Privacy Statement
Data Protection Policy
Preamble
This Privacy Policy is intended to inform you about the types of personal data concerning you (hereinafter also referred to simply as “data”) that we process, the purposes for which we process such data and the extent of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “Online Offering”).
The terms used are gender-neutral.
Last updated: 5 March 2025
Contents
Preamble
Controller
Data Protection Officer Contact Details
Overview of Processing Activities
Relevant Legal Bases
Security Measures
Disclosure of Personal Data
International Data Transfers
General Information on Data Retention and Erasure
Rights of Data Subjects
Business Services
Business Processes and Procedures
Provision of the Online Offering and Web Hosting
Use of Cookies
Contact and Enquiry Management
Communication via Messenger Services
Video Conferences, Online Meetings, Webinars and Screen Sharing
Web Analytics, Monitoring and Optimisation
Online Marketing
Social Media Presences
Plug-ins, Embedded Functions and Content
Application Process
Privacy Information for Whistleblowers
Changes and Updates
Definitions
Controller
Brandenburger Isoliertechnik GmbH & Co. KG
Dipl.-Ing. Peter Schwab
Taubensuhlstr. 6
76829 Landau
brandenburger-isoliertechnik.com
Email address: p.schwab@brandenburger.de
Telephone: +49 (0) 6341 5104 – 0
Legal notice: https://brandenburger-group.de/impressum/
Data Protection Officer Contact Details
We have appointed a Data Protection Officer, who may be contacted directly at:
QS-Kornmann GmbH
Sudetenstrasse 33
35625 Hüttenberg
Germany
Telephone: 06403 9295287
Email: dsb@qs-kornmann.de
Overview of Processing Activities
The following overview summarises the categories of data processed, the purposes for which they are processed and the categories of data subjects concerned.
Categories of Data Processed
Master data.
Employee data.
Payment data.
Contact data.
Content data.
Contract data.
Usage data.
Meta, communication and procedural data.
Applicant data.
Image and/or video recordings.
Audio recordings.
Event data (Facebook).
Log data.
Categories of Data Subjects
Recipients and clients of services.
Employees.
Prospective customers and other interested parties.
Communication partners.
Users.
Applicants.
Business and contractual partners.
Persons depicted.
Third parties.
Whistleblowers.
Customers.
Purposes of Processing
Provision of contractual services and fulfilment of contractual obligations.
Communication.
Security measures.
Direct marketing.
Audience measurement.
Tracking.
Office and organisational procedures.
Conversion measurement.
Click tracking.
Audience targeting.
A/B testing.
Organisational and administrative procedures.
Application process.
Feedback.
Heatmaps.
Marketing.
Profiles containing user-related information.
Provision of our Online Offering and user-friendliness.
Information technology infrastructure.
Whistleblower protection.
Financial and payment management.
Public relations.
Sales promotion.
Business processes and commercial procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR: The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection legislation may apply in your or our country of residence or establishment. Where more specific legal bases apply in individual cases, we will identify them in this Privacy Policy.
Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of personal data relating to them for one or more specified purposes.
Performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Compliance with a legal obligation (Article 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
Application process as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR) – Where special categories of personal data within the meaning of Article 9(1) GDPR (for example, health data such as information concerning severe disability, or data concerning ethnic origin) are requested from applicants during the application process so that the controller or the data subject may exercise rights and comply with obligations arising from employment law and the law governing social security and social protection, such data are processed in accordance with Article 9(2)(b) GDPR; where processing is necessary to protect the vital interests of applicants or other persons, in accordance with Article 9(2)(c) GDPR; or for the purposes of preventive or occupational medicine, the assessment of an employee’s working capacity, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services, in accordance with Article 9(2)(h) GDPR. Where special categories of data are disclosed on the basis of voluntary consent, they are processed on the basis of Article 9(2)(a) GDPR.
National data protection legislation in Germany: In addition to the data protection provisions of the GDPR, national data protection legislation applies in Germany. This includes, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions concerning, in particular, the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers and automated individual decision-making, including profiling. The data protection laws of the individual German federal states may also apply.
Security Measures
In accordance with the statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, securing the availability of and separation of the data. We have also established procedures to ensure that data subjects may exercise their rights, that data are erased and that appropriate responses are made to threats to the data. Furthermore, we take the protection of personal data into account from the development or selection stage of hardware, software and procedures, in accordance with the principles of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are fundamental technologies for secure data transmission on the internet. These technologies encrypt the information transmitted between the website or application and the user’s browser, or between two servers, thereby protecting the data against unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. Where a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This provides users with an indication that their data are transmitted securely and in encrypted form.
Disclosure of Personal Data
In the course of processing personal data, we may transfer such data to, or otherwise disclose them to, other bodies, companies, legally independent organisational units or persons. Recipients of such data may include, for example, service providers commissioned to perform IT-related tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude appropriate contracts or arrangements with the recipients of the data in order to protect your data.
Data transfers within the group of companies: We may transfer personal data to other companies within our group or grant them access to such data. This sharing of data is based on our legitimate corporate and commercial interests. These include, for example, improving business processes, ensuring efficient and effective internal communication, making optimum use of our personnel and technological resources and enabling informed business decisions. In certain cases, sharing the data may also be necessary in order to fulfil our contractual obligations, or it may be based on the data subject’s consent or another statutory authorisation.
