We have drawn up this Privacy Policy (Version 11.11.2025-113077832) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter ‘data’) we, as the data controller – and the data processors commissioned by us (e.g. providers) – process, will process in future, and what legal options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, aims to describe the most important points as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We therefore inform you in clear and simple language that, within the scope of our business activities, we only process personal data only where there is a corresponding legal basis. This is certainly not possible if one provides explanations that are as brief, unclear and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information here that you were not yet aware of.
If you still have any questions, please contact the data controller listed below or in the legal notice, follow the links provided, and consult further information on third-party websites. You will, of course, also find our contact details in the legal notice.
This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (data processors). By personal data, we mean information within the meaning of Article 4(1) of the GDPR, such as a person’s name, email address and postal address of a person. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:
In short: This privacy policy applies to all areas within the company where personal data is processed in a structured manner via the channels mentioned. Should we enter into legal relationships with you outside these channels, we will inform you separately where necessary.
In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, which enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/ DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Other conditions, such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests do not generally apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate place.
In addition to the EU Regulation, national laws also apply:
Where further regional or national laws apply, we will inform you of this in the following sections.
Should you have any questions regarding data protection or the processing of personal data, you will find the contact details of the data controller below, in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR):
Mag. Michael Kalivoda
Schwarzhorngasse 1/2
1050 Vienna
Email: contact@michaelkalivoda.net
Telephone: +436643961280
Legal notice: https://www.michaelkalivoda.net/impressum/
It is a general principle for us that we only store personal data for as long as is strictly necessary for the provision of our services and products. This means we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally obliged to retain certain data even after the original purpose has ceased to apply, for example for accounting purposes.
Should you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.
We provide further information below regarding the specific duration of the respective data processing, where we have further details.
In accordance with Articles 13 and 14 of the GDPR, we inform you of the following rights to which you are entitled to ensure fair and transparent data processing:
In short: You have rights – do not hesitate to contact the controller listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you may lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Head: Dr Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Telephone no.: +43 1 52 152-0
Email address: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
We only transfer or process data to countries outside the scope of the GDPR (third countries) if you consent to such processing or if there is another legal basis for doing so. This applies in particular where processing is required by law or necessary to fulfil a contractual relationship, and in any case only to the extent that this is generally permitted. In most cases, your consent is the primary reason why we process data in third countries. The processing of personal data in third countries such as the USA, where many software providers offer services and have their server locations, may mean personal data being processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists only if a US company processing personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. You can find more information on this at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data not being processed and stored anonymously. Furthermore, US government authorities may, in some cases, access individual data. In addition, collected data may be linked to data from other services provided by the same provider, provided you have a corresponding user account. Where possible, we endeavour to use server locations within the EU, provided this is offered.
We provide more detailed information on data transfers to third countries, where applicable, in the relevant sections of this privacy policy.
To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as possible, within the limits of our capabilities, for third parties to deduce personal information from our data.
Article 25 of the GDPR refers here to “data protection by design and by default” and means that security must always be considered in relation to both software (e.g. forms) and hardware (e.g. access to the server room), and that appropriate measures must be put in place. Where necessary, we will discuss specific measures in more detail below.
TLS, encryption and HTTPS sound very technical, and indeed they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the internet in a way that is secure against eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secured – nobody can “ eavesdrop”.
We have thus introduced an additional layer of security and comply with data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission security by the small padlock symbol in the top left-hand corner of the browser, to the left of the web address (e.g. examplepage. de) and the use of the https scheme (instead of http) as part of our web address.
If you would like to know more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.
Communication Summary
👥 Data subjects: Anyone who communicates with us by telephone, email or online form
📓 Data processed: e.g. telephone number, name, email address, form data entered. You can find more details on this under the respective contact method
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Retention period: Duration of the business transaction and as required by law
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)( b GDPR (Contract), Art. 6(1)(f) GDPR (Legitimate Interests)
If you contact us and communicate via telephone, email or online form, personal data may be processed.
The data is processed for the handling and processing of your enquiry and the associated business transaction. The data is stored for as long as necessary or for as long as required by law .
The processes described above apply to anyone who contacts us via the communication channels we provide.
When you call us, the call data is stored in pseudonymised form on the relevant device and with the telecommunications provider used. In addition, data such as your name and telephone number may subsequently be sent by email and stored for the purpose of responding to your enquiry. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
If you communicate with us via email, data may be stored on the relevant device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
If you communicate with us via an online form, data will be stored on our web server and, where applicable, forwarded to one of our email addresses. The data will be deleted as soon as the business transaction has been completed and legal requirements permit.
The processing of data is based on the following legal grounds:
In this section, we would like to explain what a Data Processing Agreement is and why it is required. As the term “Data Processing Agreement” is quite a mouthful, we will often use the acronym DPA in the text below. Like most companies, we do not operate in isolation but also make use of services provided by other companies or individuals. By involving various companies or service providers, we may need to pass on personal data for processing. These partners then act as data processors, with whom we enter into a contract known as a Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be governed by the DPA.
As a company and website owner, we are responsible for all data we process from you. In addition to the controllers, there may also be so-called data processors. This includes any company or person who processes personal data on our behalf. More precisely, and according to the GDPR definition: any natural or legal person, public authority, agency or other body which processes personal data on our behalf is considered a data processor. Data processors may therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
To help you better understand the terminology, here is an overview of the three roles in the GDPR:
Data subject (you as a customer or prospective customer) → Data Controller (we as a company and the data controller) → Data Processor (service providers such as web hosts or cloud providers)
As mentioned above, we have concluded . First and foremost, this stipulates that the data processor shall process the data to be processed exclusively in accordance with the GDPR. The contract must be concluded in writing; however, in this context, an electronic contract is also considered to be ‘in writing’. The processing of personal data takes place only on the basis of the contract. The contract must contain the following:
Furthermore, the contract sets out all the obligations of the data processor. The most important obligations are:
You can see what such a DPA looks like in practice, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A sample contract is presented here.
Cookies Summary
👥 Data subjects: Website visitors
🤝 Purpose: Depends on the specific cookie. Further details can be found below or from the software provider that sets the cookie.
📓 Data processed: Depends on the specific cookie used. Further details can be found below or from the software provider that sets the cookie.
📅 Storage period: Depends on the specific cookie; may vary from hours to years
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate interests)
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. To be more precise, they are HTTP cookies, as there are also other types of cookies for different applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, which is essentially the ‘brain’ of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must be specified.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following diagram illustrates a possible interaction between a web browser such as, Chrome, and the web server. In this process, the web browser requests a website and receives a cookie from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, whilst third-party cookies are created by partner websites (e. Google Analytics). Each cookie must be assessed individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programmes and do not contain viruses, Trojans or other ‘malware’. Cookies cannot access information on your PC either.
Here is an example of what cookie data might look like:
Name: _ga
Value: GA1.2.1326744211.152113077832-9
Purpose: To distinguish between website visitors
Expiry date: after 2 years
A browser should be able to support the following minimum sizes:
The specific cookies we use depend on the services employed and are explained in the following sections of the privacy policy. At this point, we would like to briefly outline the different types of HTTP cookies.
There are four types of cookies:
Essential cookies
These cookies are necessary to ensure the website’s basic functions. For example, these cookies are needed when a user adds a product to their basket, then continues browsing other pages and only proceeds to checkout later. These cookies ensure that the shopping basket is not cleared, even if the user closes their browser window.
Performance cookies
These cookies collect information about user behaviour and whether the user receives any error messages. They are also used to measure the website’s loading time and performance across different browsers.
Functional cookies
These cookies improve user-friendliness. For example, they store locations entered, font sizes or form data.
Advertising cookies
These cookies are also known as targeting cookies. They are used to deliver personalised advertising to the user. This can be very useful, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these types of cookies you wish to allow. And, of course, this decision is also stored in a cookie.
If you would like to know more about cookies and are not put off by technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments entitled “HTTP State Management Mechanism”.
The purpose ultimately depends on the specific cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalise about what data is stored in cookies, but we will inform you about the data processed or stored in the context of the following privacy policy.
The storage period depends on the specific cookie and is specified in more detail below. Some cookies are deleted after less than an hour, whilst others may remain stored on a computer for several years.
You also have control over the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below ). Furthermore, cookies based on consent will be deleted at the latest upon withdrawal of your consent, although the lawfulness of their storage up to that point remains unaffected.
You decide for yourself how and whether you wish to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you wish to find out which cookies have been stored in your browser, or if you settings, you can find this information in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies, to remove data that websites have stored on your computer
Internet Explorer: Deleting and managing cookies
Microsoft Edge: Deleting and managing cookies
If you do not wish to have any cookies at all, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It is best to search for instructions on Google using the search term “delete cookies Chrome” or “disable cookies Chrome” if you are using the Chrome browser.
The so-called “Cookie Directive” has been in place since 2009. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). However, reactions to these guidelines still vary greatly across EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive has not been transposed into national law. Instead, the Directive has largely been implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even where no consent has been given, there are legitimate interests (Article 6(1)(f) GDPR), which are of an economic nature in most cases. We wish to provide visitors to the website with a pleasant user experience, and certain cookies are often strictly necessary for this purpose.
Where cookies that are not strictly necessary are used, this is done only with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.
The following sections provide more detailed information on the use of cookies, where the software employed utilises cookies.
Web Hosting Summary
👥 Data subjects: Website visitors
🤝 Purpose: Professional hosting of the website and safeguarding its operation
📓 Data processed: IP address, time of website visit, browser used and other data. Further details can be found below or with the respective web hosting provider.
📅 Retention period: depending on the provider in question, but generally 2 weeks
⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate interests)
When you visit websites nowadays, certain information – including personal data – is automatically generated and stored, as is the case on this website. This data should be processed as sparingly as possible and only for a valid reason. By ‘website’, we mean the entirety of all web pages on a domain, i.e. everything from the home page to the very last subpage (such as this one) . By ‘domain’ we mean, for example, example.de or sampleexample.com.
If you wish to view a website on a computer, tablet or smartphone, you use a programme called a web browser. You are probably familiar with some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We refer to these simply as ‘browsers’ or ‘web browsers’.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Running a web server is a complicated and resource-intensive task, which is why it is usually handled by professional providers. These providers offer web hosting and thus ensure reliable and error-free storage of website data. That’s quite a lot of technical terms, but please bear with us – it gets even better!
When the browser on your computer (desktop, laptop, tablet or smartphone) establishes a connection and during data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a period of time to ensure proper operation.
A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the internet and the hosting provider.
The purposes of data processing are:
Even as you visit our website right now, our web server – that is, the computer on which this website is hosted – usually automatically stores data such as
As a rule, the data mentioned above is stored for two weeks and then automatically deleted. We do not pass this data on to third parties, but cannot rule out the possibility that this data may be accessed by authorities in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without your consent!
The lawfulness of the processing of personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests) , as the use of professional hosting with a provider is necessary to present the company securely and in a user-friendly manner on the internet and, where necessary, to be able to investigate attacks and claims arising therefrom.
As a rule, there is a contract between us and the hosting provider regarding data processing in accordance with Art. 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.
Website Builder Systems Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as technical usage information including browser activity, clickstream activity, session heatmaps, as well as contact details, IP address or your geographical location. Further details can be found below in this privacy policy and in the providers’ privacy policies.
📅 Retention period: depends on the provider
⚖ ️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)
We use a website builder system for our website. Website builder systems are a specific type of content management system (CMS). With a website builder system, website operators can create a website very easily and without any programming knowledge . In many cases, web hosting providers also offer website builders. By using a website builder, your personal data may also be collected, stored and processed. In this privacy notice, we provide you with general information about data processing via website builders. Further details can be found in the provider’s privacy policy.
The biggest advantage of a website builder is its ease of use. We want to offer you a clear, simple and well-organised website that we can easily operate and maintain ourselves – without external support. A website builder now offers many helpful functions that we can use even without any programming knowledge. This allows us to design our website according to our preferences and offer you an informative and enjoyable experience on our site.
Exactly what data is stored naturally depends on the website builder used. Each provider processes and collects different data from website visitors. However, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your visit to the website is usually collected. Furthermore, tracking data (e.g. browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Personal data may also be collected and stored. This usually consists of contact details such as your email address, telephone number (if you have provided it), IP address and geographical location data. You can find out exactly which data is stored in the provider’s privacy policy.
We provide further information below regarding the duration of data processing in connection with the website builder system used, provided we have further details. You can find detailed information on this in the provider’s privacy policy. Generally, we process personal data only for as long as is strictly necessary for the provision of our services and products. It may be the case that the provider stores data about you in accordance with their own policies, over which we have no control.
You always have the right to access, rectify and erase your personal data. If you have any questions, you can also contact the controllers of the website builder system used at any time. You can find contact details either in our privacy policy or on the relevant provider’s website.
You can delete, disable or manage cookies used by providers for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
We have a legitimate interest in using a website builder system to optimise our online service and present it to you in an efficient and user-friendly manner. The relevant legal basis for this is Article 6(1)(f) of the GDPR (legitimate interests). However, we only use the website builder system to the extent that you have given your consent.
Insofar as the processing of data is the operation of the website, the data will only be processed on the basis of your consent. This applies in particular to tracking activities. The legal basis in this respect is Article 6(1)(a) of the GDPR.
With this privacy policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information on this subject, you will find further details – where available – in the following section or in the provider’s privacy policy.
WordPress.com Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as technical usage information (e.g. browser activity, clickstream activity, session heatmaps), as well as contact details, IP address or your geographical location. You can find more details on this further down in this privacy policy.
📅 Retention period: This depends primarily on the type of data stored and the specific settings.
⚖ ️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
The company was founded in 2003 and, in a relatively short time, developed into one of the world’s best-known content management systems (CMS) worldwide. A CMS is software that helps us design our website and present content in an attractive and organised manner. This content may include text, audio and video.
By using WordPress, your personal data may also be collected, stored and processed. As a rule, this mainly involves technical data such as operating system, browser, screen resolution or hosting provider. However, personal data such as IP address, geographical data or contact details may also be processed.
We have many strengths, but actual programming is simply not one of our core competencies.
Nevertheless, we want a high-performance and attractive website that we can manage and maintain ourselves. With a website builder or a content management system like WordPress, this is exactly what is possible. With WordPress, we don’t need to be programming experts to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without prior technical knowledge. Should technical problems ever arise or should we have specific requirements for our website, our specialists – who are well versed in HTML, PHP, CSS and the like – are always on hand.
Thanks to WordPress’s ease of use and comprehensive features, we can design our website to our specifications and offer you a user-friendly experience.
Non-personal data includes technical usage information such as browser activity, clickstream activity, session heatmaps, and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet provider, and the date of your visit.
Personal data is also collected. This primarily consists of contact details (email address or telephone number, if you provide them), IP address or your geographical location.
WordPress may also use cookies to collect data. These often record information about your behaviour on our website. For example, they may record which subpages you particularly like to view, how long you stay on individual pages, when you leave a page (bounce rate) or even which preferences (e.g. language selection ) you have selected. Based on this data, WordPress can also better tailor its own marketing activities to your interests and user behaviour. Consequently, the next time you visit our website, it will be displayed to you as you have previously configured it.
WordPress may also use technologies such as pixel tags (web beacons) to, for example, clearly identify you as a user and potentially offer interest-based advertising.
How long the data is stored depends on various factors. In particular, it depends on the type of data stored and the specific settings of the website. In principle, WordPress deletes the data once it is no longer required for its own purposes. There are, of course, exceptions, particularly where legal obligations require the data to be retained for a longer period. Web server logs, which contain your IP address and technical data, are deleted by WordPress or Automattic after 30 days. For this period, Automattic uses the data to analyse traffic on its own websites (for example, all WordPress sites) and to resolve any potential issues. Deleted content on WordPress websites is also kept in the rubbish bin for 30 days to allow for restoration; after that, it may remain in backups and caches until these are deleted. The data is stored on Automattic’s servers in the US .
You have the right and the option to access your personal data at any time and to object to its use and processing. You may also lodge a complaint with a government supervisory authority at any time.
In your browser, you also have the option to manage cookies individually, delete or deactivate them. Please note, however, that deactivated or deleted cookies may have a negative impact on the functionality of our WordPress site. Depending on which browser you use, managing cookies works slightly differently. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
If you have consented to the use of WordPress, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by WordPress.
We also have a legitimate interest in using WordPress to optimise our online service and present it attractively to you. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use WordPress if you have given your consent.
WordPress and Automattic process your data, including in the USA. Automattic is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Automattic uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Automattic undertakes to comply with European data protection standards when processing your relevant data, even if the data is . These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
Further details on the privacy policy and what data is processed by WordPress and in what manner can be found at https://automattic.com/privacy/.
