…

Purpose: This cookie stores information about your login credentials.

Expiration date: after 2 years

Name: SAPISID

Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM

Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.

Expiration date: after 2 years

Name: SID

Value: oQfNKjAsI312860492-

Purpose: This cookie stores your Google account ID and the time of your last login in a digitally signed and encrypted format.

Expiration date: after 2 years

Name: SIDCC

Value: AN0-TYuqub2JOcDTyL

Purpose: This cookie stores information about how you use the website and what ads you may have seen before visiting our site.

Expiration date: after 3 months

How long and where is the data stored?

The data that YouTube receives from you and processes is stored on Google’s servers. Most of these servers are located in the United States. At https://www.google. com/about/datacenters/locations/?hl=de you can see exactly where Google’s data centers are located. Your data is distributed across the servers. This makes the data more accessible and better protected against tampering.

Google stores the collected data for varying lengths of time. You can delete some data at any time, other data is automatically deleted after a limited time, and still other data is stored by Google for a longer period. Some data (such as items from “My Activity,” photos, documents, or products) stored in your Google Account remains there until you delete it. Even if you’re not signed in to a Google Account, you can delete some data associated with your device, browser, or app.

How can I delete my data or prevent it from being stored?

Generally, you can manually delete data in your Google Account. With the automatic deletion feature for location and activity data introduced in 2019, information is stored for either 3 or 18 months—depending on your choice—and then deleted.

Whether or not you have a Google account or not, you can configure your browser to delete or disable cookies from Google. Depending on which browser you use, this works in different ways. Under the “Cookies” section, you’ll find links to the instructions for the most popular browsers.

If you generally don’t want any cookies, you can set your browser to always notify you when a cookie is about to be set. This way, decide for each individual cookie whether to allow it or not.

Legal Basis

If you have consented to the processing and storage of your data through embedded YouTube elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded YouTube elements to the extent that you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

YouTube also processes your data in the U.S., among other places. YouTube and Google are active participants in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR) . Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to to comply with European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/ oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

Since YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to learn more about how your data is handled, we recommend reviewing the privacy policy at https://policies.google.com/privacy? hl=de.

YouTube Subscribe Button Privacy Policy

We have integrated the YouTube Subscribe button on our website. You can usually recognize the button by the classic YouTube logo. The logo displays the words “Subscribe” or “YouTube” in white text on a red background, with the white “Play” icon to the left of it. However, the button may also appear in a different design.

Our YouTube channel regularly offers you funny, interesting, or exciting videos. With the embedded “Subscribe” button, you can subscribe to our channel directly from our website without having to visit the YouTube website separately. We want to make it as easy as possible for you to access our extensive content. Please note that this allows YouTube to store and process your data.

When you see an embedded Subscribe button on our site, YouTube—according to Google—sets at least one cookie. This cookie stores your IP address and our URL. YouTube can also obtain information about your browser, your approximate location, and your default language. During our test, the following four cookies were set without being logged in to YouTube:

Name: YSC

Value: b9-CV6ojI5312860492Y

Purpose: This cookie records a unique ID to store statistics about the video you watched.

Expiration date: at the end of the session

Name: PREF

Value: f1=50000000

Purpose: This cookie also records your unique ID. Google uses PREF to collect statistics on how you use YouTube videos on our website.

Expiration date: after 8 months

Name: GPS

Value: 1

Purpose: This cookie records your unique ID on mobile devices to track your GPS location.

Expiration date: after 30 minutes

Name: VISITOR_INFO1_LIVE

Value: 31286049295Chz8bagyU

Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).

Expiration date: after 8 months

Note: These cookies were set following a test and are not intended to be exhaustive.

If you are logged into your YouTube account, YouTube can use cookies to store many of your actions and interactions on our website and associate them with your YouTube account. For example, YouTube receives information such as how long you browse our site, what type of browser you use, what screen resolution you prefer, or what actions you perform.

YouTube uses this data both to improve its own services and offerings and to provide analytics and statistics for advertisers (who use Google Ads).