International Data Transfers
Processing of data in third countries: Where we process data in a third country, that is, outside the European Union (EU) or the European Economic Area (EEA), or where processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies, this is carried out only in accordance with the statutory requirements. Where the level of data protection in the third country has been recognised by means of an adequacy decision (Article 45 GDPR), that decision serves as the basis for the transfer. Otherwise, data are transferred only where an adequate level of data protection is ensured by other means, in particular through Standard Contractual Clauses (Article 46(2)(c) GDPR), explicit consent or where the transfer is necessary for contractual or statutory reasons (Article 49(1) GDPR). We also identify the basis for transfers to third countries in the information provided for the individual providers established in those countries, with adequacy decisions taking precedence as a legal basis. Information on transfers to third countries and existing adequacy decisions is available from the European Commission at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de. Under the EU–US Data Privacy Framework (DPF), the European Commission has also recognised an adequate level of data protection for certain companies in the United States by means of its adequacy decision of 10 July 2023. A list of certified companies and further information on the DPF are available in English on the website of the United States Department of Commerce at https://www.dataprivacyframework.gov/. Within this Privacy Policy, we identify which service providers used by us are certified under the Data Privacy Framework.
General Information on Data Retention and Erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or no other legal basis for processing remains. This applies where the original purpose of processing no longer applies or the data are no longer required. Exceptions apply where statutory obligations or particular interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax-law purposes, or whose retention is necessary for the establishment, exercise or defence of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy information contains additional information on the retention and erasure of data applicable specifically to certain processing activities.
Where more than one retention period or erasure deadline is specified for an item of data, the longest period will always apply.
Where a period does not expressly commence on a specific date and is at least one year in duration, it will automatically commence at the end of the calendar year in which the event triggering the period occurred. In the case of an ongoing contractual relationship in connection with which data are stored, the event triggering the period is the date on which notice of termination takes effect or the legal relationship otherwise ends.
Data that are no longer retained for their originally intended purpose but must be retained on the basis of statutory requirements or for other reasons are processed solely for the purposes that justify their retention.
Further information on processing activities, procedures and services:
Retention and erasure of data: The following general periods apply to retention and archiving under German law:
10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the operating instructions and other organisational documents required in order to understand them (Section 147(1) no. 1 in conjunction with Section 147(3) of the German Fiscal Code (AO), Section 14b(1) of the German Value Added Tax Act (UStG), and Section 257(1) no. 1 in conjunction with Section 257(4) of the German Commercial Code (HGB)).
8 years – Accounting records, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with Section 147(3), first sentence, AO, and Section 257(1) no. 4 in conjunction with Section 257(4) HGB).
6 years – Other business records: commercial or business correspondence received, copies of commercial or business correspondence sent and other documents relevant for taxation, such as hourly wage records, cost accounting sheets, calculation documents and price lists, as well as payroll records where they do not already constitute accounting records, and till receipts (Section 147(1) nos. 2, 3 and 5 in conjunction with Section 147(3) AO, and Section 257(1) nos. 2 and 3 in conjunction with Section 257(4) HGB).
3 years – Data required in order to consider potential warranty and damages claims, or similar contractual claims and rights, and to process related enquiries are retained for the standard statutory limitation period of three years on the basis of previous business experience and customary industry practice (Sections 195 and 199 of the German Civil Code (BGB)).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data relating to you which is based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where personal data relating to you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data relating to you for such marketing, including profiling to the extent that it is related to such direct marketing.
Right to withdraw consent: You have the right to withdraw consent at any time.
Right of access: You have the right to obtain confirmation as to whether personal data relating to you are being processed and, where that is the case, access to those data, together with further information and a copy of the data, in accordance with the statutory requirements.
Right to rectification: In accordance with the statutory requirements, you have the right to request the completion of data relating to you or the rectification of inaccurate data relating to you.
Right to erasure and restriction of processing: In accordance with the statutory requirements, you have the right to request the erasure of data relating to you without undue delay or, alternatively, to request restriction of the processing of those data.
Right to data portability: In accordance with the statutory requirements, you have the right to receive data relating to you which you have provided to us in a structured, commonly used and machine-readable format, or to request that those data be transmitted to another controller.
Right to lodge a complaint with a supervisory authority: In accordance with the statutory requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, where you consider that the processing of personal data relating to you infringes the GDPR.
Business Services
We process data relating to our contractual and business partners, such as customers and prospective customers (collectively referred to as “Contractual Partners”), within the context of contractual and comparable legal relationships and associated measures, and for the purpose of communicating with the Contractual Partners, including prior to entering into a contract, for example in order to respond to enquiries.
We use these data in order to fulfil our contractual obligations. These include, in particular, obligations to provide the agreed services, any updating obligations and remedies in the event of warranty claims or other failures in performance. In addition, we use the data to safeguard our rights and for administrative tasks and corporate organisation associated with these obligations. We also process the data on the basis of our legitimate interests in proper and commercially sound business management and in security measures designed to protect our Contractual Partners and our business operations against misuse and threats to their data, confidential information, information and rights, for example through the involvement of telecommunications, transport and other ancillary service providers, subcontractors, banks, tax advisers, legal advisers, payment service providers or tax authorities. Within the limits of applicable law, we disclose the data of Contractual Partners to third parties only to the extent necessary for the above purposes or to comply with legal obligations. Contractual Partners are informed of other forms of processing, such as processing for marketing purposes, in this Privacy Policy.
We inform Contractual Partners of the data required for the above purposes before or at the time of collection, for example in online forms, by means of specific markings such as colours or symbols such as asterisks, or in person.
We erase the data once statutory warranty and comparable obligations have expired, generally after four years, unless the data are stored in a customer account, for example for as long as they must be retained for statutory archiving purposes, usually ten years for tax purposes. Data disclosed to us by a Contractual Partner in connection with an instruction are erased in accordance with the Contractual Partner’s instructions and, as a general rule, upon completion of the instruction.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); payment data (for example, bank details, invoices and payment history); contact data (for example, postal and email addresses or telephone numbers); contract data (for example, subject matter of the contract, term and customer category).
Data subjects: Recipients and clients of services; prospective customers and other interested parties; business and contractual partners.
Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures; business processes and commercial procedures.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal bases: Performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Technical services: We process the data of our customers and clients (hereinafter collectively referred to as “Customers”) in order to enable them to select, purchase or commission the chosen services or works and associated activities, as well as to pay for and receive, have performed or otherwise obtain those services or works.
The required information is identified as such when an order, purchase or comparable contract is concluded and includes the information required for the provision of services and billing, as well as contact details required for any follow-up queries. Where we gain access to information concerning end customers, employees or other persons, we process such information in accordance with the statutory and contractual requirements; legal basis: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR).
Business Processes and Procedures
Personal data relating to recipients and clients of services – including customers, clients or, in specific cases, principals, patients or business partners, as well as other third parties – are processed in the context of contractual and comparable legal relationships and pre-contractual measures, such as the initiation of business relationships. This processing supports and facilitates commercial operations in areas such as customer management, sales, payments, accounting and project management.
The data collected are used to fulfil contractual obligations and organise operational processes efficiently. This includes processing business transactions, managing customer relationships, optimising sales strategies and ensuring internal accounting and financial processes. In addition, the data support the protection of the controller’s rights and facilitate administrative tasks and the organisation of the company.
Personal data may be disclosed to third parties where this is necessary to fulfil the stated purposes or comply with statutory obligations. The data are erased after statutory retention periods have expired or where the purpose of processing no longer applies. This also includes data that must be retained for longer periods on account of tax-law and statutory documentary obligations.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); payment data (for example, bank details, invoices and payment history); contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); contract data (for example, subject matter of the contract, term and customer category); log data (for example, log files concerning log-ins, retrieval of data or access times); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved); employee data (information concerning employees and other persons in an employment relationship).
Data subjects: Recipients and clients of services; prospective customers and other interested parties; communication partners; business and contractual partners; third parties; users (for example, website visitors and users of online services); employees (for example, members of staff, applicants, temporary workers and other workers); customers.
Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; business processes and commercial procedures; communication; marketing; sales promotion; public relations; financial and payment management; information technology infrastructure (operation and provision of information systems and technical equipment, such as computers and servers).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal bases: Performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR).
Further information on processing activities, procedures and services:
Customer management and customer relationship management (CRM): Procedures required for customer management and customer relationship management (CRM), for example customer acquisition in compliance with data protection requirements, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with due regard to data protection, data management and analysis to support customer relationships, administration of CRM systems, secure account management, customer segmentation and audience targeting; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Contact management and maintenance: Procedures required for the organisation, maintenance and safeguarding of contact information, for example establishing and maintaining a central contact database, regularly updating contact information, monitoring data integrity, implementing data protection measures, ensuring access controls, backing up and restoring contact data, training employees in the effective use of contact management software, regularly reviewing communication history and adapting contact strategies; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
General payment transactions: Procedures required for carrying out payment transactions, monitoring bank accounts and controlling payment flows, for example preparing and checking bank transfers, processing direct debits, reviewing bank statements, monitoring incoming and outgoing payments, managing returned direct debits, reconciling accounts and cash management; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Accounting, accounts payable and accounts receivable: Procedures required for recording, processing and checking business transactions in accounts payable and accounts receivable, for example preparing and checking incoming and outgoing invoices, monitoring and managing outstanding items, carrying out payment transactions, managing reminders and collection, reconciling receivables and liabilities, accounts payable and accounts receivable; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Financial accounting and tax: Procedures required for recording, administering and monitoring financially relevant business transactions and for calculating, reporting and paying taxes, for example coding and posting business transactions, preparing quarterly and annual financial statements, carrying out payment transactions, managing reminders and collection, reconciling accounts, obtaining tax advice, preparing and filing tax returns and handling tax matters; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Sales: Procedures required for planning, carrying out and monitoring measures to market and sell products or services, for example customer acquisition, preparing and following up quotations, order processing, customer advice and support, sales promotion, product training, sales controlling and analysis, and sales channel management; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Marketing, advertising and sales promotion: Procedures required for marketing, advertising and sales promotion, for example market analysis and audience identification, developing marketing strategies, planning and conducting advertising campaigns, designing and producing advertising materials, online marketing including SEO and social media campaigns, event marketing and participation in trade fairs, customer loyalty programmes, sales promotion measures, performance measurement and optimisation of marketing activities, and budget and cost management; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Public relations: Procedures required for public relations and corporate communications, for example developing and implementing communication strategies, planning and conducting PR campaigns, preparing and distributing press releases, maintaining media contacts, monitoring and analysing media coverage, organising press conferences and public events, crisis communications, creating content for social media and corporate websites, and managing corporate branding; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Provision of the Online Offering and Web Hosting
We process user data in order to make our online services available to users. For this purpose, we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or device.
Categories of data processed: Usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved); log data (for example, log files concerning log-ins, retrieval of data or access times).
Data subjects: Users (for example, website visitors and users of online services).
Purposes of processing: Provision of our Online Offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment, such as computers and servers); security measures.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Provision of the Online Offering using rented storage space: In order to provide our Online Offering, we use storage space, computing capacity and software which we rent or otherwise obtain from an appropriate server provider, also referred to as a web host; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Collection of access data and log files: Access to our Online Offering is recorded in the form of server log files. Server log files may include the address and name of the websites and files accessed, the date and time of access, the volume of data transmitted, notification of successful retrieval, browser type and version, the user’s operating system, the referrer URL (the previously visited page), and generally the IP address and requesting provider. Server log files may be used, firstly, for security purposes, for example to prevent servers from being overloaded, particularly in the event of abusive attacks known as DDoS attacks, and, secondly, to ensure server capacity utilisation and stability; legal basis: legitimate interests (Article 6(1)(f) GDPR). Erasure of data: Log-file information is retained for a maximum of 30 days and is then erased or anonymised. Data whose further retention is necessary for evidential purposes are excluded from erasure until the relevant incident has been finally clarified.