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded a Data Processing Agreement (DPA). You can read about exactly what a DPA is and, above all, what must be included in a DPA in our general section ‘Data Processing Agreement (DPA)’.
This agreement is required by law because WordPress.com processes personal data on our behalf. It clarifies that WordPress.com may only process data received from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://wordpress.com/support/ data-processing-agreements/.
Web Analytics Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimise the website.
📓 Data processed: Access statistics containing data such as access locations, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses. Further details can be found in the relevant web analytics tool.
📅 Retention period: Depends on the web analytics tool used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use software on our website to analyse the behaviour of website visitors, known as web analytics or web analysis. This involves the collection of data which the respective analytics tool provider (also known as a tracking tool) stores, manages and processes. The data is used to generate analyses of user behaviour on our website, which are then made available to us as the website operator. In addition, most tools offer various testing options. This allows us, for example, to test which offers or content are most popular with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles may also be created and the data stored in cookies.
With our website, we have a clear goal in mind: we want to provide the best online offering on the market for our industry. To achieve this goal, we aim, on the one hand, to offer the best and most interesting content and, on the other hand, to ensure that you feel completely at home on our website. With the help of web analytics tools, we can examine the behaviour of our website visitors in more detail and then improve our website for both you and us accordingly. For example, we can identify the average age of our visitors, where they come from, when our website is most frequently visited, or which content or products are particularly popular. All this information helps us to optimise the website and thus tailor it as closely as possible to your needs, interests and preferences .
Exactly what data is stored naturally depends on the analytics tools used. However, as a rule, the following information is typically stored: what content you view on our website, which buttons or links you click, when you visit a page, which browser you use, which device (PC, tablet, smartphone, etc. ) you use to visit the website, or which computer system you use. If you have consented to the collection of location data, this may also be processed by the web analytics tool provider.
Your IP address is also stored. Under the General Data Protection Regulation (GDPR), IP addresses constitute personal data. However, your IP address is generally stored in pseudonymised form (i.e. in an unrecognisable and truncated form). For the purposes of testing, web analytics and web optimisation, no direct data such as your name, age, address or email address is stored. All such data, where collected, is stored in pseudonymised form. This means you cannot be identified as an individual.
The following example schematically illustrates how Google Analytics works as an example of client-based web tracking using JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data for only a few minutes or until you leave the website, whilst other cookies may store data for several years.
We provide further information on the duration of data processing below, where we have additional details. Generally, we process personal data only for as long as is strictly necessary to provide our services and products. If, as is the case with accounting, this retention period may be exceeded.
You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
The use of web analytics requires your consent, which we have obtained via our cookie pop-up. According to Article 6(1)(a) of the GDPR (Consent), this consent forms the legal basis for the processing of personal data, as may occur during collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of web analytics, we detect website errors, identify attacks and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) GDPR (Legitimate Interests). However, we only use these tools if you have given your consent.
As web analytics tools use cookies, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools is provided – where available – in the following sections.
Jetpack Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimise the website.
📓 Data processed: Access statistics containing data such as access locations, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses.
📅 Retention period: until the data is no longer required for the services
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate Interests) (Legitimate interests)
We use the WordPress plug-in Jetpack on our website. Jetpack is software that provides us with web analytics, amongst other things. Jetpack is operated by the company Automattic (Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA), which utilises technology from the company Quantcast (Inc., 201 3rd St, Floor 2, San Francisco, CA 94103-3153, USA) for this product. The integrated tracking tool also collects, stores and processes your personal data. In this privacy policy, we explain exactly what data is involved, why we use Jetpack and how you can prevent this data storage.
Jetpack is a plug-in -in for WordPress websites with many different functions and modules. All these tools help us to make our website more attractive, more secure and enable us to welcome more visitors. For example, the tool can display related posts, content can be shared, and Jetpack can also improve the loading speed of our website. All functions are hosted and provided by WordPress.
It is crucial to us that you feel at home on our website and find what you are looking for. We can only be successful if you are satisfied with our service. And to know how and where we can further improve our website, we need information. Through Jetpack, we can see, for example, how often and for how long you stay on a single webpage, or which buttons you like to click. With the help of this information, we can improve our website and adapt it to your wishes and preferences.
In particular, the built-in tracking tool WordPress.com Statistics collects, stores and processes your personal data. To ensure the Jetpack tool works, Jetpack sets a cookie in your browser when you open a webpage that incorporates components of the tool. The collected data is synchronised with Automattic and stored there.
This includes, in addition to your IP address (which is anonymised before storage) and data on user behaviour, such as browser type, unique device identifier, preferred language, date and time of page visit, operating system and information about the mobile network. Jetpack uses this information to improve its own services and offerings and to gain better insights into the use of its own service. Furthermore, the following data may also be synchronised and stored:
Jetpack also uses cookies for data storage. Below, we show you a few selected examples of cookies used by Jetpack:
Name: eucookielaw
Value: 1613651061376113077832-6
Purpose: Stores the status of the user’s consent to the use of cookies.
Expiry date: after 180 days
Name: tk_ai
Value: 0
Purpose: This cookie stores a randomly generated anonymous ID. It is only used within the admin area to track general analytics.
Expiry date: at the end of the session
Name: tk_tc
Value: E3%2BgJ1Pw6iYKk%2Fvj113077832-3
Purpose: This is a so-called referral cookie. It is used to analyse the connection between WooCommerce and a website with the Jetpack plugin.
Expiry date: at the end of the session
Note: Jetpack uses many different cookies. Which specific cookies are used depends, on the one hand, on the Jetpack features utilised and, on the other hand, on your actions on websites with the Jetpack plugin integrated. At https://de.jetpack.com/support/cookies/ you can view a list of possible cookies used by Jetpack.
Automattic stores the collected data until it is no longer required for its own services. Beyond this period, the data is only retained if the company is legally obliged to do so. Web server logs, such as your IP address, browser type and operating system, are deleted after approximately 30 days. The data is stored on the company’s servers in the United States.
As mentioned above, Jetpack uses cookies to store data. If you do not want Jetpack to collect data from you in future, you can request an ‘opt-out’ cookie at https://www.quantcast.com/opt-out/. Quantcast sets this cookie, which means that no visitor data relating to you will be stored. This remains the case until you delete this cookie.
Alternatively, you can simply manage, disable or delete cookies in your browser as you wish. Cookie management works slightly differently depending on the type of browser. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
The use of Jetpack requires your consent, which we have obtained via our cookie pop-up. This consent constitutes the legal basis for the processing of personal data, as may occur during collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of Jetpack, we detect website errors, identify attacks and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) f GDPR (Legitimate Interests). However, we only use Jetpack if you have given your consent.
Automattic also processes your data in the USA, amongst other places. Jetpack and Automattic are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Automattic uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Automattic undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant standard contractual clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
If you would like to find out more about the data protection policies and the processing of data by Jetpack or Automattic, we recommend you read the privacy policy at https://automattic.com/privacy/, the cookie policy at https://automattic.com/cookies/ and also the information page https://jetpack.com/support/ what-data-does-jetpack-sync/. We hope we have been able to provide you with a good insight into data processing by Jetpack.
Email Marketing Summary
👥 Data subjects: Newsletter subscribers
🤝 Purpose: Direct marketing via email, notification of system-related events
📓 Data processed: Data entered during registration, but at least the email address. You can find more details on this in the relevant email marketing tool.
📅 Retention period: For the duration of the subscription
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
To keep you up to date, we also use email marketing. In doing so, provided you have consented to receiving our emails or newsletters, your data will also be processed and stored. Email marketing is a sub-sector of online marketing. It involves sending news or general information about a company, products or services via email to a specific group of people who are interested in them.
If you wish to take part in our email marketing (usually via a newsletter), you normally simply need to register with your email address. To do this, you fill in an online form and submit it. However, we may also ask you for your title and name so that we can address you personally.
Generally, signing up for newsletters works using the so-called “double opt-in procedure”. After you have signed up for our newsletter on our website, you will receive an email to confirm your newsletter subscription. This ensures that the email and that nobody has signed up using someone else’s email address. We, or a notification tool we use, log every single subscription. This is necessary so that we can also provide evidence of a legally correct subscription process. As a rule, the time of subscription, the time of subscription confirmation and your IP address are stored. In addition, any changes to your stored data.
Naturally, we want to stay in touch with you and keep you up to date with the most important news about our company. To this end, we use email marketing – often simply referred to as a “newsletter” – as a key component of our online marketing. Provided you consent to this or it is permitted by law, we will send you newsletters, system emails or other notifications via email. When we use the term “newsletter” in the following text, we mainly mean emails sent out on a regular basis. Naturally, we do not wish to bother you in any way with our newsletters. That is why we always strive to provide only relevant and interesting content. This way, you can find out more about our company, our services or our products. As we are constantly improving our offerings, our newsletter will also keep you informed whenever there is news or we are currently running special, lucrative promotions. Should we engage a service provider offering a professional mailing tool for our email marketing, we do so in order to provide you with fast and secure newsletters. The purpose of our email marketing is fundamentally to inform you about new offers and to help us achieve our business objectives.
If you subscribe to our newsletter via our website, you confirm your membership of an email list via email to your membership of an email list. In addition to your IP address and email address, your title, name, address and telephone number may also be stored. However, this will only occur if you consent to this data being stored. The data marked as such is necessary for you to be able to use the service offered. Providing this information is voluntary; however, failure to do so will mean that you cannot use the service. In addition, information about your device or your preferred content on our website may also be stored. You can find out more about data storage when you visit a website in the section “Automatic data storage”. We record your declaration of consent so that we can always demonstrate that it complies with our laws.
If you unsubscribe your email address from our email/newsletter distribution list, we may store your address for up to three years on the basis of our legitimate interests, so that we can still prove your consent at that time. We may only process this data if we need to defend ourselves against any claims.
However, if you confirm that you have given us your consent to subscribe to the newsletter, you may submit an individual request for deletion at any time. If you permanently withdraw your consent, we reserve the right to store your email address on a block list. As long as you have voluntarily subscribed to our newsletter, we will of course retain your email address.
You can cancel your newsletter subscription at any time. To do so, you simply need to withdraw your consent to the newsletter subscription. This usually takes just a few seconds or one or two clicks. You will usually find a link at the very end of each email to cancel your newsletter subscription. If you really cannot find the link in the newsletter, please contact us by email and we will cancel your newsletter subscription immediately.
Our newsletter is sent on the basis of your consent (Article 6(1)(a) a GDPR). This means that we may only send you a newsletter if you have actively subscribed to it beforehand. Where applicable, we may also send you promotional messages, provided that you have become a customer of ours and have not objected to the use of your email address for direct marketing.
Information on specific email marketing services and how they process personal data can be found – where available – in the following sections.
Social Media Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Presentation and optimisation of our services, contact with visitors, prospective customers, etc., advertising
📓 Data processed: Data such as telephone numbers, email addresses, contact details, user behaviour data, information about your device and your IP address.
You can find more details on this under the respective social media tool used.
📅 Retention period: depending on the social media platforms used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate interests)
In addition to our website, we are also active on various social media platforms. In doing so, user data may be processed so that we can specifically target users who are interested in us via social networks. Furthermore, elements of a social media platform may also be embedded directly into our website. This is the case, for example, when you click on a so-called social media button on our website and are redirected directly to our social media presence. The term ‘social media’ refers to websites and apps through which registered members can produce content, share content openly or within specific groups, and network with other members.
For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to interested parties. The social media elements integrated into our website help you switch to our social media content quickly and without complications.
The data stored and processed through your use of a social media channel is primarily intended to enable web analytics. The aim of these analyses is to develop more precise and personalised marketing and advertising strategies. Depending on your behaviour on a social media platform, the analysed data can be used to draw relevant conclusions about your interests and create so-called user profiles. This also enables platforms to present you with tailored advertisements. In most cases, cookies are set in your browser for this purpose, which store data on your usage behaviour.
We generally assume that we remain responsible under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Article 26 of the GDPR. Where this is the case, we will draw your attention to this separately and operate on the basis of a relevant agreement. The key points of the agreement are then set out below for the platform in question.
Please note that when using social media platforms or our embedded elements, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are American companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.
Exactly what data is stored and processed depends on the respective provider of the social media platform. However, it usually involves data such as telephone numbers, email addresses, data you enter into a contact form, user data such as which buttons you click, who you like or follow, when you visited which pages, information about your device and your IP address. Most of this data is stored in cookies. In particular, if you have a profile on the social media channel you are visiting and are logged in, data can be linked to your profile.
All data collected via a social media platform is also stored on the providers’ servers. Consequently, only the providers have access to the data and can provide you with the relevant or make changes.
If you wish to know exactly what data is stored and processed by the social media and how you can object to data processing, you should read the company’s privacy policy carefully. If you have any questions regarding data storage and processing or wish to exercise your rights, we recommend that you contact the provider directly.
We provide further information on the duration of data processing below, where available. For example , the social media platform Facebook stores data until it is no longer required for its own purposes. However, customer data that is matched with the user’s own data is deleted within two days. Generally, we process personal data only for as long as is strictly necessary for the provision of our services and products. If required by law, such as in the case of accounting, this retention period may be exceeded.
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers such as embedded social media elements. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
As social media tools may use cookies, we also recommend that you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
If you have consented to your data being processed and stored via integrated social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, where consent has been given, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining swift and effective communication with you or other customers and business partners. Nevertheless, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
Information on specific social media platforms can be found – where available – in the following sections.
Facebook Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as customer data, user behaviour data, information about your device and your IP address.
You can find more details on this further down in the privacy policy.
📅 Retention period: until the data is no longer useful for Facebook’s purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We use selected Facebook tools on our website. Facebook is a social media network operated by Meta Platforms Inc. or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. These tools enable us to offer you and others interested in our products and services the best possible experience.
If data is collected from you and forwarded via our embedded Facebook elements or via our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook bears sole responsibility for the further processing of this data. Our joint obligations have also been set out in a publicly accessible agreement at https://www.facebook. com/legal/controller_addendum. This stipulates, for example, that we must clearly inform you about the use of Facebook tools on our site. Furthermore, we are also responsible for ensuring that the tools are integrated into our website in a manner that complies with data protection laws. Facebook, on the other hand, is responsible, for example, for the data security of Facebook products. If you have any questions regarding data collection and processing by Facebook, you can contact the company directly . If you direct your enquiry to us, we are obliged to forward it to Facebook.
Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.
Alongside many other products, Facebook also offers the so-called “Facebook Business Tools”. This is Facebook’s official term. However, as the term is not widely known, we have decided to refer to them simply as Facebook tools. These include, amongst others:
Facebook Pixelsocial plugins (such as the “Like” or “Share” button)Facebook LoginAccount KitAPIs
(Application Programming Interface)SDKs (Software Development Kits)Platform integrationsPluginsCodesSpecificationsDocumentationTechnologies and services
Through these tools, Facebook expands its services and is able to obtain information about user activity outside of Facebook.
We only want to show our services and products to people who are genuinely interested in them. With the help of advertisements (Facebook Ads) we can reach precisely these people. However, in order to show users relevant adverts, Facebook requires information about people’s preferences and needs. Consequently, information about user behaviour (and contact details) on our website is made available to the company. This enables Facebook to collect better user and can display relevant adverts about our products or services to interested people. The tools thus enable tailored advertising campaigns on Facebook.
Facebook refers to data about your behaviour on our website as “event data” . This data is also used for measurement and analysis services. Facebook can thus create “campaign reports” on our behalf regarding the effectiveness of our advertising campaigns. Furthermore, through analysis, we gain a better insight into how you use our services, website or products. This enables us to use some of these tools to optimise your user experience on our website. For example, you can use the social plugins to share content from our site directly on Facebook.
When using individual Facebook tools, personal data (customer data) be sent to Facebook. Depending on the tools used, customer data such as name, address, telephone number and IP address may be transmitted.
Facebook uses this information to match the data with the data it already holds about you (provided you are a Facebook member). Before customer data is transmitted to Facebook, a process known as “hashing” takes place . This means that a data set of any size is transformed into a string of characters. This also serves to encrypt the data.
In addition to contact details, ‘event data’ is also transmitted. ‘Event data’ refers to the information we receive about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information received with third parties (such as advertisers), unless the company has explicit permission or is legally obliged to do so. ‘Event data’ can also be linked to contact details. This enables Facebook to offer better personalised advertising. Following the aforementioned matching process, Facebook deletes the contact details.
In order to deliver optimised adverts, Facebook only uses the event data if it has been aggregated with other data (collected by Facebook in other ways). Facebook also uses this event data for security, protection, development and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files which are used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, different numbers of cookies are created in your browser. We go into more detail about individual Facebook cookies in the descriptions of the individual Facebook tools. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.
In principle, Facebook stores data until it is no longer required for its own services and Facebook products. Facebook has servers located all over the world where its data is stored. However, customer data is deleted within 48 hours after it has been matched with the user’s own data.