Web Design Introduction

Web Design Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Improving the user experience

📓 Data Processed: The specific data processed depends heavily on the services used. Typically, this includes IP address, technical data, language settings, browser version, screen resolution, and browser name. You can find more details on this in the descriptions of the respective web design tools used.

📅 Retention Period: Depends on the tools used

⚖️ Legal Basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is web design?

We use various tools on our website to support our web design. Contrary to popular belief, web design is not just about making our website look attractive; it’s also about functionality and performance. But of course, creating the right visual appearance for a website is also one of the main goals of professional web design. Web design is a subset of media design and deals with the visual, structural, and functional design of a website. The goal of web design is to enhance your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience encompasses all the impressions and experiences a website visitor has while on a website. A key aspect of user experience is usability. This refers to how user-friendly a website is. The primary focus here is on ensuring that content, subpages, or products are clearly structured so that you can find what you’re looking for quickly and easily. To provide you with the best possible experience on our website, we also use third-party web design tools. In this privacy policy, the category “web design” therefore includes all services that enhance the design of our website. These may include, for example, fonts, various plugins, or other integrated web design features.

Why do we use web design tools?

How you take in information on a website depends heavily on the website’s structure, functionality, and visual appeal. That’s why a high-quality, professional web design has become increasingly important to us as well. We’re constantly working to improve our website and view this as an added service for you as a visitor. Furthermore, an attractive and functional website also offers economic benefits for us. After all, you’ll only visit us and take advantage of our offerings if you feel completely at ease.

What data is stored by web design tools?

When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data is involved depends, of course, heavily on the tools used. Below, you can see exactly which tools we use for our website. For more detailed information about data processing, we also recommend that you read the respective privacy policies of the tools we use. There, you’ll usually find out what data is processed, whether cookies are used, and how long the data is retained. For example, fonts such as Google Fonts automatically transmit information such as language settings, IP address, browser version, browser screen resolution, and browser name is automatically transmitted to Google’s servers.

Duration of Data Processing

How long data is processed varies greatly and depends on the web design . If cookies are used, for example, the retention period can range from just one minute to several years. Please educate yourself on this matter. To that end, we recommend both our general section on cookies and the privacy policies of the tools in use. There you’ll typically find out exactly which cookies are used, and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. In general, data is only retained for as long as necessary to provide the service. Data may also be stored for longer periods if required by law.

Right to Object

You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or via other opt-out features. You can also prevent data collection via cookies by managing cookies in your browser, disabling or deleting them. However, some data—particularly related to web design elements (most commonly fonts)—cannot be deleted quite so easily. This is the case when data is automatically collected directly upon visiting a page and transmitted to a third-party provider (such as Google). In such cases, please contact the support team of the respective provider. For Google, you can reach support at https:/ /support.google.com/?hl=de.

Legal Basis

If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur when data is collected by web design tools . We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use web design tools to the extent that you have given your consent. We would like to emphasize this point once again here.

Information on specific web design tools—where available—can be found in the following sections.

Adobe Fonts Privacy Policy

We use Adobe Fonts, a web font hosting service, on our website. The service provider is the U.S. company Adobe Inc. For the European region, the Irish company Adobe Systems Software Ireland Companies, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland.

Adobe processes your data, among other places, in the U.S. Adobe is an active participant in the EU-U.S. Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the U.S. You can find more information on this at https://commission.europa.eu/ document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Adobe uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR) . Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the U.S.) and stored there. Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Adobe commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more information on Adobe’s Standard Contractual Clauses, visit https://www.adobe.com/at/privacy/eudatatransfers.html.

To learn more about the data processed through the use of Adobe Fonts, please see the Privacy Policy at https://www .adobe.com/at/privacy.html

.

Font Awesome Privacy Policy

Font Awesome Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: To optimize our services

📓 Data Processed: Such as IP address and which icon files are loaded

You can find more details below in this privacy policy.

📅 Retention period: Files in an identifiable form are stored for a few weeks

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Font Awesome?