Content Delivery Network: We use a Content Delivery Network (CDN). A CDN is a service that enables content forming part of an Online Offering, in particular large media files such as graphics or program scripts, to be delivered more quickly and securely using servers that are regionally distributed and connected via the internet; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and read information from those devices. Cookies may be used for various purposes, including ensuring the functionality, security and convenience of online offerings and analysing visitor traffic. We use cookies in accordance with the statutory requirements. Where required, we obtain users’ consent in advance. Where consent is not required, we rely on our legitimate interests. This applies where storing and accessing information is strictly necessary in order to provide expressly requested content and functions. This includes, for example, storing preferences and ensuring the functionality and security of our Online Offering. Consent may be withdrawn at any time. We provide clear information concerning the scope of consent and the cookies used.
Information on legal bases under data protection law: Whether we process personal data by means of cookies depends on consent. Where consent has been given, it constitutes the legal basis. In the absence of consent, we rely on our legitimate interests as explained above in this section and in the context of the respective services and procedures.
Storage period: The following types of cookies are distinguished with regard to their storage period:
Temporary cookies (also known as session cookies): Temporary cookies are erased no later than when a user leaves an Online Offering and closes their device application, for example their browser or mobile application.
Persistent cookies: Persistent cookies remain stored even after the device application has been closed. For example, the log-in status may be saved and preferred content displayed directly when the user visits a website again. User data collected with the assistance of cookies may also be used for audience measurement. Unless we provide users with explicit information on the type and storage period of cookies, for example when obtaining consent, users should assume that the cookies are persistent and may be stored for up to two years.
General information on withdrawal and objection (opt-out): Users may withdraw consent they have given at any time and may also object to processing in accordance with the statutory requirements, including by using their browser’s privacy settings.
Cookie settings/objection option:
Categories of data processed: Meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved).
Data subjects: Users (for example, website visitors and users of online services).
Legal bases: Legitimate interests (Article 6(1)(f) GDPR); consent (Article 6(1)(a) GDPR).
Further information on processing activities, procedures and services:
Processing of cookie data on the basis of consent: We use a consent management solution through which users’ consent is obtained for the use of cookies or for the procedures and providers specified within the consent management solution. This procedure is used to obtain, record, manage and withdraw consent, particularly in relation to the use of cookies and comparable technologies used to store, access and process information on users’ devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers named in the consent management procedure. Users may also manage and withdraw their consent. Declarations of consent are stored in order to avoid repeated requests and to enable proof of consent to be provided in accordance with the statutory requirements. Storage takes place on the server side and/or in a cookie, known as an opt-in cookie, or using comparable technologies in order to associate the consent with a specific user or their device. Unless specific information concerning providers of consent management services is provided, the following general information applies: Consent is retained for up to two years. A pseudonymous user identifier is generated and stored together with the time consent was given, information concerning the scope of consent, for example the relevant categories of cookies and/or service providers, and information concerning the browser, system and device used; legal basis: consent (Article 6(1)(a) GDPR).
Cookiebot: Consent management; procedures for obtaining, recording, managing and withdrawing consent, particularly for the use of cookies and similar technologies for storing, accessing and processing information on users’ devices and the subsequent processing of such information; service provider: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark; website: https://www.cookiebot.com/de; privacy policy: https://www.cookiebot.com/de/privacy-policy/; data processing agreement: provided by the service provider; further information: Data stored on the service provider’s server comprises the user’s IP number in anonymised form (the final three digits are set to 0), the date and time consent was given, browser information, the URL from which consent was submitted, an anonymous, random and encrypted key value, and the user’s consent status.
Contact and Enquiry Management
Where you contact us, for example by post, contact form, email, telephone or social media, and within existing user and business relationships, the information provided by the person making the enquiry is processed to the extent necessary in order to respond to the contact enquiry and carry out any requested measures.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved).
Data subjects: Communication partners; recipients and clients of services; users (for example, website visitors and users of online services).
Purposes of processing: Communication; organisational and administrative procedures; feedback (for example, collecting feedback using an online form); provision of our Online Offering and user-friendliness.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal bases: Legitimate interests (Article 6(1)(f) GDPR); performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR).
Further information on processing activities, procedures and services:
Contact form: Where you contact us using our contact form, by email or via other communication channels, we process the personal data transmitted to us in order to respond to and deal with the relevant matter. This generally includes information such as your name, contact details and, where applicable, other information communicated to us and required in order to deal with the matter appropriately. We use these data solely for the stated purpose of making contact and communicating; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
Elementor: Creation of online forms and collection and storage of the associated user entries; service provider: Elementor Ltd., Tuval St 40, Ramat Gan, Israel; legal bases: performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR); website: https://elementor.com/features/form-builder/; privacy policy: https://elementor.com/about/privacy/; data processing agreement: https://elementor.com/terms/cloud-toc/elementor-data-processing-agreement/; basis for transfers to third countries: adequacy decision (Israel); further information: https://elementor.com/trust/.
Communication via Messenger Services
We use messenger services for communication purposes and therefore ask you to note the following information concerning the functionality of messenger services, encryption, the use of communication metadata and your options for objecting.
You may also contact us by alternative means, for example by telephone or email. Please use the contact options communicated to you or the contact options provided within our Online Offering.
Where content is end-to-end encrypted, that is, the content of your message and attachments, the communication content, namely the content of the message and attached images, is encrypted from end to end. This means that the content of the messages cannot be viewed, even by the messenger service providers themselves. You should always use an up-to-date version of the messenger service with encryption enabled in order to ensure that message content is encrypted.