In accordance with the General Data Protection Regulation , you have the right to access, rectify, transfer and delete your data.
Your data will only be completely deleted if you delete your Facebook account entirely. Here’s how to delete your Facebook account:
1) Click on ‘Settings’ on the right-hand side of Facebook.
2) Then click on ‘Your Facebook Information’ in the left-hand column.
3) Now click on ‘Deactivation and Deletion’.
4) Select ‘Delete Account’ and then click on ‘Continue and Delete Account’
5) Enter your password, click on “Continue” and then on “Delete Account”
The data that Facebook receives via our site is stored, amongst other things, via cookies (e.g. in social plugins). In your browser, you can disable individual or all cookies, delete or manage individual or all cookies. Depending on which browser you use, this works in different ways. Under the “Cookies” section, you will find the relevant links to the instructions for the most popular browsers.
If you do not wish to have any cookies at all, you can set your browser to always inform you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
If you have consented to your data being processed and stored via integrated Facebook tools, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for the purpose of fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and review Facebook’s privacy policy or cookie guidelines.
Facebook also processes your data in the USA, amongst other places. Facebook, or Meta Platforms, is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Facebook uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU -US Data Privacy Framework and the Standard Contractual Clauses, Facebook undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/ legal/terms/dataprocessing.
We hope we have provided you with the most important information regarding the use and data processing by Facebook tools. If you would like to find out more about how Facebook uses your data, we recommend you read the data policy at https://www.facebook.com/privacy/policy/.
Instagram Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as user behaviour data, information about your device and your IP address.
Further details can be found below in the privacy policy.
📅 Retention period: until Instagram no longer requires the data for its purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We have integrated Instagram features into our website. Instagram is a social media platform operated by Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and is one of the Facebook products. The integration of Instagram content on our website is known as embedding. This allows us to display content such as buttons, photos or videos from Instagram directly on our website. When you visit pages on our website that have an integrated Instagram feature, data is transmitted to, stored and processed by Instagram. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed across all Facebook companies.
Below, we would like to give you a more detailed insight into why Instagram collects data,
what data is involved, and how you can largely control the processing of this data. As Instagram is part of Meta Platforms Inc., we draw our information from both the Instagram guidelines and the Meta Privacy Policy itself.
Instagram is one of the world’s best-known social media networks. Instagram combines the benefits of a blog with those of audiovisual platforms such as YouTube or Vimeo. On ‘Insta’ (as many users colloquially call the platform) to upload photos and short videos, edit them with various filters, and share them on other social networks. And if you don’t want to be active yourself, you can simply follow other interesting users.
Instagram is the social media platform that has really taken off in recent years. And, of course, we have responded to this boom too. We want you to feel as comfortable as possible on our website. That’s why presenting our content in a varied way is a matter of course for us. Through the embedded Instagram features, we can enrich our content with helpful, funny or exciting content from the world of Instagram. As Instagram is a subsidiary of Facebook, the data collected can also be used for personalised advertising on Facebook. This ensures our adverts only reach people who are genuinely interested in our products or services.
Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics, giving us greater insight into your preferences and interests. It is important to note that these reports do not identify you personally.
When you visit one of our pages that incorporates Instagram features (such as Instagram images or plug-ins ), your browser automatically connects to Instagram’s servers. In doing so, data is sent to Instagram, stored and processed. This happens regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases made, the adverts you see and how you use our service. Furthermore, the date and time of your interaction with Instagram are also stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.
Facebook distinguishes between customer data and event data. We assume that this is also the case with Instagram. Customer data includes, for example, name, address, telephone number and IP address. This customer data will only be transmitted to Instagram once it has been ‘hashed’. Hashing means that a data record is converted into a string of characters. This allows contact details to be encrypted. In addition, the ‘event data’ mentioned above is also transmitted. By ‘event data’, Facebook – and consequently Instagram – means data about your user behaviour. It may also happen that contact details are combined with event data. The contact details collected are matched against the data Instagram already holds about you.
Via small text files (cookies), which are usually stored in your browser, the collected data is transmitted to Facebook. Depending on the Instagram features you use and whether you have an Instagram account yourself, varying amounts of data are stored.
We assume that data processing on Instagram works in the same way as on Facebook. This means: if you have an Instagram account or have visited www.instagram.com, Instagram has set at least one cookie. If this is the case, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram feature. After 90 days at the latest (following synchronisation)
this data will be deleted or anonymised. Although we have looked closely at Instagram’s data processing, we cannot say exactly what data Instagram collects and stores.
Below, we show you the cookies that are set in your browser at the very least when you click on an Instagram feature (such as a button or an Instagram image) . In our test, we assume that you do not have an Instagram account. If you are logged into Instagram, significantly more cookies will of course be set in your browser.
These cookies were used in our test:
Name: csrftoken
Value: “”
Purpose: This cookie is most likely set for security reasons to prevent forged requests. However, we were unable to ascertain this with any greater certainty.
Expiry date: after one year
Name: mid
Value: “”
Purpose: Instagram sets this cookie to optimise its own services and offerings both on and off Instagram. The cookie assigns a unique user ID.
Expiry date: at the end of the session
Name: fbsr_113077832124024
Value: No information
Purpose: This cookie stores the login request for users of the Instagram app.
Expiry date: At the end of the session
Name: rur
Value: ATN
Purpose: This is an Instagram cookie that ensures functionality on Instagram.
Expiry date: At the end of the session
Name: urlgen
Value: “{”194.96.75.33”: 1901}:1iEtYv:Y833k2_UjKvXgYe113077832”
Purpose: This cookie is used for Instagram’s marketing purposes.
Expiry date: at the end of the session
Note: We cannot claim that this list is exhaustive. Which cookies are set in each individual case depends on the embedded features and your use of Instagram.
Instagram shares the information it receives with Facebook companies, external partners and people you connect with worldwide. Data processing is carried out in accordance with its own data policy. Your data is distributed across Facebook servers worldwide, partly for security reasons. Most of these servers are located in the USA.
Thanks to the General Data Protection Regulation, you have the right to access, transfer, rectify and erase your data. You can manage your data in the Instagram settings. If you wish to completely delete your data on Instagram, you must permanently delete your Instagram account.
Here’s how to delete your Instagram account:
First, open the Instagram app. On your profile page, scroll down and tap ‘Help Centre’. This will take you to the company’s website. On the website, click ‘Manage your account’ and then ‘Delete your account ”.
If you delete your account completely, Instagram will delete posts such as your photos and status updates. Information that other people have shared about you does not belong to your account and will therefore not be deleted.
As mentioned above, Instagram primarily stores your data via cookies. You can manage, disable or delete these cookies in your browser. Depending on your browser, the process works slightly differently. Under the “Cookies” section, you will find links to the relevant guides for the most popular browsers.
You can also generally configure your browser so that you are always notified when a cookie is about to be set. You can then decide on a case-by-case basis whether or not to accept the cookie.
If you have consented to your data being processed and stored via embedded social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers and business partners. Nevertheless, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy on cookies carefully and to consult the privacy policy or cookie guidelines of the respective service provider.
Instagram also processes your data in the USA, amongst other places. Instagram and Meta Platforms are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Instagram uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the US). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Instagram undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https:// eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
We have tried to provide you with the most important information about data processing by Instagram. You can find out more about Instagram’s data policies at https://privacycenter.instagram.com/policy/.
Security & Anti-Spam Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Cybersecurity
📓 Data processed: Data such as your IP address, name or technical data such as browser version
You can find more details below and in the individual privacy policy texts.
📅 Retention period: In most cases, the data is stored until it is no longer required to fulfil the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
With so-called security & anti spam software, you and we can protect ourselves against various spam or phishing emails and other potential cyberattacks. Spam refers to unsolicited bulk marketing emails that you did not request. Such emails are also known as junk mail and can incur costs. Phishing emails, on the other hand, are messages designed to build trust through fake messages or websites in order to gain access to personal data . Anti-spam software generally protects against unwanted spam messages or malicious emails that could, for example, introduce viruses into our system. We also use general firewall and security systems that protect our computers from unwanted network attacks.
We place particular emphasis on security on our website. After all, it is not just about our security, but above all about yours. Unfortunately, cyber threats have now become part of everyday life in the world of IT and the internet. Hackers often attempt to steal personal data from an IT system using a cyberattack. And that is why a good defence system is absolutely essential. A security system monitors all incoming and outgoing connections to our network or computer. To achieve even greater protection against cyberattacks, we use additional external security services alongside the standardised security systems on our computer. This helps to better prevent unauthorised data traffic, thereby protecting us from cybercrime.
Exactly which data is collected and stored naturally depends on the specific service. However, we always endeavour to use only programmes that collect data sparingly or store only data necessary for the provision of the service offered. In principle, the service may store data such as name, address, IP address, email address and technical data such as browser type or browser version. Performance and log data may be collected to detect potential incoming threats in good time. This data is processed within the scope of the services and in compliance with applicable laws. This also includes, in the case of US providers (via the Standard Contractual Clauses). In some cases, these security services also work with third-party providers who may store and/or process data under instruction and in accordance with the privacy policy and further security measures. Data storage usually takes place via cookies.
We provide further information on the duration of data processing below, where we have additional details. For example, security programmes store data until you or we revoke consent for data storage. Generally, personal data is only stored for as long as is strictly necessary to provide the services. Unfortunately, in many cases we do not have precise information from the providers regarding the duration of storage.
You also have the right and the option to withdraw your consent to the use of cookies or third-party security software providers at any time. This can be done either via our cookie management tool or via other opt
-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
As such security services may also use cookies, we recommend you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
We implement the security services primarily on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in maintaining a robust security system against various cyberattacks.
Certain processing activities, in particular the use of cookies and security features, require your consent. If you have given your consent, that your data may be processed and stored by integrated security services, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the services we use place cookies in your browser to store data. We therefore recommend that you read our privacy policy on cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
Information on specific tools can be found – where available – in the following sections.
Audio & Video Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
Further details can be found below in the relevant privacy policy texts.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We have integrated audio and video elements into our website so that you can, for example, watch videos or listen to music/podcasts directly via our website. The content is provided by service providers. All content is therefore also sourced from the providers’ respective servers.
These are embedded functional elements from platforms such as YouTube, Vimeo or Spotify. Use of these portals is generally free of charge, although paid content may also be published. With the help of these embedded elements, you can listen to or watch the respective content via our website.
When you use audio or video elements on our website, your personal data may also be transmitted to, processed by and stored.
Naturally, we want to provide you with the best possible experience on our website. And we are aware that content is no longer conveyed solely through text and static images. Instead of simply providing you with a link to a video, we offer audio and video formats directly on our website that are entertaining or informative – and ideally both. This enhances our service and makes it easier for you to access interesting content. Thus, in addition to our texts and images, we also offer video and/or audio content.
When you visit a page on our website that contains, for example, an embedded video, your server connects to the service provider’s server. In the process, data is also transferred from you to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system, and other general information about your device. Furthermore, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which button you clicked, or via which website you are using the service. All this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymised data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
You can find out exactly how long the data is stored on the third-party providers’ servers either further down in the privacy text for the respective tool or in the provider’s privacy policy. As a general rule, personal data is only processed for as long as is absolutely necessary for the provision of our services or products. This generally applies to third-party providers as well. In most cases, you can assume that certain data will be stored on the third-party providers’ servers for several years. Data can be stored for varying lengths of time, particularly in cookies. Some cookies are deleted as soon as you leave the website, whilst others may remain stored in your browser for several years.
You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser. The lawfulness of the processing up to the point of withdrawal remains unaffected.
As cookies are usually also used through the embedded audio and video functions on our site, you should also read our general privacy policy regarding cookies. You can find out more about the handling and storage of your data in the privacy policies of the respective third-party providers.
If you have consented to your data being processed and stored through embedded audio and video elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded audio and video elements to the extent that you have given your consent.
Vimeo Privacy Policy Summary
👥 Data subjects: Website visitors
🤝
Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
You can find more details on this further down in this privacy policy.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6( 1(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate interests)
We also use videos from Vimeo on our website. The video portal is operated by Vimeo LLC, 555 West 18th Street, New York, New York 10011, USA. With the help of a plug-in, we can display interesting video content directly on our website. In doing so, certain data relating to you may be transferred to Vimeo. In this privacy policy, we explain what data is involved, why we use Vimeo, and how you can manage or prevent the transfer of your data.
Vimeo is a video platform founded in 2004 that has enabled the streaming of videos in HD quality since 2007. Since 2015, streaming in 4K Ultra HD has also been available. Use of the portal is free of charge, although paid content can also be published. Compared to the market leader YouTube, Vimeo places a primary emphasis on high-quality content. The platform thus offers a wide range of artistic content such as music videos and short films, as well as informative documentaries on a diverse array of topics.
The aim of our website is to to provide you with the best possible content. And to make it as easily accessible as possible. Only when we have achieved this are we satisfied with our service. The video service Vimeo helps us to achieve this goal. Vimeo offers us the opportunity to present high-quality content directly on our website. Instead of simply providing you with a link to an interesting video, you can watch the video straight away on our site. This enhances our service and makes it easier for you to access interesting content. We therefore offer video content in addition to our text and images.
When you visit a page on our website that has an embedded Vimeo video, your browser connects to Vimeo’s servers. This involves a transfer of data. This data is collected, stored and processed on Vimeo’s servers. Regardless of whether you have a Vimeo account or not, Vimeo collects data about you. This includes your IP address, technical information about your browser type, your operating system or very basic device information. Furthermore, Vimeo stores information about which website you are using the Vimeo service on and what actions (web activities) you carry out on our website. These web activities include, for example, session duration, bounce rate or which button you clicked on our website with the built-in Vimeo function. Vimeo can
track and store these actions using cookies and similar technologies.
If you are logged in as a registered member of Vimeo, more data may generally be collected, as more cookies may already have been set in your browser. Furthermore, your actions on our website are directly linked to your Vimeo account. To prevent this, you must log out of Vimeo whilst ‘browsing’ our website.
Below, we list the cookies set by Vimeo when you are on a website with an integrated Vimeo function. This list is not exhaustive and assumes that you do not have a Vimeo account.
Name: player
Value: “”
Purpose: This cookie saves your settings before you play an embedded Vimeo video. This ensures that your preferred settings are restored the next time you watch a Vimeo video.
Expiry date: after one year
Name: vuid
Value: pl1046149876.614422590113077832-4
Purpose: This cookie collects information about your actions on websites that have an embedded Vimeo video.
Expiry date: after 2 years
Note: These two cookies are always set as soon as you visit a website with an embedded Vimeo video. If you watch the video and click the button to, for example, “ share” or “like” the video, for example, further cookies are set. These are also third-party cookies such as _ga or _gat_UA-76641-8 from Google Analytics or _fbp from Facebook. Exactly which cookies are set here depends on your interaction with the video.
The following list shows a selection of possible cookies that are set when you interact with the Vimeo video:
Name: _abexps
Value: %5B% 5D
Purpose: This Vimeo cookie helps Vimeo to remember the settings you have chosen. These may include, for example, a default language, a region or a username. In general, the cookie stores data about how you use Vimeo.
Expiry date: after one year
Name: continuous_play_v3
Value: 1
Purpose: This is a first-party cookie from Vimeo. The cookie collects information on how you use the Vimeo service. For example, the cookie stores when you pause or resume playback of a video.
Expiry date: after one year
Name: _ga
Value: GA1.2.1522249635.1578401280113077832-7
Purpose: This is a third-party cookie from Google. By default, analytics.js uses the _ga cookie to store the user ID.
Essentially, it is used to distinguish between website visitors.
Expiry date: after 2 years
Name: _gcl_au
Value: 1.1.770887836.1578401279113077832-3
Purpose: This third-party cookie from Google AdSense is used to improve the effectiveness of adverts on websites.
Expiry date: after 3 months
Name: _fbp
Value: fb.1.1578401280585.310434968
Purpose: This is a Facebook cookie. This cookie is used to display adverts or promotional from Facebook or other advertisers.
Expiry date: after 3 months
Vimeo uses this data, amongst other things, to improve its own service, to communicate with you and to implement its own targeted advertising measures. Vimeo emphasises on its website that, for embedded videos, only first-party cookies (i.e. cookies from Vimeo itself) are used as long as you do not interact with the video.
Vimeo is headquartered in White Plains, New York (USA). However, its services are offered worldwide. In doing so, the company uses computer systems, databases and servers in the USA and in other countries. Your data may therefore also be stored and processed on servers in America. The data remains stored at Vimeo until the company no longer has a business reason for storing it. The data is then deleted or anonymised.