We use Font Awesome on our website, provided by the American company Fonticons (307 S. Main St., Suite 202, Bentonville, AR 72712, USA). When you visit one of our webpages, the Font Awesome web font (specifically icons) is loaded via the Font Awesome Content Delivery Network (CDN). This ensures that text, fonts, and icons are displayed correctly on every device. In this privacy policy, we discuss data storage and data processing by this service in more detail.

Icons are playing an increasingly important role on websites. Font Awesome is a web that was developed specifically for web designers and web developers. With Font Awesome, icons can be scaled and colored as desired using the CSS stylesheet language. They thus replace old image-based icons. Font Awesome CDN is the easiest way to load the icons or fonts onto your website. To do this, we simply had to embed a single line of code into our website.

Why do we use Font Awesome on our website?

Font Awesome allows us to present content on our website more effectively. This helps you navigate our website more easily and understand the content more quickly. With these icons, you can sometimes even replace entire words and save space. This is especially handy when we optimize content specifically for smartphones. These icons are inserted as HTML code rather than as images. This allows us to style the icons with CSS exactly as we want. At the same time, Font Awesome also improves our page load speed because they are HTML elements rather than icon images. All these benefits help us make the website even clearer, fresher, and faster for you.

What data is stored by Font Awesome?

The Font Awesome Content Delivery Network (CDN) is used to load icons and symbols. CDNs are networks of servers distributed worldwide that make it possible to quickly load files from a nearby location. This means that as soon as you visit one of our pages, the corresponding icons are provided by Font Awesome.

In order for the web fonts to load, your browser must establish a connection to the servers of Fonticons, Inc. During this process, your IP address is detected. Font Awesome also collects data on which icon files are downloaded and when. Additionally, technical data such as your browser version, screen resolution, or the time the page was accessed is transmitted.

This data is collected and stored for the following reasons:

  • to optimize content delivery networks
  • to detect and fix technical errors
  • to protect CDNs from misuse and attacks
  • to bill Font Awesome Pro customers
  • to determine the popularity of icons
  • to identify the computer and software you are using

If your browser does not support web fonts, a standard font from your PC will be used. To the best of our current knowledge, no cookies are set. We are in contact with Font Awesome’s data protection department and will let you know as soon as we learn more.

How long and where is the data stored?

Font Awesome stores data regarding the use of the Content Delivery Network on servers, including those in the United States of America. However, the CDN servers are located worldwide and store user data based on your location. The data is generally stored in an identifiable form for only a few weeks. Aggregated statistics on CDN usage may be stored for longer periods. This data does not contain any personally identifiable information.

How can I delete my data or prevent it from being stored?

To the best of our current knowledge, Font Awesome does not store any personal data via the Content Delivery Networks. If you do not want data regarding the icons you use to be stored, you unfortunately cannot visit our website. If your browser does not support web fonts, no data will be transmitted or stored. In this case, your computer’s default font will simply be used.

Legal Basis

If you have consented to the use of Font Awesome, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by Font Awesome.

We also have a legitimate interest in using Font Awesome to optimize our online service. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Font Awesome to the extent that you have given your consent.

Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. Data processing is primarily carried out by Font Awesome. This may result in data being processed and stored without being anonymized. Furthermore, U.S. government authorities may, in some cases, gain access to specific data. It is also possible that this data may be linked to data from other Font Awesome services where you have a user account.

If you would like to learn more about Font Awesome and its handling of data, we recommend reviewing the privacy policy at https://fontawesome. com/privacy and the help page at https://fontawesome.com/support.

Google Fonts Privacy Policy

Google Fonts Privacy Policy Summary 👥 Data Subjects: Website visitors

🤝 Purpose: Optimization of our services

📓 Data Processed: Data such as IP address and CSS and font requests

You can find more details on this further down in this privacy policy.

📅 Retention period: Font files are stored by Google for one year

⚖️ Legal basis: Art. 6(1)(a) a GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are Google Fonts?

We use Google Fonts on our website. These are the “Google fonts” provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

You do not need to register or provide a password to use Google fonts, you do not need to sign in or provide a password. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts. googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google while using Google Fonts. Google tracks the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We’ll take a closer look at exactly how this data is stored later.