However, we also inform our communication partners that, although messenger service providers cannot view the content, they may ascertain that and when communication partners communicate with us and may process technical information concerning the communication partner’s device and, depending on the device settings, location information, known as metadata.
Information on legal bases: Where we ask communication partners for permission before communicating with them via a messenger service, the legal basis for processing their data is their consent. Otherwise, where we do not ask for consent and, for example, they contact us on their own initiative, we use messenger services as a contractual measure in relation to our Contractual Partners and in the context of steps prior to entering into a contract, and, in the case of other interested parties and communication partners, on the basis of our legitimate interests in fast and efficient communication and in meeting our communication partners’ need to communicate via messenger services. We also point out that we do not transmit contact details provided to us to messenger service providers for the first time without your consent.
Withdrawal, objection and erasure: You may withdraw any consent given at any time and object at any time to communicating with us via a messenger service. Where communication takes place via messenger services, we erase the messages in accordance with our general erasure policy, that is, for example, as described above, following the end of contractual relationships, subject to archiving requirements and otherwise as soon as we may assume that any enquiries from the communication partner have been answered, provided that no reference back to a previous conversation is to be expected and no statutory retention obligations prevent erasure.
Reservation of the right to refer to other communication channels: In order to ensure your security, please understand that, for certain reasons, we may be unable to respond to enquiries via messenger services. This applies where, for example, contractual details must be treated as particularly confidential or a response via messenger would not satisfy formal requirements. In such cases, we recommend using more appropriate communication channels.
Categories of data processed: Contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved).
Data subjects: Communication partners.
Purposes of processing: Communication; direct marketing (for example, by email or post).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal bases: Consent (Article 6(1)(a) GDPR); performance of a contract and steps prior to entering into a contract (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Microsoft Teams: Chat, audio and video conferencing, file sharing, integration with Office 365 applications, real-time document collaboration, calendar functions, task management, screen sharing and optional recording; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.microsoft.com/de-de/microsoft-365; privacy statement: https://privacy.microsoft.com/de-de/privacystatement; security information: https://www.microsoft.com/de-de/trustcenter; basis for transfers to third countries: Data Privacy Framework (DPF).
WhatsApp: Text messages, voice and video calls, transmission of images, videos and documents, group chat functionality and end-to-end encryption for enhanced security; service provider: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.whatsapp.com/; privacy information: https://www.whatsapp.com/legal; basis for transfers to third countries: Data Privacy Framework (DPF).
Video Conferences, Online Meetings, Webinars and Screen Sharing
We use platforms and applications provided by other providers (hereinafter referred to as “Conference Platforms”) in order to conduct video and audio conferences, webinars and other forms of video and audio meetings (hereinafter collectively referred to as a “Conference”). When selecting Conference Platforms and their services, we comply with the statutory requirements.
Data processed by Conference Platforms: When a person participates in a Conference, the Conference Platforms process the participants’ personal data specified below. The scope of processing depends, firstly, on the data required for the particular Conference, for example access credentials or a full name, and, secondly, on any optional information provided by the participants. In addition to processing for the purpose of conducting the Conference, the Conference Platforms may process participant data for security purposes or to optimise their services. The data processed include personal details such as first name and surname, contact information such as email address and telephone number, access credentials such as access codes or passwords, profile pictures, information concerning professional status or function, the IP address of the internet connection, information concerning participants’ devices, their operating systems, browsers and technical and language settings, information concerning communication content, namely chat entries and audio and video data, as well as use of other available functions, such as surveys. Communication content is encrypted to the extent technically provided by the Conference provider. Where participants are registered as users of the Conference Platforms, further data may be processed in accordance with the agreement with the relevant Conference provider.
Logging and recordings: Where text entries, participation results, for example from surveys, and video or audio recordings are logged or recorded, participants will be informed transparently in advance and, where required, asked to give consent.
Data protection measures for participants: For details of how the Conference Platforms process your data, please refer to their privacy information and select the security and privacy settings that are most appropriate for you within the Conference Platform settings. During a video conference, please also ensure that data protection and personality rights are respected in the background of your recording, for example by informing people with whom you live, closing doors and, where technically possible, using a function that obscures the background. Links to Conference rooms and access credentials must not be disclosed to unauthorised third parties.
Information on legal bases: Where, in addition to the Conference Platforms, we also process users’ data and ask users for their consent to the use of Conference Platforms or certain functions, for example consent to the recording of Conferences, the legal basis for processing is that consent. Our processing may also be necessary in order to fulfil our contractual obligations, for example in participant lists or when documenting discussion results. Otherwise, users’ data are processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); image and/or video recordings (for example, photographs or video recordings of a person); audio recordings; log data (for example, log files concerning log-ins, retrieval of data or access times).
Data subjects: Communication partners; users (for example, website visitors and users of online services); persons depicted.
Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Microsoft Teams: Audio and video conferencing, chat, file sharing, integration with Office 365 applications, real-time document collaboration, calendar functions, task management, screen sharing and optional recording; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.microsoft.com/de-de/microsoft-teams/; privacy statement: https://privacy.microsoft.com/de-de/privacystatement; security information: https://www.microsoft.com/de-de/trustcenter; basis for transfers to third countries: Data Privacy Framework (DPF).
Web Analytics, Monitoring and Optimisation
Web analytics, also referred to as audience measurement, are used to evaluate visitor traffic to our Online Offering and may include pseudonymous information concerning visitors’ behaviour, interests or demographic characteristics, such as age or gender. With the assistance of audience analysis, we may, for example, identify the times at which our Online Offering, its functions or its content are used most frequently or encourage repeat use. We are also able to identify areas requiring optimisation.
In addition to web analytics, we may use testing procedures in order to test and optimise different versions of our Online Offering or its components.