You always have the option to manage cookies in your browser according to your preferences. For example, if you do not want Vimeo to set cookies and thus collect information about you, you can delete or disable cookies in your browser settings at any time. The process varies slightly depending on your browser. Please note that after disabling or deleting cookies, various functions may no longer be available to their full extent. Under the ‘Cookies’ section, you will find links to the relevant guides for the most popular browsers.
If you are a registered Vimeo member, you can also manage on Vimeo.
If you have consented to your data being processed and stored by embedded Vimeo elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded Vimeo elements to the extent that you have given your consent. Vimeo also sets cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider .
Vimeo processes your data, a. in the USA. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This may entail various risks regarding the lawfulness and security of data processing.
As the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or for data transfers to those countries, Vimeo uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through these clauses, Vimeo undertakes, when processing your relevant data, to comply with European data protection standards, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/ oj?locale=de
You can find more information on Vimeo’s standard contractual clauses at https://vimeo.com/privacy#international_data_transfers_and_certain_user_rights.
You can find out more about Vimeo’s use of cookies at https://vimeo.com/cookie_policy, and read about Vimeo’s data protection policy at https://vimeo.com/privacy.
YouTube Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
You can find more details on this further down in this privacy policy.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video portal that has been a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. In the process, various data is transmitted (depending on your settings). Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing within the European Union.
Below, we would like to explain in more detail what data is processed, why we have embedded YouTube
videos and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on and upload videos free of charge. Over the last few years, YouTube has become one of the most important social media channels worldwide. To enable us to display videos on our website, YouTube provides a code snippet which we have embedded on our site.
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our website. And, of course, interesting videos are a must. With the help of our embedded videos, we provide you with further helpful content alongside our text and images. Furthermore, the embedded videos make our website easier to find on the Google search engine. Even when we place adverts via Google Ads, Google – thanks to the data collected – only show these adverts to people who are genuinely interested in our offers.
As soon as you visit one of our pages that has a YouTube video embedded, YouTube sets at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually link your interactions on our website to your profile using cookies . This includes data such as session duration, bounce rate, approximate location, and technical information such as browser type, screen resolution or your internet service provider. Other data may include contact details, any ratings, sharing content via social media or adding it to your favourites on YouTube.
If you are not logged into a Google account or a YouTube account, Google stores data using a unique identifier which is linked to your device, browser or app. This ensures, for example, that your preferred language setting is retained. However, much interaction data cannot be stored as fewer cookies are set.
In the list below, we show cookies which were set in a browser test. On the one hand, we show cookies that are set without a logged-in YouTube account. On the other hand, we show cookies that are set with a logged-in account. The list cannot claim to be exhaustive, as user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y113077832-1
Purpose: This cookie records a unique ID to store statistics on the video viewed.
Expiry date: at the end of the session
Name: PREF
Value: f1=50000000
Purpose: This cookie also records your unique ID. Google uses PREF to obtain statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).
Expiry date: after 8 months
Additional cookies that are set when you are logged in to your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7113077832-
Purpose: This cookie is used to create a profile of your interests. The data is used for personalised advertisements.
Expiry date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user’s consent to use various Google services. CONSENT also serves security purposes, to verify users and protect user data from unauthorised attacks.
Expiry date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile of your interests. This data helps to display personalised advertising.
Expiry date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login details.
Expiry date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.
Expiry date: after 2 years
Name: SID
Value: oQfNKjAsI113077832 -
Purpose: This cookie stores your Google account ID and the time of your last login in a digitally signed and encrypted form.
Expiry date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and what adverts you may have seen before visiting our site.
Expiry date: after 3 months
The data that YouTube receives from you and processes is stored on Google’s servers. Most of these servers are located in the United States. At https://datacenters.google/ you can see exactly where Google’s data centres are located. Your data is distributed across the servers. This makes the data quicker to access and better protected against tampering.
Google stores the collected data for varying lengths of time. You can delete some data at any time, other data is automatically deleted after a limited period, and yet other data is stored by Google for a longer period. Some data (such as items from ‘My Activity’, photos or documents, products) stored in your Google Account remains there until you delete it. Even if you are not signed in to a Google Account, you can delete some data linked to your device, browser or app.
In principle, you can delete data manually in your Google Account. With the automatic deletion feature for location and activity data introduced in 2019, information is stored for either 3 or 18 months, depending on your choice, and then deleted.
Regardless of whether you have a Google account or not, you can configure your browser to delete or disable Google cookies. Depending on which browser you use, this works in different ways. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
If you do not wish to accept cookies at all, you can set your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
If you have consented to your data being processed and stored by embedded YouTube elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining swift and effective communication with you or other customers and business partners. We use the embedded YouTube elements only to the extent that you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
YouTube also processes your data in the USA, amongst other places. YouTube and Google are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60 -be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards, even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.
eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
As YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to find out more about how your data is handled, we recommend you read the privacy policy at https://policies.google.com/privacy?hl=de.
We have incorporated the YouTube Subscribe Button . You can usually recognise the button by the classic YouTube logo. The logo displays the words ‘Subscribe’ or ‘YouTube’ in white text on a red background, with the white ‘Play’ icon to the left of it. However, the button may also appear in a different design.
Our YouTube channel regularly offers you funny, interesting or exciting videos. With the embedded “Subscribe” button, you can subscribe to our channel directly from our website and do not need to visit the YouTube website separately. We therefore want to make accessing our comprehensive content as easy as possible for you. Please note that this allows YouTube to store and process data about you.
If you see a built-in subscribe button on our site, YouTube – according to Google – sets at least one cookie. This cookie stores your IP address and our URL. YouTube can also obtain information about your browser, your approximate location and your default language in this way. During our test, the following four cookies were set without being logged in to YouTube:
Name: YSC
Value: b9-CV6ojI5113077832Y
Purpose: This cookie records a unique ID to store statistics on the video viewed.
Expiry date: at the end of the session
Name: PREF
Value: f1=50000000
Purpose: This cookie also records your unique ID. Google uses PREF to obtain statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 11307783295Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).
Expiry date: after 8 months
Note: These cookies were set following a test and not claim to be exhaustive.
If you are logged into your YouTube account, YouTube can use cookies to record many of your actions/interactions on our website and associate them with your YouTube account.
For example, YouTube thereby receives information such as how long you spend on our site, what type of browser you use, what screen resolution you prefer, or what actions you perform.
YouTube uses this data both to improve its own services and offerings, and to provide analytics and statistics for advertisers (who use Google Ads).
Web Design Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Data processed: The data processed depends heavily on the services used. This usually includes IP address, technical data, language settings, browser version, screen resolution and browser name. You can find more details on this under the respective web design tools used.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use various tools on our website to support our web design. Web design is not, as is often assumed, merely about making our website look attractive, but also about functionality and performance. But of course, achieving the right look for a website is also one of the main goals of professional web design. Web design is a sub-field of media design and deals with the visual, structural and functional design of a website. The aim is to use web design to improve your experience on our website. In web design jargon, the terms ‘user experience’ (UX) and ‘usability’ are used in this context. User experience refers to all the impressions and experiences a website visitor has whilst on a website. Usability is a sub-category of user experience. This concerns the user-friendliness of a website. The main focus here is on ensuring that content, subpages or products are clearly structured and that you can find what you are looking for quickly and easily. To offer you the best possible experience on our website, we also use so-called third-party web design tools. In this privacy policy, the category ‘web design’ therefore covers all services that improve the design of our website. These may include, for example, fonts, various plugins or other integrated web design features.
How you take in information on a website depends very much on the structure, functionality and visual presentation of the website. That is why a good and professional web design has become increasingly important to us too. We are constantly working to improve our website and see this as an added service for you as a website visitor. Furthermore, an attractive and functional website also has economic benefits for us. After all, you will only visit us and make use of our services if you feel completely at ease.
When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data this involves naturally depends heavily on the tools used. Below, you can see exactly which tools we use for our website. For further information on data processing, we also recommend that you read the respective privacy policy of the tools used. There you will usually find out what data is processed, whether cookies are used and how long the data is retained. Through fonts such as Google Fonts, for example, information such as language settings, IP address, browser version, browser screen resolution
and the browser name are automatically transmitted to Google’s servers.
The length of time data is processed varies greatly and depends on the web design elements used. If cookies are used, for example, the retention period may be as short as one minute or as long as a few years. Please do your own research on this matter. We recommend that you consult both our general section on cookies and the privacy policies of the tools used. There you will usually find out exactly which cookies are used and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. In principle, data is only retained for as long as is necessary to provide the service. Data may also be stored for longer where required by law.
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. You can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser. However, under web design elements (mostly in the case of fonts), however, there is also data that cannot be deleted quite so easily. This is the case when data is automatically collected directly when a page is loaded and transmitted to a third-party provider (such as Google). In such cases, please contact the support team of the relevant provider. In the case of Google, you can reach support at https://support.google.com/?hl=de.
If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) 1(a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The relevant legal basis for this is Article 6(1)(f) GDPR (Legitimate Interests). However, we only use web design tools if you have given your consent. We would like to emphasise this point once again here.
Information on specific web design tools is provided – where available – in the following sections.
We use Adobe Fonts, a web font hosting service, on our website. The service provider is the American company Adobe Inc. For the European region, the Irish company Adobe Systems Software Ireland Companies, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland, is responsible.
Adobe processes your data, among other things, in the USA. Adobe is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/
fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Adobe uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR) . Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are designed to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Adobe undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur -lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find more information on Adobe’s standard contractual clauses at https:// www.adobe.com/at/privacy/eudatatransfers.html.
You can find out more about the data processed through the use of Adobe Fonts in the Privacy Policy at https://www.adobe.com/at/privacy.html .
Google Fonts Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as IP address and CSS and font requests
Further details can be found below in this privacy policy.
📅 Retention period: Font files are stored by Google for one year
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We use Google Fonts on our website. These are the “Google fonts” provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.
You do not need to register or provide a password to use Google Fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic. com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google whilst using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used, and stores this data securely. We will look at exactly how this data is stored in more detail later.
Google Fonts (formerly Google Web Fonts) is a directory containing over 800 fonts that Google makes available to its users free of charge.
Many of these fonts are published under the SIL Open Font License, whilst others have been released under the Apache Licence. Both are free software licences.
With Google Fonts, we can use fonts on our own website without having to upload them to our own server. Google Fonts is a key component in maintaining the high quality of our website. All Google fonts are automatically optimised for the web, which saves data volume and is particularly use on mobile devices. When you visit our site, the small file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Different rendering systems in various browsers, operating systems and mobile devices can lead to errors. Such errors can sometimes cause text or entire web pages to appear distorted. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We therefore use Google Fonts so that we can present our entire online service as attractively and consistently as possible.
When you visit our website, the fonts are loaded via a Google server. This external request transmits data to the Google servers. This is how Google recognises that you, or rather your IP address, are visiting our website. The Google Fonts API was developed to limit the use, storage and collection of end-user data to what is necessary for the proper provision of fonts. Incidentally, API stands for ‘Application Programming Interface’ and serves, amongst other things, as a data transmitter in the software sector.
Google Fonts securely stores CSS and font requests on Google’s servers, ensuring they are protected. Through the usage statistics collected, Google can determine how well the individual fonts are received. Google publishes the results on internal analytics pages, such as Google Analytics. Google also uses data from its own web crawler to identify which websites use Google Fonts. This data is published in the Google Fonts BigQuery database. Entrepreneurs and developers use the Google web service BigQuery to analyse and process large volumes of data.
It should also be borne in mind, however, that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution and browser name. It is not clear whether this data is also stored, nor is this explicitly communicated by Google.
Google stores requests for CSS assets on its servers for one day; these servers are mainly located outside the EU. This enables us to use the fonts with the help of a Google stylesheet. A stylesheet is a template that allows you to quickly and easily change, for example, the design or font of a website.
The font files are stored by Google for one year. Google’s aim is to improve website loading times across the board. When millions of websites reference the same fonts, they are cached after the first visit and appear immediately on all other websites visited subsequently. Google sometimes updates font files to reduce file size, increase language coverage and improve design.
Data that Google stores for a day or a year cannot simply be deleted. The data is automatically transmitted to Google when the page is loaded. To delete this data early, you must contact Google Support at https:/ /support.google.com/?hl=en&tid=113077832. In this case, you can only prevent data storage by not visiting our site.
Unlike other web fonts, Google grants us unrestricted access to all fonts. We can therefore access an unlimited range of fonts and thus get the most out of our website. You can find out more about Google Fonts and other questions at https://developers.google.com/fonts/faq?tid=113077832. Although Google addresses data protection issues there, it does not provide truly detailed information on data storage is not provided. It is relatively difficult to obtain truly precise information from Google regarding stored data.
If you have consented to the use of Google Fonts, this consent forms the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent forms the legal basis for the processing of personal data, as may occur during collection via Google Fonts.
We also have a legitimate interest in using Google Fonts to optimise our online service. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Fonts to the extent that you have .
Google also processes your data in the USA, amongst other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d -4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data continues to comply with European data protection standards even when it is transferred to third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant standard contractual clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business. safety.google/intl/de/adsprocessorterms/.
You can also read about what data Google generally collects and how this data is used at https://www.google.com/intl/de/policies/privacy/.
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, particularly when dealing with technical and legal matters. It often makes sense to use legal terms (such as personal data) or specific technical expressions (such as cookies, IP address). However, we do not wish to use these without explanation. Below you will find an alphabetical list of important terms used which we may not have covered sufficiently in the previous privacy policy. Where these terms are taken from the GDPR and constitute definitions, we will also quote the relevant GDPR text here and, where appropriate, add our own explanations.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“Supervisory authority” means an independent public authority established by a Member State in accordance with Article 51;
Explanation: “Supervisory authorities” are always independent public bodies which, in certain cases, also have the power to issue instructions. They are responsible for carrying out so-called state supervision and are located within ministries, special departments or other authorities. In Austria, there is an Austrian Data Protection Authority; in Germany, each federal state has its own data protection authority.
Definition pursuant to Article 4 of the GDPR GDPR
For the purposes of this Regulation, the term:
“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to the controllers, there may also be so-called data processors. This includes any company or person that processes personal data on our behalf. Data processors may therefore include, in addition to service providers such as tax advisors, hosting or cloud providers, payment or newsletter or large companies such as Google or Microsoft.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
‘consent’ of the data subject means any freely given, specific, in an informed and unambiguous manner, in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that they agree to the processing of personal data relating to them;
Explanation: On websites, such consent is usually obtained via a cookie consent
tool. You are no doubt familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also configure individual settings and thus decide for yourself which data processing you permit and which you do not. If you do not consent, no personal data relating to you may be processed. In principle, consent may of course also be given in writing, i.e. not via a tool, .
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
‘recipient’ means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a specific inquiry mandate under Union or Member State law shall not be regarded not as recipients; the processing of such data by the aforementioned authorities shall be carried out in accordance with the applicable data protection regulations in line with the purposes of the processing;
Explanation: Any person or company that receives personal data is considered a recipient. Consequently, we and our processors are also so-called recipients. Only public authorities carrying out an investigative mandate are not considered recipients.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data therefore comprises all data that can be used to identify you as a person. This generally includes data such as:
According to the European Court of Justice (ECJ), your IP address also counts as personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, you as the account holder. Therefore, the storage of an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that are particularly worthy of protection. These include:
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and are therefore the “controller”. If we pass on collected data to other service providers for processing, these are “data processors”. A “Data Processing Agreement (DPA)” must be signed for this purpose.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“processing” any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction , erasure or destruction;
Note: When we refer to processing in our privacy policy, we mean any form of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.
Congratulations! If you are reading this, you have really ‘battled’ your way through our entire privacy policy, or at least scrolled down to this point. As you can see from the length of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, however, we do not merely wish to tell you which data is processed, but also to explain the reasons behind the use of various software programmes. Privacy policies usually sound very technical and legal. However, as most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this is not always possible given the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the data controller. We hope you enjoy your visit and look forward to welcoming you back to our website soon.
All texts are protected by copyright.
Source: Privacy Policy created using the Privacy Policy Generator for Austria by AdSimple
We have drawn up this Privacy Policy (Version 11.11.2025-113077832) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter ‘data’) we, as the data controller – and the data processors commissioned by us (e.g. providers) – process, will process in future, and what legal options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, aims to describe the most important points as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We therefore inform you in clear and simple language that, within the scope of our business activities, we only process personal data only where there is a corresponding legal basis. This is certainly not possible if one provides explanations that are as brief, unclear and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information here that you were not yet aware of.
If you still have any questions, please contact the data controller listed below or in the legal notice, follow the links provided, and consult further information on third-party websites. You will, of course, also find our contact details in the legal notice.
This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (data processors). By personal data, we mean information within the meaning of Article 4(1) of the GDPR, such as a person’s name, email address and postal address of a person. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:
In short: This privacy policy applies to all areas within the company where personal data is processed in a structured manner via the channels mentioned. Should we enter into legal relationships with you outside these channels, we will inform you separately where necessary.