Google Fonts (formerly Google Web Fonts) is a directory of over 800 fonts that Google makes available to its users for free.

Many of these fonts are released under the SIL Open Font License, while others are released under the Apache License . Both are free software licenses.

Why do we use Google Fonts on our website?

With Google Fonts, we can use fonts on our own website without having to upload them to our own server. Google Fonts is an important component in maintaining the high quality of our website. All Google fonts are automatically optimized for the web, which saves data usage and is a major advantage, especially for use on mobile devices. When you visit our site, the small file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Differences in rendering systems across various browsers, operating systems, and mobile devices can lead to errors. Such such errors can sometimes cause text or entire web pages to appear distorted. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can present our entire online service as attractively and consistently as possible.

What data does Google store?

When you visit our website, the fonts are loaded via a Google server. This external request transmits data to Google’s servers. This is how Google recognizes that you—or rather, your IP address—are visiting our website. The Google Fonts API was developed to limit the use, storage, and collection of end-user data to what is necessary for the proper delivery of fonts. By the way, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.

Google Fonts securely stores CSS and font requests on Google’s servers, ensuring they are protected. Based on the collected usage statistics, Google can determine how well the individual fonts are received. Google publishes the results on internal analytics platforms, such as Google Analytics. In addition, Google also uses data from its own web crawler to determine which websites use Google Fonts. This data is published in the Google Fonts BigQuery database. Business owners and developers use the Google web service BigQuery to analyze and process large volumes of data.

It’s important to note, , however, that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers. It is not clear whether this data is also stored, nor does Google communicate this explicitly.

How long and where is the data stored?

Google stores requests for CSS assets on its servers—which are primarily located outside the EU—for one day. This allows us to use the fonts with the help of a Google -stylesheet. A stylesheet is a formatting template that allows you to quickly and easily change, for example, the design or font of a website.

The font files are stored by Google for one year. Google’s goal in doing so is to generally improve website loading times. When millions of websites reference the same fonts, they are cached after the first visit and immediately reappear on all other websites visited later. Sometimes Google updates font files to reduce file size, increase language coverage, and improve design.

How can I delete my data or prevent it from being stored?

The data that Google stores for one day or one year cannot simply be deleted. The data is automatically transmitted to Google when you visit a page. To delete this data early, you must contact Google Support at https: //support.google.com/?hl=de&tid=312860492. In this case, the only way to prevent data storage is to not visit our site.

Unlike other web fonts, Google grants us unrestricted access to all fonts. This means we have unlimited access to a vast array of fonts, allowing us to get the most out of our website. For more information about Google Fonts and other questions can be found at https:/ /developers.google.com/fonts/faq?tid=312860492. Although Google addresses data protection-related issues there, the page does not contain truly detailed information about data storage. It is relatively difficult to obtain truly precise information from Google regarding stored data.

Legal Basis

If you have consented to the use of Google Fonts, this consent serves as the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by Google Fonts.

We also have a legitimate interest in using Google Fonts to optimize our online service. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Fonts to the extent that you have given your consent.

Google also processes your data in the United States, among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. You can find more information on this at https://commission.europa.eu/document/fa09cbad -dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (= Art. 46, paras. 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the U.S.). Through the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the U.S. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/ de/adsprocessorterms/.

You can also read about what data Google generally collects and how it is used at https://www.google.com/intl/de/policies/privacy/.

Google Fonts Local Privacy Policy

On our website, we use Google Fonts provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible. We have integrated the Google fonts locally, i.e., on our web server—not on Google’s servers. As a result, there is no connection to Google’s servers and, therefore, no data transmission or storage.

What Are Google Fonts?

Google Fonts used to be called Google Web Fonts. It is an interactive directory with over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, to prevent any data transmission to Google servers, we have downloaded the fonts to our own server. This ensures we comply with data protection regulations and do not forward any data to Google Fonts.

All texts are protected by copyright.

Source: Created with the Privacy Policy Generator by AdSimple