Unless otherwise stated below, profiles, meaning data consolidated in relation to a single usage session, may be created for these purposes, and information may be stored in and subsequently accessed from a browser or device. The information collected includes, in particular, websites visited and elements used on those websites, as well as technical information such as the browser and computer system used and details concerning usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.
Users’ IP addresses are also stored. However, we use an IP-masking procedure, meaning pseudonymisation by truncating the IP address, in order to protect users. As a general rule, no directly identifying user data, such as email addresses or names, are stored in connection with web analytics, A/B testing and optimisation; instead, pseudonyms are stored. This means that neither we nor the providers of the software used know the users’ actual identity, but only the information stored in their profiles for the purpose of the relevant procedures.
Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for processing is consent. Otherwise, users’ data are processed on the basis of our legitimate interests, namely our interest in providing efficient, cost-effective and user-friendly services. In this context, we also draw your attention to the information on the use of cookies in this Privacy Policy.
Categories of data processed: Usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved).
Data subjects: Users (for example, website visitors and users of online services).
Purposes of processing: Audience measurement (for example, access statistics and recognition of returning visitors); profiles containing user-related information (creation of user profiles); provision of our Online Offering and user-friendliness; conversion measurement (measurement of the effectiveness of marketing measures); click tracking; A/B testing; heatmaps (users’ mouse movements consolidated into an overall representation).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
Security measures: IP masking (pseudonymisation of the IP address).
Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Google Analytics: We use Google Analytics to measure and analyse use of our Online Offering on the basis of a pseudonymous user identification number. This identification number does not contain any directly identifying data, such as names or email addresses. It is used to associate analytical information with a device in order to identify the content accessed by users during one or more usage sessions, the search terms they used, whether they accessed that content again and how they interacted with our Online Offering. The time and duration of use, the sources referring users to our Online Offering and technical aspects of their devices and browsers are also stored.
Pseudonymous user profiles are created using information obtained from the use of different devices, and cookies may be used for this purpose. Google Analytics does not log or store individual IP addresses for users in the EU. However, Analytics provides approximate geographical location data by deriving the following metadata from IP addresses: city, including the city’s derived latitude and longitude, continent, country, region and subcontinent, together with the corresponding ID-based values. For EU traffic, IP-address data are used solely to derive these geolocation data and are then immediately erased. They are not logged, are not accessible and are not used for any other purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent (Article 6(1)(a) GDPR); website: https://marketingplatform.google.com/intl/de/about/analytics/; security measures: IP masking (pseudonymisation of the IP address); privacy policy: https://policies.google.com/privacy; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for transfers to third countries: Data Privacy Framework (DPF); objection option (opt-out): opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de; settings for the display of advertising: https://myadcenter.google.com/personalizationoff; further information: https://business.safety.google/adsservices/ (types of processing and categories of data processed).
Google Tag Manager: We use Google Tag Manager, software provided by Google which enables us to manage website tags centrally through a user interface. Tags are small items of code on our website that are used to record and analyse visitor activity. This technology assists us in improving our website and the content offered on it. Google Tag Manager itself does not create user profiles, does not store cookies containing user profiles and does not carry out independent analysis. Its function is limited to simplifying and improving the efficiency of integrating and managing the tools and services used on our website. Nevertheless, when Google Tag Manager is used, users’ IP addresses are transmitted to Google, which is technically necessary in order to implement the services we use. Cookies may also be placed. However, such data processing takes place only where services are integrated through Tag Manager. For more detailed information on those services and their processing of data, please refer to the further sections of this Privacy Policy; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent (Article 6(1)(a) GDPR); website: https://marketingplatform.google.com; privacy policy: https://policies.google.com/privacy; data processing agreement:
https://business.safety.google/adsprocessorterms. Basis for transfers to third countries: Data Privacy Framework (DPF).
Clarity: Software for analysing and optimising online offerings on the basis of feedback functions and pseudonymous measurements and analyses of user behaviour. This may include, in particular, A/B testing, meaning measurement of the popularity and user-friendliness of different content and functions, measurement of click paths, and interaction with content and functions of the Online Offering; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal basis: consent (Article 6(1)(a) GDPR); website: https://clarity.microsoft.com/; privacy statement: https://privacy.microsoft.com/de-de/privacystatement; basis for transfers to third countries: Data Privacy Framework (DPF).
Plausible Analytics: We use Plausible Analytics to measure audience reach and analyse user behaviour on our website. Plausible is a privacy-friendly web analytics tool that operates without cookies and does not store personal data in a user profile. Only aggregated, anonymised statistics are collected, for example page views, time spent on pages and visitor sources; service provider: Plausible Analytics OÜ, Västriku tn 2, 50403 Tartu, Estonia; website: https://plausible.io; privacy policy: https://plausible.io/data-policy; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Sentry: We use Sentry to monitor the technical stability of our website and to identify and analyse programming errors (error monitoring). In doing so, Sentry records technical information such as error messages, stack traces, the browser and operating system used and, where applicable, the user’s IP address. These data are processed solely for troubleshooting and to improve the stability and security of our Online Offering; service provider: Functional Software, Inc. trading as Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA; website: https://sentry.io; privacy policy: https://sentry.io/privacy/; legal basis: legitimate interests (Article 6(1)(f) GDPR).
Online Marketing
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of advertising and other content, collectively referred to as “Content”, on the basis of users’ potential interests, and measurement of the effectiveness of that Content.
For these purposes, user profiles are created and stored in a file known as a cookie, or comparable procedures are used to store information concerning the user that is relevant to the display of the aforementioned Content. This information may include, for example, Content viewed, websites visited, online networks used, communication partners and technical information such as the browser and computer system used and details concerning usage times and functions used. Where users have consented to the collection of their location data, those data may also be processed.