In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, which enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/ DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Other conditions, such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests do not generally apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate place.
In addition to the EU Regulation, national laws also apply:
Where further regional or national laws apply, we will inform you of this in the following sections.
Should you have any questions regarding data protection or the processing of personal data, you will find the contact details of the data controller below, in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR):
Mag. Michael Kalivoda
Schwarzhorngasse 1/2
1050 Vienna
Email: contact@michaelkalivoda.net
Telephone: +436643961280
Legal notice: https://www.michaelkalivoda.net/impressum/
It is a general principle for us that we only store personal data for as long as is strictly necessary for the provision of our services and products. This means we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally obliged to retain certain data even after the original purpose has ceased to apply, for example for accounting purposes.
Should you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.
We provide further information below regarding the specific duration of the respective data processing, where we have further details.
In accordance with Articles 13 and 14 of the GDPR, we inform you of the following rights to which you are entitled to ensure fair and transparent data processing:
In short: You have rights – do not hesitate to contact the controller listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you may lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Head: Dr Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Telephone no.: +43 1 52 152-0
Email address: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
We only transfer or process data to countries outside the scope of the GDPR (third countries) if you consent to such processing or if there is another legal basis for doing so. This applies in particular where processing is required by law or necessary to fulfil a contractual relationship, and in any case only to the extent that this is generally permitted. In most cases, your consent is the primary reason why we process data in third countries. The processing of personal data in third countries such as the USA, where many software providers offer services and have their server locations, may mean personal data being processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists only if a US company processing personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. You can find more information on this at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data not being processed and stored anonymously. Furthermore, US government authorities may, in some cases, access individual data. In addition, collected data may be linked to data from other services provided by the same provider, provided you have a corresponding user account. Where possible, we endeavour to use server locations within the EU, provided this is offered.
We provide more detailed information on data transfers to third countries, where applicable, in the relevant sections of this privacy policy.
To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as possible, within the limits of our capabilities, for third parties to deduce personal information from our data.
Article 25 of the GDPR refers here to “data protection by design and by default” and means that security must always be considered in relation to both software (e.g. forms) and hardware (e.g. access to the server room), and that appropriate measures must be put in place. Where necessary, we will discuss specific measures in more detail below.
TLS, encryption and HTTPS sound very technical, and indeed they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the internet in a way that is secure against eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secured – nobody can “ eavesdrop”.
We have thus introduced an additional layer of security and comply with data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission security by the small padlock symbol in the top left-hand corner of the browser, to the left of the web address (e.g. examplepage. de) and the use of the https scheme (instead of http) as part of our web address.
If you would like to know more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.
Communication Summary
👥 Data subjects: Anyone who communicates with us by telephone, email or online form
📓 Data processed: e.g. telephone number, name, email address, form data entered. You can find more details on this under the respective contact method
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Retention period: Duration of the business transaction and as required by law
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)( b GDPR (Contract), Art. 6(1)(f) GDPR (Legitimate Interests)
If you contact us and communicate via telephone, email or online form, personal data may be processed.
The data is processed for the handling and processing of your enquiry and the associated business transaction. The data is stored for as long as necessary or for as long as required by law .
The processes described above apply to anyone who contacts us via the communication channels we provide.
When you call us, the call data is stored in pseudonymised form on the relevant device and with the telecommunications provider used. In addition, data such as your name and telephone number may subsequently be sent by email and stored for the purpose of responding to your enquiry. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
If you communicate with us via email, data may be stored on the relevant device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
If you communicate with us via an online form, data will be stored on our web server and, where applicable, forwarded to one of our email addresses. The data will be deleted as soon as the business transaction has been completed and legal requirements permit.
The processing of data is based on the following legal grounds:
In this section, we would like to explain what a Data Processing Agreement is and why it is required. As the term “Data Processing Agreement” is quite a mouthful, we will often use the acronym DPA in the text below. Like most companies, we do not operate in isolation but also make use of services provided by other companies or individuals. By involving various companies or service providers, we may need to pass on personal data for processing. These partners then act as data processors, with whom we enter into a contract known as a Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be governed by the DPA.
As a company and website owner, we are responsible for all data we process from you. In addition to the controllers, there may also be so-called data processors. This includes any company or person who processes personal data on our behalf. More precisely, and according to the GDPR definition: any natural or legal person, public authority, agency or other body which processes personal data on our behalf is considered a data processor. Data processors may therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
To help you better understand the terminology, here is an overview of the three roles in the GDPR:
Data subject (you as a customer or prospective customer) → Data Controller (we as a company and the data controller) → Data Processor (service providers such as web hosts or cloud providers)
As mentioned above, we have concluded . First and foremost, this stipulates that the data processor shall process the data to be processed exclusively in accordance with the GDPR. The contract must be concluded in writing; however, in this context, an electronic contract is also considered to be ‘in writing’. The processing of personal data takes place only on the basis of the contract. The contract must contain the following:
Furthermore, the contract sets out all the obligations of the data processor. The most important obligations are:
You can see what such a DPA looks like in practice, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A sample contract is presented here.
Cookies Summary
👥 Data subjects: Website visitors
🤝 Purpose: Depends on the specific cookie. Further details can be found below or from the software provider that sets the cookie.
📓 Data processed: Depends on the specific cookie used. Further details can be found below or from the software provider that sets the cookie.
📅 Storage period: Depends on the specific cookie; may vary from hours to years
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate interests)
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. To be more precise, they are HTTP cookies, as there are also other types of cookies for different applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, which is essentially the ‘brain’ of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must be specified.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following diagram illustrates a possible interaction between a web browser such as, Chrome, and the web server. In this process, the web browser requests a website and receives a cookie from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, whilst third-party cookies are created by partner websites (e. Google Analytics). Each cookie must be assessed individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programmes and do not contain viruses, Trojans or other ‘malware’. Cookies cannot access information on your PC either.
Here is an example of what cookie data might look like:
Name: _ga
Value: GA1.2.1326744211.152113077832-9
Purpose: To distinguish between website visitors
Expiry date: after 2 years
A browser should be able to support the following minimum sizes:
The specific cookies we use depend on the services employed and are explained in the following sections of the privacy policy. At this point, we would like to briefly outline the different types of HTTP cookies.
There are four types of cookies:
Essential cookies
These cookies are necessary to ensure the website’s basic functions. For example, these cookies are needed when a user adds a product to their basket, then continues browsing other pages and only proceeds to checkout later. These cookies ensure that the shopping basket is not cleared, even if the user closes their browser window.
Performance cookies
These cookies collect information about user behaviour and whether the user receives any error messages. They are also used to measure the website’s loading time and performance across different browsers.
Functional cookies
These cookies improve user-friendliness. For example, they store locations entered, font sizes or form data.
Advertising cookies
These cookies are also known as targeting cookies. They are used to deliver personalised advertising to the user. This can be very useful, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these types of cookies you wish to allow. And, of course, this decision is also stored in a cookie.
If you would like to know more about cookies and are not put off by technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments entitled “HTTP State Management Mechanism”.
The purpose ultimately depends on the specific cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalise about what data is stored in cookies, but we will inform you about the data processed or stored in the context of the following privacy policy.
The storage period depends on the specific cookie and is specified in more detail below. Some cookies are deleted after less than an hour, whilst others may remain stored on a computer for several years.
You also have control over the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below ). Furthermore, cookies based on consent will be deleted at the latest upon withdrawal of your consent, although the lawfulness of their storage up to that point remains unaffected.
You decide for yourself how and whether you wish to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you wish to find out which cookies have been stored in your browser, or if you settings, you can find this information in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies, to remove data that websites have stored on your computer
Internet Explorer: Deleting and managing cookies
Microsoft Edge: Deleting and managing cookies
If you do not wish to have any cookies at all, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It is best to search for instructions on Google using the search term “delete cookies Chrome” or “disable cookies Chrome” if you are using the Chrome browser.
The so-called “Cookie Directive” has been in place since 2009. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). However, reactions to these guidelines still vary greatly across EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive has not been transposed into national law. Instead, the Directive has largely been implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even where no consent has been given, there are legitimate interests (Article 6(1)(f) GDPR), which are of an economic nature in most cases. We wish to provide visitors to the website with a pleasant user experience, and certain cookies are often strictly necessary for this purpose.
Where cookies that are not strictly necessary are used, this is done only with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.
The following sections provide more detailed information on the use of cookies, where the software employed utilises cookies.
Web Hosting Summary
👥 Data subjects: Website visitors
🤝 Purpose: Professional hosting of the website and safeguarding its operation
📓 Data processed: IP address, time of website visit, browser used and other data. Further details can be found below or with the respective web hosting provider.
📅 Retention period: depending on the provider in question, but generally 2 weeks
⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate interests)
When you visit websites nowadays, certain information – including personal data – is automatically generated and stored, as is the case on this website. This data should be processed as sparingly as possible and only for a valid reason. By ‘website’, we mean the entirety of all web pages on a domain, i.e. everything from the home page to the very last subpage (such as this one) . By ‘domain’ we mean, for example, example.de or sampleexample.com.
If you wish to view a website on a computer, tablet or smartphone, you use a programme called a web browser. You are probably familiar with some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We refer to these simply as ‘browsers’ or ‘web browsers’.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Running a web server is a complicated and resource-intensive task, which is why it is usually handled by professional providers. These providers offer web hosting and thus ensure reliable and error-free storage of website data. That’s quite a lot of technical terms, but please bear with us – it gets even better!
When the browser on your computer (desktop, laptop, tablet or smartphone) establishes a connection and during data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a period of time to ensure proper operation.
A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the internet and the hosting provider.
The purposes of data processing are:
Even as you visit our website right now, our web server – that is, the computer on which this website is hosted – usually automatically stores data such as
As a rule, the data mentioned above is stored for two weeks and then automatically deleted. We do not pass this data on to third parties, but cannot rule out the possibility that this data may be accessed by authorities in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without your consent!
The lawfulness of the processing of personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests) , as the use of professional hosting with a provider is necessary to present the company securely and in a user-friendly manner on the internet and, where necessary, to be able to investigate attacks and claims arising therefrom.
As a rule, there is a contract between us and the hosting provider regarding data processing in accordance with Art. 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.
Website Builder Systems Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as technical usage information including browser activity, clickstream activity, session heatmaps, as well as contact details, IP address or your geographical location. Further details can be found below in this privacy policy and in the providers’ privacy policies.
📅 Retention period: depends on the provider
⚖ ️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)
We use a website builder system for our website. Website builder systems are a specific type of content management system (CMS). With a website builder system, website operators can create a website very easily and without any programming knowledge . In many cases, web hosting providers also offer website builders. By using a website builder, your personal data may also be collected, stored and processed. In this privacy notice, we provide you with general information about data processing via website builders. Further details can be found in the provider’s privacy policy.
The biggest advantage of a website builder is its ease of use. We want to offer you a clear, simple and well-organised website that we can easily operate and maintain ourselves – without external support. A website builder now offers many helpful functions that we can use even without any programming knowledge. This allows us to design our website according to our preferences and offer you an informative and enjoyable experience on our site.
Exactly what data is stored naturally depends on the website builder used. Each provider processes and collects different data from website visitors. However, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your visit to the website is usually collected. Furthermore, tracking data (e.g. browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Personal data may also be collected and stored. This usually consists of contact details such as your email address, telephone number (if you have provided it), IP address and geographical location data. You can find out exactly which data is stored in the provider’s privacy policy.
We provide further information below regarding the duration of data processing in connection with the website builder system used, provided we have further details. You can find detailed information on this in the provider’s privacy policy. Generally, we process personal data only for as long as is strictly necessary for the provision of our services and products. It may be the case that the provider stores data about you in accordance with their own policies, over which we have no control.
You always have the right to access, rectify and erase your personal data. If you have any questions, you can also contact the controllers of the website builder system used at any time. You can find contact details either in our privacy policy or on the relevant provider’s website.
You can delete, disable or manage cookies used by providers for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
We have a legitimate interest in using a website builder system to optimise our online service and present it to you in an efficient and user-friendly manner. The relevant legal basis for this is Article 6(1)(f) of the GDPR (legitimate interests). However, we only use the website builder system to the extent that you have given your consent.
Insofar as the processing of data is the operation of the website, the data will only be processed on the basis of your consent. This applies in particular to tracking activities. The legal basis in this respect is Article 6(1)(a) of the GDPR.
With this privacy policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information on this subject, you will find further details – where available – in the following section or in the provider’s privacy policy.
WordPress.com Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as technical usage information (e.g. browser activity, clickstream activity, session heatmaps), as well as contact details, IP address or your geographical location. You can find more details on this further down in this privacy policy.
📅 Retention period: This depends primarily on the type of data stored and the specific settings.
⚖ ️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
The company was founded in 2003 and, in a relatively short time, developed into one of the world’s best-known content management systems (CMS) worldwide. A CMS is software that helps us design our website and present content in an attractive and organised manner. This content may include text, audio and video.
By using WordPress, your personal data may also be collected, stored and processed. As a rule, this mainly involves technical data such as operating system, browser, screen resolution or hosting provider. However, personal data such as IP address, geographical data or contact details may also be processed.
We have many strengths, but actual programming is simply not one of our core competencies.
Nevertheless, we want a high-performance and attractive website that we can manage and maintain ourselves. With a website builder or a content management system like WordPress, this is exactly what is possible. With WordPress, we don’t need to be programming experts to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without prior technical knowledge. Should technical problems ever arise or should we have specific requirements for our website, our specialists – who are well versed in HTML, PHP, CSS and the like – are always on hand.
Thanks to WordPress’s ease of use and comprehensive features, we can design our website to our specifications and offer you a user-friendly experience.
Non-personal data includes technical usage information such as browser activity, clickstream activity, session heatmaps, and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet provider, and the date of your visit.
Personal data is also collected. This primarily consists of contact details (email address or telephone number, if you provide them), IP address or your geographical location.
WordPress may also use cookies to collect data. These often record information about your behaviour on our website. For example, they may record which subpages you particularly like to view, how long you stay on individual pages, when you leave a page (bounce rate) or even which preferences (e.g. language selection ) you have selected. Based on this data, WordPress can also better tailor its own marketing activities to your interests and user behaviour. Consequently, the next time you visit our website, it will be displayed to you as you have previously configured it.
WordPress may also use technologies such as pixel tags (web beacons) to, for example, clearly identify you as a user and potentially offer interest-based advertising.
How long the data is stored depends on various factors. In particular, it depends on the type of data stored and the specific settings of the website. In principle, WordPress deletes the data once it is no longer required for its own purposes. There are, of course, exceptions, particularly where legal obligations require the data to be retained for a longer period. Web server logs, which contain your IP address and technical data, are deleted by WordPress or Automattic after 30 days. For this period, Automattic uses the data to analyse traffic on its own websites (for example, all WordPress sites) and to resolve any potential issues. Deleted content on WordPress websites is also kept in the rubbish bin for 30 days to allow for restoration; after that, it may remain in backups and caches until these are deleted. The data is stored on Automattic’s servers in the US .
You have the right and the option to access your personal data at any time and to object to its use and processing. You may also lodge a complaint with a government supervisory authority at any time.
In your browser, you also have the option to manage cookies individually, delete or deactivate them. Please note, however, that deactivated or deleted cookies may have a negative impact on the functionality of our WordPress site. Depending on which browser you use, managing cookies works slightly differently. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
If you have consented to the use of WordPress, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by WordPress.
We also have a legitimate interest in using WordPress to optimise our online service and present it attractively to you. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use WordPress if you have given your consent.
WordPress and Automattic process your data, including in the USA. Automattic is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Automattic uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Automattic undertakes to comply with European data protection standards when processing your relevant data, even if the data is . These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
Further details on the privacy policy and what data is processed by WordPress and in what manner can be found at https://automattic.com/privacy/.
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded a Data Processing Agreement (DPA). You can read about exactly what a DPA is and, above all, what must be included in a DPA in our general section ‘Data Processing Agreement (DPA)’.
This agreement is required by law because WordPress.com processes personal data on our behalf. It clarifies that WordPress.com may only process data received from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://wordpress.com/support/ data-processing-agreements/.
Web Analytics Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimise the website.
📓 Data processed: Access statistics containing data such as access locations, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses. Further details can be found in the relevant web analytics tool.
📅 Retention period: Depends on the web analytics tool used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use software on our website to analyse the behaviour of website visitors, known as web analytics or web analysis. This involves the collection of data which the respective analytics tool provider (also known as a tracking tool) stores, manages and processes. The data is used to generate analyses of user behaviour on our website, which are then made available to us as the website operator. In addition, most tools offer various testing options. This allows us, for example, to test which offers or content are most popular with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles may also be created and the data stored in cookies.
With our website, we have a clear goal in mind: we want to provide the best online offering on the market for our industry. To achieve this goal, we aim, on the one hand, to offer the best and most interesting content and, on the other hand, to ensure that you feel completely at home on our website. With the help of web analytics tools, we can examine the behaviour of our website visitors in more detail and then improve our website for both you and us accordingly. For example, we can identify the average age of our visitors, where they come from, when our website is most frequently visited, or which content or products are particularly popular. All this information helps us to optimise the website and thus tailor it as closely as possible to your needs, interests and preferences .
Exactly what data is stored naturally depends on the analytics tools used. However, as a rule, the following information is typically stored: what content you view on our website, which buttons or links you click, when you visit a page, which browser you use, which device (PC, tablet, smartphone, etc. ) you use to visit the website, or which computer system you use. If you have consented to the collection of location data, this may also be processed by the web analytics tool provider.
Your IP address is also stored. Under the General Data Protection Regulation (GDPR), IP addresses constitute personal data. However, your IP address is generally stored in pseudonymised form (i.e. in an unrecognisable and truncated form). For the purposes of testing, web analytics and web optimisation, no direct data such as your name, age, address or email address is stored. All such data, where collected, is stored in pseudonymised form. This means you cannot be identified as an individual.
The following example schematically illustrates how Google Analytics works as an example of client-based web tracking using JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data for only a few minutes or until you leave the website, whilst other cookies may store data for several years.
We provide further information on the duration of data processing below, where we have additional details. Generally, we process personal data only for as long as is strictly necessary to provide our services and products. If, as is the case with accounting, this retention period may be exceeded.
You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
The use of web analytics requires your consent, which we have obtained via our cookie pop-up. According to Article 6(1)(a) of the GDPR (Consent), this consent forms the legal basis for the processing of personal data, as may occur during collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of web analytics, we detect website errors, identify attacks and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) GDPR (Legitimate Interests). However, we only use these tools if you have given your consent.
As web analytics tools use cookies, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools is provided – where available – in the following sections.
Jetpack Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Analysis of visitor information to optimise the website.
📓 Data processed: Access statistics containing data such as access locations, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses.
📅 Retention period: until the data is no longer required for the services
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate Interests) (Legitimate interests)
We use the WordPress plug-in Jetpack on our website. Jetpack is software that provides us with web analytics, amongst other things. Jetpack is operated by the company Automattic (Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA), which utilises technology from the company Quantcast (Inc., 201 3rd St, Floor 2, San Francisco, CA 94103-3153, USA) for this product. The integrated tracking tool also collects, stores and processes your personal data. In this privacy policy, we explain exactly what data is involved, why we use Jetpack and how you can prevent this data storage.
Jetpack is a plug-in -in for WordPress websites with many different functions and modules. All these tools help us to make our website more attractive, more secure and enable us to welcome more visitors. For example, the tool can display related posts, content can be shared, and Jetpack can also improve the loading speed of our website. All functions are hosted and provided by WordPress.
It is crucial to us that you feel at home on our website and find what you are looking for. We can only be successful if you are satisfied with our service. And to know how and where we can further improve our website, we need information. Through Jetpack, we can see, for example, how often and for how long you stay on a single webpage, or which buttons you like to click. With the help of this information, we can improve our website and adapt it to your wishes and preferences.
In particular, the built-in tracking tool WordPress.com Statistics collects, stores and processes your personal data. To ensure the Jetpack tool works, Jetpack sets a cookie in your browser when you open a webpage that incorporates components of the tool. The collected data is synchronised with Automattic and stored there.
This includes, in addition to your IP address (which is anonymised before storage) and data on user behaviour, such as browser type, unique device identifier, preferred language, date and time of page visit, operating system and information about the mobile network. Jetpack uses this information to improve its own services and offerings and to gain better insights into the use of its own service. Furthermore, the following data may also be synchronised and stored:
Jetpack also uses cookies for data storage. Below, we show you a few selected examples of cookies used by Jetpack:
Name: eucookielaw
Value: 1613651061376113077832-6
Purpose: Stores the status of the user’s consent to the use of cookies.
Expiry date: after 180 days
Name: tk_ai
Value: 0
Purpose: This cookie stores a randomly generated anonymous ID. It is only used within the admin area to track general analytics.
Expiry date: at the end of the session
Name: tk_tc
Value: E3%2BgJ1Pw6iYKk%2Fvj113077832-3
Purpose: This is a so-called referral cookie. It is used to analyse the connection between WooCommerce and a website with the Jetpack plugin.
Expiry date: at the end of the session
Note: Jetpack uses many different cookies. Which specific cookies are used depends, on the one hand, on the Jetpack features utilised and, on the other hand, on your actions on websites with the Jetpack plugin integrated. At https://de.jetpack.com/support/cookies/ you can view a list of possible cookies used by Jetpack.
Automattic stores the collected data until it is no longer required for its own services. Beyond this period, the data is only retained if the company is legally obliged to do so. Web server logs, such as your IP address, browser type and operating system, are deleted after approximately 30 days. The data is stored on the company’s servers in the United States.
As mentioned above, Jetpack uses cookies to store data. If you do not want Jetpack to collect data from you in future, you can request an ‘opt-out’ cookie at https://www.quantcast.com/opt-out/. Quantcast sets this cookie, which means that no visitor data relating to you will be stored. This remains the case until you delete this cookie.
Alternatively, you can simply manage, disable or delete cookies in your browser as you wish. Cookie management works slightly differently depending on the type of browser. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
The use of Jetpack requires your consent, which we have obtained via our cookie pop-up. This consent constitutes the legal basis for the processing of personal data, as may occur during collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of Jetpack, we detect website errors, identify attacks and improve cost-effectiveness. The legal basis for this is Article 6(1)(f) f GDPR (Legitimate Interests). However, we only use Jetpack if you have given your consent.
Automattic also processes your data in the USA, amongst other places. Jetpack and Automattic are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Automattic uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Automattic undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant standard contractual clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de.
If you would like to find out more about the data protection policies and the processing of data by Jetpack or Automattic, we recommend you read the privacy policy at https://automattic.com/privacy/, the cookie policy at https://automattic.com/cookies/ and also the information page https://jetpack.com/support/ what-data-does-jetpack-sync/. We hope we have been able to provide you with a good insight into data processing by Jetpack.
Email Marketing Summary
👥 Data subjects: Newsletter subscribers
🤝 Purpose: Direct marketing via email, notification of system-related events
📓 Data processed: Data entered during registration, but at least the email address. You can find more details on this in the relevant email marketing tool.
📅 Retention period: For the duration of the subscription
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
To keep you up to date, we also use email marketing. In doing so, provided you have consented to receiving our emails or newsletters, your data will also be processed and stored. Email marketing is a sub-sector of online marketing. It involves sending news or general information about a company, products or services via email to a specific group of people who are interested in them.
If you wish to take part in our email marketing (usually via a newsletter), you normally simply need to register with your email address. To do this, you fill in an online form and submit it. However, we may also ask you for your title and name so that we can address you personally.
Generally, signing up for newsletters works using the so-called “double opt-in procedure”. After you have signed up for our newsletter on our website, you will receive an email to confirm your newsletter subscription. This ensures that the email and that nobody has signed up using someone else’s email address. We, or a notification tool we use, log every single subscription. This is necessary so that we can also provide evidence of a legally correct subscription process. As a rule, the time of subscription, the time of subscription confirmation and your IP address are stored. In addition, any changes to your stored data.
Naturally, we want to stay in touch with you and keep you up to date with the most important news about our company. To this end, we use email marketing – often simply referred to as a “newsletter” – as a key component of our online marketing. Provided you consent to this or it is permitted by law, we will send you newsletters, system emails or other notifications via email. When we use the term “newsletter” in the following text, we mainly mean emails sent out on a regular basis. Naturally, we do not wish to bother you in any way with our newsletters. That is why we always strive to provide only relevant and interesting content. This way, you can find out more about our company, our services or our products. As we are constantly improving our offerings, our newsletter will also keep you informed whenever there is news or we are currently running special, lucrative promotions. Should we engage a service provider offering a professional mailing tool for our email marketing, we do so in order to provide you with fast and secure newsletters. The purpose of our email marketing is fundamentally to inform you about new offers and to help us achieve our business objectives.
If you subscribe to our newsletter via our website, you confirm your membership of an email list via email to your membership of an email list. In addition to your IP address and email address, your title, name, address and telephone number may also be stored. However, this will only occur if you consent to this data being stored. The data marked as such is necessary for you to be able to use the service offered. Providing this information is voluntary; however, failure to do so will mean that you cannot use the service. In addition, information about your device or your preferred content on our website may also be stored. You can find out more about data storage when you visit a website in the section “Automatic data storage”. We record your declaration of consent so that we can always demonstrate that it complies with our laws.
If you unsubscribe your email address from our email/newsletter distribution list, we may store your address for up to three years on the basis of our legitimate interests, so that we can still prove your consent at that time. We may only process this data if we need to defend ourselves against any claims.
However, if you confirm that you have given us your consent to subscribe to the newsletter, you may submit an individual request for deletion at any time. If you permanently withdraw your consent, we reserve the right to store your email address on a block list. As long as you have voluntarily subscribed to our newsletter, we will of course retain your email address.
You can cancel your newsletter subscription at any time. To do so, you simply need to withdraw your consent to the newsletter subscription. This usually takes just a few seconds or one or two clicks. You will usually find a link at the very end of each email to cancel your newsletter subscription. If you really cannot find the link in the newsletter, please contact us by email and we will cancel your newsletter subscription immediately.
Our newsletter is sent on the basis of your consent (Article 6(1)(a) a GDPR). This means that we may only send you a newsletter if you have actively subscribed to it beforehand. Where applicable, we may also send you promotional messages, provided that you have become a customer of ours and have not objected to the use of your email address for direct marketing.
Information on specific email marketing services and how they process personal data can be found – where available – in the following sections.
Social Media Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Presentation and optimisation of our services, contact with visitors, prospective customers, etc., advertising
📓 Data processed: Data such as telephone numbers, email addresses, contact details, user behaviour data, information about your device and your IP address.
You can find more details on this under the respective social media tool used.
📅 Retention period: depending on the social media platforms used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate interests)
In addition to our website, we are also active on various social media platforms. In doing so, user data may be processed so that we can specifically target users who are interested in us via social networks. Furthermore, elements of a social media platform may also be embedded directly into our website. This is the case, for example, when you click on a so-called social media button on our website and are redirected directly to our social media presence. The term ‘social media’ refers to websites and apps through which registered members can produce content, share content openly or within specific groups, and network with other members.
For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to interested parties. The social media elements integrated into our website help you switch to our social media content quickly and without complications.
The data stored and processed through your use of a social media channel is primarily intended to enable web analytics. The aim of these analyses is to develop more precise and personalised marketing and advertising strategies. Depending on your behaviour on a social media platform, the analysed data can be used to draw relevant conclusions about your interests and create so-called user profiles. This also enables platforms to present you with tailored advertisements. In most cases, cookies are set in your browser for this purpose, which store data on your usage behaviour.
We generally assume that we remain responsible under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Article 26 of the GDPR. Where this is the case, we will draw your attention to this separately and operate on the basis of a relevant agreement. The key points of the agreement are then set out below for the platform in question.
Please note that when using social media platforms or our embedded elements, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are American companies. As a result, you may no longer be able to assert or enforce your rights regarding your personal data as easily.
Exactly what data is stored and processed depends on the respective provider of the social media platform. However, it usually involves data such as telephone numbers, email addresses, data you enter into a contact form, user data such as which buttons you click, who you like or follow, when you visited which pages, information about your device and your IP address. Most of this data is stored in cookies. In particular, if you have a profile on the social media channel you are visiting and are logged in, data can be linked to your profile.
All data collected via a social media platform is also stored on the providers’ servers. Consequently, only the providers have access to the data and can provide you with the relevant or make changes.
If you wish to know exactly what data is stored and processed by the social media and how you can object to data processing, you should read the company’s privacy policy carefully. If you have any questions regarding data storage and processing or wish to exercise your rights, we recommend that you contact the provider directly.
We provide further information on the duration of data processing below, where available. For example , the social media platform Facebook stores data until it is no longer required for its own purposes. However, customer data that is matched with the user’s own data is deleted within two days. Generally, we process personal data only for as long as is strictly necessary for the provision of our services and products. If required by law, such as in the case of accounting, this retention period may be exceeded.
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers such as embedded social media elements. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
As social media tools may use cookies, we also recommend that you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
If you have consented to your data being processed and stored via integrated social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, where consent has been given, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining swift and effective communication with you or other customers and business partners. Nevertheless, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
Information on specific social media platforms can be found – where available – in the following sections.
Facebook Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as customer data, user behaviour data, information about your device and your IP address.
You can find more details on this further down in the privacy policy.
📅 Retention period: until the data is no longer useful for Facebook’s purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We use selected Facebook tools on our website. Facebook is a social media network operated by Meta Platforms Inc. or, for the European region, by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. These tools enable us to offer you and others interested in our products and services the best possible experience.
If data is collected from you and forwarded via our embedded Facebook elements or via our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook bears sole responsibility for the further processing of this data. Our joint obligations have also been set out in a publicly accessible agreement at https://www.facebook. com/legal/controller_addendum. This stipulates, for example, that we must clearly inform you about the use of Facebook tools on our site. Furthermore, we are also responsible for ensuring that the tools are integrated into our website in a manner that complies with data protection laws. Facebook, on the other hand, is responsible, for example, for the data security of Facebook products. If you have any questions regarding data collection and processing by Facebook, you can contact the company directly . If you direct your enquiry to us, we are obliged to forward it to Facebook.
Below, we provide an overview of the various Facebook tools, what data is sent to Facebook, and how you can delete this data.
Alongside many other products, Facebook also offers the so-called “Facebook Business Tools”. This is Facebook’s official term. However, as the term is not widely known, we have decided to refer to them simply as Facebook tools. These include, amongst others:
Facebook Pixelsocial plugins (such as the “Like” or “Share” button)Facebook LoginAccount KitAPIs
(Application Programming Interface)SDKs (Software Development Kits)Platform integrationsPluginsCodesSpecificationsDocumentationTechnologies and services
Through these tools, Facebook expands its services and is able to obtain information about user activity outside of Facebook.
We only want to show our services and products to people who are genuinely interested in them. With the help of advertisements (Facebook Ads) we can reach precisely these people. However, in order to show users relevant adverts, Facebook requires information about people’s preferences and needs. Consequently, information about user behaviour (and contact details) on our website is made available to the company. This enables Facebook to collect better user and can display relevant adverts about our products or services to interested people. The tools thus enable tailored advertising campaigns on Facebook.
Facebook refers to data about your behaviour on our website as “event data” . This data is also used for measurement and analysis services. Facebook can thus create “campaign reports” on our behalf regarding the effectiveness of our advertising campaigns. Furthermore, through analysis, we gain a better insight into how you use our services, website or products. This enables us to use some of these tools to optimise your user experience on our website. For example, you can use the social plugins to share content from our site directly on Facebook.
When using individual Facebook tools, personal data (customer data) be sent to Facebook. Depending on the tools used, customer data such as name, address, telephone number and IP address may be transmitted.
Facebook uses this information to match the data with the data it already holds about you (provided you are a Facebook member). Before customer data is transmitted to Facebook, a process known as “hashing” takes place . This means that a data set of any size is transformed into a string of characters. This also serves to encrypt the data.
In addition to contact details, ‘event data’ is also transmitted. ‘Event data’ refers to the information we receive about you on our website. For example, which subpages you visit or which products you purchase from us. Facebook does not share the information received with third parties (such as advertisers), unless the company has explicit permission or is legally obliged to do so. ‘Event data’ can also be linked to contact details. This enables Facebook to offer better personalised advertising. Following the aforementioned matching process, Facebook deletes the contact details.
In order to deliver optimised adverts, Facebook only uses the event data if it has been aggregated with other data (collected by Facebook in other ways). Facebook also uses this event data for security, protection, development and research purposes. Much of this data is transmitted to Facebook via cookies. Cookies are small text files which are used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, different numbers of cookies are created in your browser. We go into more detail about individual Facebook cookies in the descriptions of the individual Facebook tools. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.
In principle, Facebook stores data until it is no longer required for its own services and Facebook products. Facebook has servers located all over the world where its data is stored. However, customer data is deleted within 48 hours after it has been matched with the user’s own data.
In accordance with the General Data Protection Regulation , you have the right to access, rectify, transfer and delete your data.
Your data will only be completely deleted if you delete your Facebook account entirely. Here’s how to delete your Facebook account:
1) Click on ‘Settings’ on the right-hand side of Facebook.