Users’ IP addresses are also stored. However, we use available IP-masking procedures, meaning pseudonymisation by truncating the IP address, in order to protect users. As a general rule, no directly identifying user data, such as email addresses or names, are stored within online marketing procedures; instead, pseudonyms are stored. This means that neither we nor the providers of the online marketing procedures know the user’s actual identity, but only the information stored in the relevant profiles.
The information contained in the profiles is generally stored in cookies or using comparable procedures. Those cookies may subsequently also be accessed on other websites using the same online marketing procedure, analysed for the purpose of displaying Content, supplemented with further data and stored on the server of the provider of the online marketing procedure.
In exceptional cases, directly identifying data may be associated with the profiles, particularly where users are members of a social network whose online marketing procedures we use and the network links the user profiles to the aforementioned information. Please note that users may enter into additional arrangements with the providers, for example by giving consent during registration.
As a general rule, we receive access only to aggregated information concerning the success of our advertisements. However, in connection with conversion measurement, we may examine which of our online marketing procedures resulted in a conversion, for example the conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing measures.
Unless otherwise stated, please assume that cookies used are stored for a period of two years.
Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for processing is consent. Otherwise, users’ data are processed on the basis of our legitimate interests, namely our interest in providing efficient, cost-effective and user-friendly services. In this context, we also draw your attention to the information on the use of cookies in this Privacy Policy.
Information on withdrawal and objection:
We refer to the privacy information provided by the respective providers and the objection options identified for those providers, known as opt-outs. Where no explicit opt-out option is specified, you may disable cookies in your browser settings. However, this may restrict functions of our Online Offering. We therefore additionally recommend the following opt-out options, which are offered for the respective territories:
a) Europe: https://www.youronlinechoices.eu.
b) Canada: https://www.youradchoices.ca/choices.
c) USA: https://www.aboutads.info/choices.
d) Cross-territory: https://optout.aboutads.info.
Categories of data processed: Usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved).
Data subjects: Users (for example, website visitors and users of online services).
Purposes of processing: Audience measurement (for example, access statistics and recognition of returning visitors); tracking (for example, interest-based or behavioural profiling and the use of cookies); audience targeting; marketing; profiles containing user-related information (creation of user profiles).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
Security measures: IP masking (pseudonymisation of the IP address).
Social Media Presences
We maintain online presences within social networks and, in this context, process user data in order to communicate with users active on those networks or provide information about us.
We point out that user data may be processed outside the European Union. This may entail risks for users, for example because it may be more difficult for them to enforce their rights.
Furthermore, users’ data within social networks are generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of usage behaviour and the users’ resulting interests. Those usage profiles may in turn be used, for example, to display advertisements within and outside the networks that are presumed to correspond to users’ interests. Cookies in which users’ usage behaviour and interests are stored are therefore generally placed on users’ computers. Data may also be stored in usage profiles independently of the devices used by users, particularly where they are members of the respective platforms and are logged in.
For a detailed description of the respective forms of processing and the available objection options (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
We also point out that requests for access and the exercise of data subject rights can be dealt with most effectively by the providers. Only the providers have access to the users’ data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you may contact us.
Categories of data processed: Contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions).
Data subjects: Users (for example, website visitors and users of online services).
Purposes of processing: Communication; feedback (for example, collecting feedback using an online form); public relations.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Instagram: Social network enabling users to share photographs and videos, comment on and favourite posts, send messages and follow profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/; basis for transfers to third countries: Data Privacy Framework (DPF).
Facebook Pages: Profiles within the Facebook social network – We and Meta Platforms Ireland Limited are joint controllers for the collection, but not the further processing, of data concerning visitors to our Facebook Page, also known as a fan page. These data include information concerning the types of content users view or interact with and the actions they take (see “Things you and others do and provide” in Facebook’s Data Policy at https://www.facebook.com/privacy/policy/), as well as information concerning the devices used by users, for example IP addresses, operating system, browser type, language settings and cookie data (see “Device information” in Facebook’s Data Policy at https://www.facebook.com/privacy/policy/). As explained in Facebook’s Data Policy under “How do we use this information?”, Facebook also collects and uses information in order to provide analytics services known as Page Insights to Page operators, enabling them to obtain information on how people interact with their Pages and the associated content. We have entered into a specific agreement with Facebook, the “Page Insights Controller Addendum” at https://www.facebook.com/legal/terms/page_controller_addendum, which specifies, in particular, the security measures Facebook must observe and under which Facebook has agreed to fulfil data subject rights, meaning that users may, for example, address access or erasure requests directly to Facebook. Users’ rights, in particular the rights of access, erasure and objection and the right to lodge a complaint with the competent supervisory authority, are not restricted by the arrangements with Facebook. Further information is available in the “Information about Page Insights Data” at https://www.facebook.com/legal/terms/information_about_page_insights_data. Joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company established in the EU. Meta Platforms Ireland Limited is solely responsible for the further processing of the data, including, in particular, their transfer to its parent company Meta Platforms, Inc. in the USA; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; basis for transfers to third countries: Data Privacy Framework (DPF).
LinkedIn: Social network – We and LinkedIn Ireland Unlimited Company are joint controllers for the collection, but not the further processing, of visitor data used to create Page Insights, meaning statistics relating to our LinkedIn profiles. These data include information concerning the types of content users view or interact with and the actions they take. Details are also collected concerning the devices used, such as IP addresses, operating system, browser type, language settings and cookie data, together with information from user profiles, such as job function, country, industry, seniority, company size and employment status. Information on LinkedIn’s processing of user data is available in LinkedIn’s privacy policy at https://www.linkedin.com/legal/privacy-policy.