2) Then click on ‘Your Facebook Information’ in the left-hand column.
3) Now click on ‘Deactivation and Deletion’.
4) Select ‘Delete Account’ and then click on ‘Continue and Delete Account’
5) Enter your password, click on “Continue” and then on “Delete Account”
The data that Facebook receives via our site is stored, amongst other things, via cookies (e.g. in social plugins). In your browser, you can disable individual or all cookies, delete or manage individual or all cookies. Depending on which browser you use, this works in different ways. Under the “Cookies” section, you will find the relevant links to the instructions for the most popular browsers.
If you do not wish to have any cookies at all, you can set your browser to always inform you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
If you have consented to your data being processed and stored via integrated Facebook tools, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for the purpose of fast and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and review Facebook’s privacy policy or cookie guidelines.
Facebook also processes your data in the USA, amongst other places. Facebook, or Meta Platforms, is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Facebook uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU -US Data Privacy Framework and the Standard Contractual Clauses, Facebook undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Facebook Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://www.facebook.com/ legal/terms/dataprocessing.
We hope we have provided you with the most important information regarding the use and data processing by Facebook tools. If you would like to find out more about how Facebook uses your data, we recommend you read the data policy at https://www.facebook.com/privacy/policy/.
Instagram Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as user behaviour data, information about your device and your IP address.
Further details can be found below in the privacy policy.
📅 Retention period: until Instagram no longer requires the data for its purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We have integrated Instagram features into our website. Instagram is a social media platform operated by Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and is one of the Facebook products. The integration of Instagram content on our website is known as embedding. This allows us to display content such as buttons, photos or videos from Instagram directly on our website. When you visit pages on our website that have an integrated Instagram feature, data is transmitted to, stored and processed by Instagram. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed across all Facebook companies.
Below, we would like to give you a more detailed insight into why Instagram collects data,
what data is involved, and how you can largely control the processing of this data. As Instagram is part of Meta Platforms Inc., we draw our information from both the Instagram guidelines and the Meta Privacy Policy itself.
Instagram is one of the world’s best-known social media networks. Instagram combines the benefits of a blog with those of audiovisual platforms such as YouTube or Vimeo. On ‘Insta’ (as many users colloquially call the platform) to upload photos and short videos, edit them with various filters, and share them on other social networks. And if you don’t want to be active yourself, you can simply follow other interesting users.
Instagram is the social media platform that has really taken off in recent years. And, of course, we have responded to this boom too. We want you to feel as comfortable as possible on our website. That’s why presenting our content in a varied way is a matter of course for us. Through the embedded Instagram features, we can enrich our content with helpful, funny or exciting content from the world of Instagram. As Instagram is a subsidiary of Facebook, the data collected can also be used for personalised advertising on Facebook. This ensures our adverts only reach people who are genuinely interested in our products or services.
Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics, giving us greater insight into your preferences and interests. It is important to note that these reports do not identify you personally.
When you visit one of our pages that incorporates Instagram features (such as Instagram images or plug-ins ), your browser automatically connects to Instagram’s servers. In doing so, data is sent to Instagram, stored and processed. This happens regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases made, the adverts you see and how you use our service. Furthermore, the date and time of your interaction with Instagram are also stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.
Facebook distinguishes between customer data and event data. We assume that this is also the case with Instagram. Customer data includes, for example, name, address, telephone number and IP address. This customer data will only be transmitted to Instagram once it has been ‘hashed’. Hashing means that a data record is converted into a string of characters. This allows contact details to be encrypted. In addition, the ‘event data’ mentioned above is also transmitted. By ‘event data’, Facebook – and consequently Instagram – means data about your user behaviour. It may also happen that contact details are combined with event data. The contact details collected are matched against the data Instagram already holds about you.
Via small text files (cookies), which are usually stored in your browser, the collected data is transmitted to Facebook. Depending on the Instagram features you use and whether you have an Instagram account yourself, varying amounts of data are stored.
We assume that data processing on Instagram works in the same way as on Facebook. This means: if you have an Instagram account or have visited www.instagram.com, Instagram has set at least one cookie. If this is the case, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram feature. After 90 days at the latest (following synchronisation)
this data will be deleted or anonymised. Although we have looked closely at Instagram’s data processing, we cannot say exactly what data Instagram collects and stores.
Below, we show you the cookies that are set in your browser at the very least when you click on an Instagram feature (such as a button or an Instagram image) . In our test, we assume that you do not have an Instagram account. If you are logged into Instagram, significantly more cookies will of course be set in your browser.
These cookies were used in our test:
Name: csrftoken
Value: “”
Purpose: This cookie is most likely set for security reasons to prevent forged requests. However, we were unable to ascertain this with any greater certainty.
Expiry date: after one year
Name: mid
Value: “”
Purpose: Instagram sets this cookie to optimise its own services and offerings both on and off Instagram. The cookie assigns a unique user ID.
Expiry date: at the end of the session
Name: fbsr_113077832124024
Value: No information
Purpose: This cookie stores the login request for users of the Instagram app.
Expiry date: At the end of the session
Name: rur
Value: ATN
Purpose: This is an Instagram cookie that ensures functionality on Instagram.
Expiry date: At the end of the session
Name: urlgen
Value: “{”194.96.75.33”: 1901}:1iEtYv:Y833k2_UjKvXgYe113077832”
Purpose: This cookie is used for Instagram’s marketing purposes.
Expiry date: at the end of the session
Note: We cannot claim that this list is exhaustive. Which cookies are set in each individual case depends on the embedded features and your use of Instagram.
Instagram shares the information it receives with Facebook companies, external partners and people you connect with worldwide. Data processing is carried out in accordance with its own data policy. Your data is distributed across Facebook servers worldwide, partly for security reasons. Most of these servers are located in the USA.
Thanks to the General Data Protection Regulation, you have the right to access, transfer, rectify and erase your data. You can manage your data in the Instagram settings. If you wish to completely delete your data on Instagram, you must permanently delete your Instagram account.
Here’s how to delete your Instagram account:
First, open the Instagram app. On your profile page, scroll down and tap ‘Help Centre’. This will take you to the company’s website. On the website, click ‘Manage your account’ and then ‘Delete your account ”.
If you delete your account completely, Instagram will delete posts such as your photos and status updates. Information that other people have shared about you does not belong to your account and will therefore not be deleted.
As mentioned above, Instagram primarily stores your data via cookies. You can manage, disable or delete these cookies in your browser. Depending on your browser, the process works slightly differently. Under the “Cookies” section, you will find links to the relevant guides for the most popular browsers.
You can also generally configure your browser so that you are always notified when a cookie is about to be set. You can then decide on a case-by-case basis whether or not to accept the cookie.
If you have consented to your data being processed and stored via embedded social media elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining fast and effective communication with you or other customers and business partners. Nevertheless, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy on cookies carefully and to consult the privacy policy or cookie guidelines of the respective service provider.
Instagram also processes your data in the USA, amongst other places. Instagram and Meta Platforms are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https:// commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Instagram uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the US). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Instagram undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https:// eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
We have tried to provide you with the most important information about data processing by Instagram. You can find out more about Instagram’s data policies at https://privacycenter.instagram.com/policy/.
Security & Anti-Spam Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Cybersecurity
📓 Data processed: Data such as your IP address, name or technical data such as browser version
You can find more details below and in the individual privacy policy texts.
📅 Retention period: In most cases, the data is stored until it is no longer required to fulfil the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
With so-called security & anti spam software, you and we can protect ourselves against various spam or phishing emails and other potential cyberattacks. Spam refers to unsolicited bulk marketing emails that you did not request. Such emails are also known as junk mail and can incur costs. Phishing emails, on the other hand, are messages designed to build trust through fake messages or websites in order to gain access to personal data . Anti-spam software generally protects against unwanted spam messages or malicious emails that could, for example, introduce viruses into our system. We also use general firewall and security systems that protect our computers from unwanted network attacks.
We place particular emphasis on security on our website. After all, it is not just about our security, but above all about yours. Unfortunately, cyber threats have now become part of everyday life in the world of IT and the internet. Hackers often attempt to steal personal data from an IT system using a cyberattack. And that is why a good defence system is absolutely essential. A security system monitors all incoming and outgoing connections to our network or computer. To achieve even greater protection against cyberattacks, we use additional external security services alongside the standardised security systems on our computer. This helps to better prevent unauthorised data traffic, thereby protecting us from cybercrime.
Exactly which data is collected and stored naturally depends on the specific service. However, we always endeavour to use only programmes that collect data sparingly or store only data necessary for the provision of the service offered. In principle, the service may store data such as name, address, IP address, email address and technical data such as browser type or browser version. Performance and log data may be collected to detect potential incoming threats in good time. This data is processed within the scope of the services and in compliance with applicable laws. This also includes, in the case of US providers (via the Standard Contractual Clauses). In some cases, these security services also work with third-party providers who may store and/or process data under instruction and in accordance with the privacy policy and further security measures. Data storage usually takes place via cookies.
We provide further information on the duration of data processing below, where we have additional details. For example, security programmes store data until you or we revoke consent for data storage. Generally, personal data is only stored for as long as is strictly necessary to provide the services. Unfortunately, in many cases we do not have precise information from the providers regarding the duration of storage.
You also have the right and the option to withdraw your consent to the use of cookies or third-party security software providers at any time. This can be done either via our cookie management tool or via other opt
-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser.
As such security services may also use cookies, we recommend you read our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
We implement the security services primarily on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in maintaining a robust security system against various cyberattacks.
Certain processing activities, in particular the use of cookies and security features, require your consent. If you have given your consent, that your data may be processed and stored by integrated security services, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the services we use place cookies in your browser to store data. We therefore recommend that you read our privacy policy on cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
Information on specific tools can be found – where available – in the following sections.
Audio & Video Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
Further details can be found below in the relevant privacy policy texts.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We have integrated audio and video elements into our website so that you can, for example, watch videos or listen to music/podcasts directly via our website. The content is provided by service providers. All content is therefore also sourced from the providers’ respective servers.
These are embedded functional elements from platforms such as YouTube, Vimeo or Spotify. Use of these portals is generally free of charge, although paid content may also be published. With the help of these embedded elements, you can listen to or watch the respective content via our website.
When you use audio or video elements on our website, your personal data may also be transmitted to, processed by and stored.
Naturally, we want to provide you with the best possible experience on our website. And we are aware that content is no longer conveyed solely through text and static images. Instead of simply providing you with a link to a video, we offer audio and video formats directly on our website that are entertaining or informative – and ideally both. This enhances our service and makes it easier for you to access interesting content. Thus, in addition to our texts and images, we also offer video and/or audio content.
When you visit a page on our website that contains, for example, an embedded video, your server connects to the service provider’s server. In the process, data is also transferred from you to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system, and other general information about your device. Furthermore, most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which button you clicked, or via which website you are using the service. All this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymised data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
You can find out exactly how long the data is stored on the third-party providers’ servers either further down in the privacy text for the respective tool or in the provider’s privacy policy. As a general rule, personal data is only processed for as long as is absolutely necessary for the provision of our services or products. This generally applies to third-party providers as well. In most cases, you can assume that certain data will be stored on the third-party providers’ servers for several years. Data can be stored for varying lengths of time, particularly in cookies. Some cookies are deleted as soon as you leave the website, whilst others may remain stored in your browser for several years.
You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser. The lawfulness of the processing up to the point of withdrawal remains unaffected.
As cookies are usually also used through the embedded audio and video functions on our site, you should also read our general privacy policy regarding cookies. You can find out more about the handling and storage of your data in the privacy policies of the respective third-party providers.
If you have consented to your data being processed and stored through embedded audio and video elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for the purpose of ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded audio and video elements to the extent that you have given your consent.
Vimeo Privacy Policy Summary
👥 Data subjects: Website visitors
🤝
Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
You can find more details on this further down in this privacy policy.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6( 1(a) GDPR (consent), Art. 6(1)(f) GDPR (Legitimate interests)
We also use videos from Vimeo on our website. The video portal is operated by Vimeo LLC, 555 West 18th Street, New York, New York 10011, USA. With the help of a plug-in, we can display interesting video content directly on our website. In doing so, certain data relating to you may be transferred to Vimeo. In this privacy policy, we explain what data is involved, why we use Vimeo, and how you can manage or prevent the transfer of your data.
Vimeo is a video platform founded in 2004 that has enabled the streaming of videos in HD quality since 2007. Since 2015, streaming in 4K Ultra HD has also been available. Use of the portal is free of charge, although paid content can also be published. Compared to the market leader YouTube, Vimeo places a primary emphasis on high-quality content. The platform thus offers a wide range of artistic content such as music videos and short films, as well as informative documentaries on a diverse array of topics.
The aim of our website is to to provide you with the best possible content. And to make it as easily accessible as possible. Only when we have achieved this are we satisfied with our service. The video service Vimeo helps us to achieve this goal. Vimeo offers us the opportunity to present high-quality content directly on our website. Instead of simply providing you with a link to an interesting video, you can watch the video straight away on our site. This enhances our service and makes it easier for you to access interesting content. We therefore offer video content in addition to our text and images.
When you visit a page on our website that has an embedded Vimeo video, your browser connects to Vimeo’s servers. This involves a transfer of data. This data is collected, stored and processed on Vimeo’s servers. Regardless of whether you have a Vimeo account or not, Vimeo collects data about you. This includes your IP address, technical information about your browser type, your operating system or very basic device information. Furthermore, Vimeo stores information about which website you are using the Vimeo service on and what actions (web activities) you carry out on our website. These web activities include, for example, session duration, bounce rate or which button you clicked on our website with the built-in Vimeo function. Vimeo can
track and store these actions using cookies and similar technologies.
If you are logged in as a registered member of Vimeo, more data may generally be collected, as more cookies may already have been set in your browser. Furthermore, your actions on our website are directly linked to your Vimeo account. To prevent this, you must log out of Vimeo whilst ‘browsing’ our website.
Below, we list the cookies set by Vimeo when you are on a website with an integrated Vimeo function. This list is not exhaustive and assumes that you do not have a Vimeo account.
Name: player
Value: “”
Purpose: This cookie saves your settings before you play an embedded Vimeo video. This ensures that your preferred settings are restored the next time you watch a Vimeo video.
Expiry date: after one year
Name: vuid
Value: pl1046149876.614422590113077832-4
Purpose: This cookie collects information about your actions on websites that have an embedded Vimeo video.
Expiry date: after 2 years
Note: These two cookies are always set as soon as you visit a website with an embedded Vimeo video. If you watch the video and click the button to, for example, “ share” or “like” the video, for example, further cookies are set. These are also third-party cookies such as _ga or _gat_UA-76641-8 from Google Analytics or _fbp from Facebook. Exactly which cookies are set here depends on your interaction with the video.
The following list shows a selection of possible cookies that are set when you interact with the Vimeo video:
Name: _abexps
Value: %5B% 5D
Purpose: This Vimeo cookie helps Vimeo to remember the settings you have chosen. These may include, for example, a default language, a region or a username. In general, the cookie stores data about how you use Vimeo.
Expiry date: after one year
Name: continuous_play_v3
Value: 1
Purpose: This is a first-party cookie from Vimeo. The cookie collects information on how you use the Vimeo service. For example, the cookie stores when you pause or resume playback of a video.
Expiry date: after one year
Name: _ga
Value: GA1.2.1522249635.1578401280113077832-7
Purpose: This is a third-party cookie from Google. By default, analytics.js uses the _ga cookie to store the user ID.
Essentially, it is used to distinguish between website visitors.
Expiry date: after 2 years
Name: _gcl_au
Value: 1.1.770887836.1578401279113077832-3
Purpose: This third-party cookie from Google AdSense is used to improve the effectiveness of adverts on websites.
Expiry date: after 3 months
Name: _fbp
Value: fb.1.1578401280585.310434968
Purpose: This is a Facebook cookie. This cookie is used to display adverts or promotional from Facebook or other advertisers.
Expiry date: after 3 months
Vimeo uses this data, amongst other things, to improve its own service, to communicate with you and to implement its own targeted advertising measures. Vimeo emphasises on its website that, for embedded videos, only first-party cookies (i.e. cookies from Vimeo itself) are used as long as you do not interact with the video.
Vimeo is headquartered in White Plains, New York (USA). However, its services are offered worldwide. In doing so, the company uses computer systems, databases and servers in the USA and in other countries. Your data may therefore also be stored and processed on servers in America. The data remains stored at Vimeo until the company no longer has a business reason for storing it. The data is then deleted or anonymised.
You always have the option to manage cookies in your browser according to your preferences. For example, if you do not want Vimeo to set cookies and thus collect information about you, you can delete or disable cookies in your browser settings at any time. The process varies slightly depending on your browser. Please note that after disabling or deleting cookies, various functions may no longer be available to their full extent. Under the ‘Cookies’ section, you will find links to the relevant guides for the most popular browsers.
If you are a registered Vimeo member, you can also manage on Vimeo.
If you have consented to your data being processed and stored by embedded Vimeo elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in ensuring fast and effective communication with you or other customers and business partners. However, we only use the embedded Vimeo elements to the extent that you have given your consent. Vimeo also sets cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider .
Vimeo processes your data, a. in the USA. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This may entail various risks regarding the lawfulness and security of data processing.
As the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or for data transfers to those countries, Vimeo uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through these clauses, Vimeo undertakes, when processing your relevant data, to comply with European data protection standards, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/ oj?locale=de
You can find more information on Vimeo’s standard contractual clauses at https://vimeo.com/privacy#international_data_transfers_and_certain_user_rights.
You can find out more about Vimeo’s use of cookies at https://vimeo.com/cookie_policy, and read about Vimeo’s data protection policy at https://vimeo.com/privacy.
YouTube Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
You can find more details on this further down in this privacy policy.
📅 Retention period: Data is generally stored for as long as it is necessary for the purpose of the service
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We have embedded YouTube videos on our website. This allows us to present interesting videos directly on our site. YouTube is a video portal that has been a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. In the process, various data is transmitted (depending on your settings). Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing within the European Union.
Below, we would like to explain in more detail what data is processed, why we have embedded YouTube
videos and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on and upload videos free of charge. Over the last few years, YouTube has become one of the most important social media channels worldwide. To enable us to display videos on our website, YouTube provides a code snippet which we have embedded on our site.
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our website. And, of course, interesting videos are a must. With the help of our embedded videos, we provide you with further helpful content alongside our text and images. Furthermore, the embedded videos make our website easier to find on the Google search engine. Even when we place adverts via Google Ads, Google – thanks to the data collected – only show these adverts to people who are genuinely interested in our offers.
As soon as you visit one of our pages that has a YouTube video embedded, YouTube sets at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually link your interactions on our website to your profile using cookies . This includes data such as session duration, bounce rate, approximate location, and technical information such as browser type, screen resolution or your internet service provider. Other data may include contact details, any ratings, sharing content via social media or adding it to your favourites on YouTube.
If you are not logged into a Google account or a YouTube account, Google stores data using a unique identifier which is linked to your device, browser or app. This ensures, for example, that your preferred language setting is retained. However, much interaction data cannot be stored as fewer cookies are set.
In the list below, we show cookies which were set in a browser test. On the one hand, we show cookies that are set without a logged-in YouTube account. On the other hand, we show cookies that are set with a logged-in account. The list cannot claim to be exhaustive, as user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y113077832-1
Purpose: This cookie records a unique ID to store statistics on the video viewed.
Expiry date: at the end of the session
Name: PREF
Value: f1=50000000
Purpose: This cookie also records your unique ID. Google uses PREF to obtain statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).
Expiry date: after 8 months
Additional cookies that are set when you are logged in to your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7113077832-
Purpose: This cookie is used to create a profile of your interests. The data is used for personalised advertisements.
Expiry date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user’s consent to use various Google services. CONSENT also serves security purposes, to verify users and protect user data from unauthorised attacks.
Expiry date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile of your interests. This data helps to display personalised advertising.
Expiry date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login details.
Expiry date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.
Expiry date: after 2 years
Name: SID
Value: oQfNKjAsI113077832 -
Purpose: This cookie stores your Google account ID and the time of your last login in a digitally signed and encrypted form.
Expiry date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and what adverts you may have seen before visiting our site.
Expiry date: after 3 months
The data that YouTube receives from you and processes is stored on Google’s servers. Most of these servers are located in the United States. At https://datacenters.google/ you can see exactly where Google’s data centres are located. Your data is distributed across the servers. This makes the data quicker to access and better protected against tampering.
Google stores the collected data for varying lengths of time. You can delete some data at any time, other data is automatically deleted after a limited period, and yet other data is stored by Google for a longer period. Some data (such as items from ‘My Activity’, photos or documents, products) stored in your Google Account remains there until you delete it. Even if you are not signed in to a Google Account, you can delete some data linked to your device, browser or app.
In principle, you can delete data manually in your Google Account. With the automatic deletion feature for location and activity data introduced in 2019, information is stored for either 3 or 18 months, depending on your choice, and then deleted.
Regardless of whether you have a Google account or not, you can configure your browser to delete or disable Google cookies. Depending on which browser you use, this works in different ways. Under the ‘Cookies’ section, you will find the relevant links to the instructions for the most popular browsers.
If you do not wish to accept cookies at all, you can set your browser to always notify you when a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not.
If you have consented to your data being processed and stored by embedded YouTube elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In general, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in maintaining swift and effective communication with you or other customers and business partners. We use the embedded YouTube elements only to the extent that you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you read our privacy policy regarding cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.
YouTube also processes your data in the USA, amongst other places. YouTube and Google are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60 -be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards, even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur-lex.europa.
eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
As YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to find out more about how your data is handled, we recommend you read the privacy policy at https://policies.google.com/privacy?hl=de.
We have incorporated the YouTube Subscribe Button . You can usually recognise the button by the classic YouTube logo. The logo displays the words ‘Subscribe’ or ‘YouTube’ in white text on a red background, with the white ‘Play’ icon to the left of it. However, the button may also appear in a different design.
Our YouTube channel regularly offers you funny, interesting or exciting videos. With the embedded “Subscribe” button, you can subscribe to our channel directly from our website and do not need to visit the YouTube website separately. We therefore want to make accessing our comprehensive content as easy as possible for you. Please note that this allows YouTube to store and process data about you.
If you see a built-in subscribe button on our site, YouTube – according to Google – sets at least one cookie. This cookie stores your IP address and our URL. YouTube can also obtain information about your browser, your approximate location and your default language in this way. During our test, the following four cookies were set without being logged in to YouTube:
Name: YSC
Value: b9-CV6ojI5113077832Y
Purpose: This cookie records a unique ID to store statistics on the video viewed.
Expiry date: at the end of the session
Name: PREF
Value: f1=50000000
Purpose: This cookie also records your unique ID. Google uses PREF to obtain statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie records your unique ID on mobile devices to track your GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 11307783295Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).
Expiry date: after 8 months
Note: These cookies were set following a test and not claim to be exhaustive.
If you are logged into your YouTube account, YouTube can use cookies to record many of your actions/interactions on our website and associate them with your YouTube account.
For example, YouTube thereby receives information such as how long you spend on our site, what type of browser you use, what screen resolution you prefer, or what actions you perform.
YouTube uses this data both to improve its own services and offerings, and to provide analytics and statistics for advertisers (who use Google Ads).
Web Design Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: To improve the user experience
📓 Data processed: The data processed depends heavily on the services used. This usually includes IP address, technical data, language settings, browser version, screen resolution and browser name. You can find more details on this under the respective web design tools used.
📅 Retention period: depends on the tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use various tools on our website to support our web design. Web design is not, as is often assumed, merely about making our website look attractive, but also about functionality and performance. But of course, achieving the right look for a website is also one of the main goals of professional web design. Web design is a sub-field of media design and deals with the visual, structural and functional design of a website. The aim is to use web design to improve your experience on our website. In web design jargon, the terms ‘user experience’ (UX) and ‘usability’ are used in this context. User experience refers to all the impressions and experiences a website visitor has whilst on a website. Usability is a sub-category of user experience. This concerns the user-friendliness of a website. The main focus here is on ensuring that content, subpages or products are clearly structured and that you can find what you are looking for quickly and easily. To offer you the best possible experience on our website, we also use so-called third-party web design tools. In this privacy policy, the category ‘web design’ therefore covers all services that improve the design of our website. These may include, for example, fonts, various plugins or other integrated web design features.
How you take in information on a website depends very much on the structure, functionality and visual presentation of the website. That is why a good and professional web design has become increasingly important to us too. We are constantly working to improve our website and see this as an added service for you as a website visitor. Furthermore, an attractive and functional website also has economic benefits for us. After all, you will only visit us and make use of our services if you feel completely at ease.
When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data this involves naturally depends heavily on the tools used. Below, you can see exactly which tools we use for our website. For further information on data processing, we also recommend that you read the respective privacy policy of the tools used. There you will usually find out what data is processed, whether cookies are used and how long the data is retained. Through fonts such as Google Fonts, for example, information such as language settings, IP address, browser version, browser screen resolution
and the browser name are automatically transmitted to Google’s servers.
The length of time data is processed varies greatly and depends on the web design elements used. If cookies are used, for example, the retention period may be as short as one minute or as long as a few years. Please do your own research on this matter. We recommend that you consult both our general section on cookies and the privacy policies of the tools used. There you will usually find out exactly which cookies are used and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. In principle, data is only retained for as long as is necessary to provide the service. Data may also be stored for longer where required by law.
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or via other opt-out functions. You can also prevent data collection via cookies by managing, disabling or deleting cookies in your browser. However, under web design elements (mostly in the case of fonts), however, there is also data that cannot be deleted quite so easily. This is the case when data is automatically collected directly when a page is loaded and transmitted to a third-party provider (such as Google). In such cases, please contact the support team of the relevant provider. In the case of Google, you can reach support at https://support.google.com/?hl=de.
If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) 1(a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur during collection by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The relevant legal basis for this is Article 6(1)(f) GDPR (Legitimate Interests). However, we only use web design tools if you have given your consent. We would like to emphasise this point once again here.
Information on specific web design tools is provided – where available – in the following sections.
We use Adobe Fonts, a web font hosting service, on our website. The service provider is the American company Adobe Inc. For the European region, the Irish company Adobe Systems Software Ireland Companies, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland, is responsible.
Adobe processes your data, among other things, in the USA. Adobe is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/
fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Adobe uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR) . Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are designed to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Adobe undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant Standard Contractual Clauses here, amongst other places: https://eur -lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find more information on Adobe’s standard contractual clauses at https:// www.adobe.com/at/privacy/eudatatransfers.html.
You can find out more about the data processed through the use of Adobe Fonts in the Privacy Policy at https://www.adobe.com/at/privacy.html .
Google Fonts Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as IP address and CSS and font requests
Further details can be found below in this privacy policy.
📅 Retention period: Font files are stored by Google for one year
⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
We use Google Fonts on our website. These are the “Google fonts” provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.
You do not need to register or provide a password to use Google Fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic. com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google whilst using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used, and stores this data securely. We will look at exactly how this data is stored in more detail later.
Google Fonts (formerly Google Web Fonts) is a directory containing over 800 fonts that Google makes available to its users free of charge.
Many of these fonts are published under the SIL Open Font License, whilst others have been released under the Apache Licence. Both are free software licences.
With Google Fonts, we can use fonts on our own website without having to upload them to our own server. Google Fonts is a key component in maintaining the high quality of our website. All Google fonts are automatically optimised for the web, which saves data volume and is particularly use on mobile devices. When you visit our site, the small file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Different rendering systems in various browsers, operating systems and mobile devices can lead to errors. Such errors can sometimes cause text or entire web pages to appear distorted. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We therefore use Google Fonts so that we can present our entire online service as attractively and consistently as possible.
When you visit our website, the fonts are loaded via a Google server. This external request transmits data to the Google servers. This is how Google recognises that you, or rather your IP address, are visiting our website. The Google Fonts API was developed to limit the use, storage and collection of end-user data to what is necessary for the proper provision of fonts. Incidentally, API stands for ‘Application Programming Interface’ and serves, amongst other things, as a data transmitter in the software sector.
Google Fonts securely stores CSS and font requests on Google’s servers, ensuring they are protected. Through the usage statistics collected, Google can determine how well the individual fonts are received. Google publishes the results on internal analytics pages, such as Google Analytics. Google also uses data from its own web crawler to identify which websites use Google Fonts. This data is published in the Google Fonts BigQuery database. Entrepreneurs and developers use the Google web service BigQuery to analyse and process large volumes of data.
It should also be borne in mind, however, that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution and browser name. It is not clear whether this data is also stored, nor is this explicitly communicated by Google.
Google stores requests for CSS assets on its servers for one day; these servers are mainly located outside the EU. This enables us to use the fonts with the help of a Google stylesheet. A stylesheet is a template that allows you to quickly and easily change, for example, the design or font of a website.
The font files are stored by Google for one year. Google’s aim is to improve website loading times across the board. When millions of websites reference the same fonts, they are cached after the first visit and appear immediately on all other websites visited subsequently. Google sometimes updates font files to reduce file size, increase language coverage and improve design.
Data that Google stores for a day or a year cannot simply be deleted. The data is automatically transmitted to Google when the page is loaded. To delete this data early, you must contact Google Support at https:/ /support.google.com/?hl=en&tid=113077832. In this case, you can only prevent data storage by not visiting our site.
Unlike other web fonts, Google grants us unrestricted access to all fonts. We can therefore access an unlimited range of fonts and thus get the most out of our website. You can find out more about Google Fonts and other questions at https://developers.google.com/fonts/faq?tid=113077832. Although Google addresses data protection issues there, it does not provide truly detailed information on data storage is not provided. It is relatively difficult to obtain truly precise information from Google regarding stored data.
If you have consented to the use of Google Fonts, this consent forms the legal basis for the corresponding data processing. According to Article 6(1)(a) of the GDPR (Consent), this consent forms the legal basis for the processing of personal data, as may occur during collection via Google Fonts.
We also have a legitimate interest in using Google Fonts to optimise our online service. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use Google Fonts to the extent that you have .
Google also processes your data in the USA, amongst other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d -4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model clauses provided by the European Commission and are intended to ensure that your data continues to comply with European data protection standards even when it is transferred to third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the relevant standard contractual clauses here, amongst other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business. safety.google/intl/de/adsprocessorterms/.
You can also read about what data Google generally collects and how this data is used at https://www.google.com/intl/de/policies/privacy/.
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, particularly when dealing with technical and legal matters. It often makes sense to use legal terms (such as personal data) or specific technical expressions (such as cookies, IP address). However, we do not wish to use these without explanation. Below you will find an alphabetical list of important terms used which we may not have covered sufficiently in the previous privacy policy. Where these terms are taken from the GDPR and constitute definitions, we will also quote the relevant GDPR text here and, where appropriate, add our own explanations.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“Supervisory authority” means an independent public authority established by a Member State in accordance with Article 51;
Explanation: “Supervisory authorities” are always independent public bodies which, in certain cases, also have the power to issue instructions. They are responsible for carrying out so-called state supervision and are located within ministries, special departments or other authorities. In Austria, there is an Austrian Data Protection Authority; in Germany, each federal state has its own data protection authority.
Definition pursuant to Article 4 of the GDPR GDPR
For the purposes of this Regulation, the term:
“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to the controllers, there may also be so-called data processors. This includes any company or person that processes personal data on our behalf. Data processors may therefore include, in addition to service providers such as tax advisors, hosting or cloud providers, payment or newsletter or large companies such as Google or Microsoft.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
‘consent’ of the data subject means any freely given, specific, in an informed and unambiguous manner, in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that they agree to the processing of personal data relating to them;
Explanation: On websites, such consent is usually obtained via a cookie consent
tool. You are no doubt familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also configure individual settings and thus decide for yourself which data processing you permit and which you do not. If you do not consent, no personal data relating to you may be processed. In principle, consent may of course also be given in writing, i.e. not via a tool, .
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
‘recipient’ means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a specific inquiry mandate under Union or Member State law shall not be regarded not as recipients; the processing of such data by the aforementioned authorities shall be carried out in accordance with the applicable data protection regulations in line with the purposes of the processing;
Explanation: Any person or company that receives personal data is considered a recipient. Consequently, we and our processors are also so-called recipients. Only public authorities carrying out an investigative mandate are not considered recipients.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data therefore comprises all data that can be used to identify you as a person. This generally includes data such as:
According to the European Court of Justice (ECJ), your IP address also counts as personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, you as the account holder. Therefore, the storage of an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that are particularly worthy of protection. These include:
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and are therefore the “controller”. If we pass on collected data to other service providers for processing, these are “data processors”. A “Data Processing Agreement (DPA)” must be signed for this purpose.
Definition pursuant to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“processing” any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction , erasure or destruction;
Note: When we refer to processing in our privacy policy, we mean any form of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.
Congratulations! If you are reading this, you have really ‘battled’ your way through our entire privacy policy, or at least scrolled down to this point. As you can see from the length of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, however, we do not merely wish to tell you which data is processed, but also to explain the reasons behind the use of various software programmes. Privacy policies usually sound very technical and legal. However, as most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this is not always possible given the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the data controller. We hope you enjoy your visit and look forward to welcoming you back to our website soon.
All texts are protected by copyright.
Source: Privacy Policy created using the Privacy Policy Generator for Austria by AdSimple