We have entered into a specific agreement with LinkedIn Ireland, the “Page Insights Joint Controller Addendum” at https://legal.linkedin.com/pages-joint-controller-addendum, which specifies, in particular, the security measures LinkedIn must observe and under which LinkedIn has agreed to fulfil data subject rights, meaning that users may, for example, address access or erasure requests directly to LinkedIn. Users’ rights, in particular the rights of access, erasure and objection and the right to lodge a complaint with the competent supervisory authority, are not restricted by the arrangements with LinkedIn. Joint controllership is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company established in the EU. LinkedIn Ireland Unlimited Company is solely responsible for further processing of the data, including, in particular, their transfer to its parent company LinkedIn Corporation in the USA; service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.linkedin.com; privacy policy: https://www.linkedin.com/legal/privacy-policy; basis for transfers to third countries: Data Privacy Framework (DPF); objection option (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
X: Social network; service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://x.com; privacy policy: https://x.com/de/privacy.
YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); privacy policy: https://policies.google.com/privacy; basis for transfers to third countries: Data Privacy Framework (DPF); objection option (opt-out): https://myadcenter.google.com/personalizationoff.
Xing: Social network; service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.xing.com/; privacy policy: https://privacy.xing.com/de/datenschutzerklaerung.
Plug-ins, Embedded Functions and Content
We integrate functional and content elements into our Online Offering which are obtained from the servers of their respective providers (hereinafter referred to as “Third-Party Providers”). These may include, for example, graphics, videos or maps (hereinafter collectively referred to as “Content”).
The integration of such Content always requires the Third-Party Providers to process users’ IP addresses, as they would otherwise be unable to transmit the Content to the users’ browsers. The IP address is therefore required in order to display the Content or functions. We endeavour to use only Content whose respective providers use the IP address solely for the purpose of delivering the Content. Third-Party Providers may also use pixel tags, meaning invisible graphics also known as web beacons, for statistical or marketing purposes. Pixel tags may be used to analyse information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on users’ devices and may include, among other things, technical information concerning the browser and operating system, referring websites, the time of the visit and further information concerning use of our Online Offering, and may also be combined with such information from other sources.
Information on legal bases: Where we ask users for their consent to the use of Third-Party Providers, the legal basis for processing is consent. Otherwise, users’ data are processed on the basis of our legitimate interests, namely our interest in providing efficient, cost-effective and user-friendly services. In this context, we also draw your attention to the information on the use of cookies in this Privacy Policy.
Categories of data processed: Usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions); meta, communication and procedural data (for example, IP addresses, time information, identification numbers and persons involved); event data (Facebook). “Event data” means information transmitted to the provider Meta, for example via the Meta Pixel, whether through applications or other channels, and relating to persons or their actions. These data include, for example, details of visits to websites, interactions with content and functions, application installations and product purchases. Event data are processed for the purpose of creating audiences for content and advertising messages (Custom Audiences). It is important to note that event data do not include actual content such as comments written by users, log-in information or contact information such as names, email addresses or telephone numbers. Meta erases event data after a maximum of two years, and the audiences created from those data cease to exist when our Meta user accounts are deleted.
Data subjects: Users (for example, website visitors and users of online services).
Purposes of processing: Provision of our Online Offering and user-friendliness; audience measurement (for example, access statistics and recognition of returning visitors); tracking (for example, interest-based or behavioural profiling and the use of cookies); audience targeting; marketing; provision of contractual services and fulfilment of contractual obligations; profiles containing user-related information (creation of user profiles).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
Facebook plug-ins and content: Facebook social plug-ins and content – These may include, for example, content such as images, videos or text and buttons enabling users to share content from this Online Offering within Facebook. We and Meta Platforms Ireland Limited are joint controllers for the collection or receipt by transmission, but not the further processing, of event data which Facebook collects by means of Facebook social plug-ins and content embedding functions used within our Online Offering, or receives by transmission, for the following purposes: a) displaying content and advertising information presumed to correspond to users’ interests; b) delivering commercial and transactional messages, for example contacting users through Facebook Messenger; and c) improving advertising delivery and personalising functions and content, for example improving the ability to identify content or advertising information presumed to correspond to users’ interests. We have entered into a specific agreement with Facebook, the “Controller Addendum” at https://www.facebook.com/legal/controller_addendum, which specifies, in particular, the security measures Facebook must observe at https://www.facebook.com/legal/terms/data_security_terms and under which Facebook has agreed to fulfil data subject rights, meaning that users may, for example, address access or erasure requests directly to Facebook. Note: Where Facebook provides us with measurements, analyses and reports which are aggregated, meaning that they contain no information concerning individual users and are anonymous for us, that processing does not take place under joint controllership, but on the basis of a data processing agreement, the “Data Processing Terms” at https://www.facebook.com/legal/terms/dataprocessing, the “Data Security Terms” at https://www.facebook.com/legal/terms/data_security_terms and, in relation to processing in the USA, Standard Contractual Clauses contained in the “Facebook EU Data Transfer Addendum” at https://www.facebook.com/legal/EU_data_transfer_addendum. Users’ rights, in particular the rights of access, erasure and objection and the right to lodge a complaint with the competent supervisory authority, are not restricted by the arrangements with Facebook; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: consent (Article 6(1)(a) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; basis for transfers to third countries: Data Privacy Framework (DPF).
Instagram plug-ins and content: Instagram plug-ins and content – These may include, for example, content such as images, videos or text and buttons enabling users to share content from this Online Offering within Instagram. We and Meta Platforms Ireland Limited are joint controllers for the collection or receipt by transmission, but not the further processing, of event data which Facebook collects through Instagram functions, for example content embedding functions used within our Online Offering, or receives by transmission, for the following purposes: a) displaying content and advertising information presumed to correspond to users’ interests; b) delivering commercial and transactional messages, for example contacting users through Facebook Messenger; and c) improving advertising delivery and personalising functions and content, for example improving the ability to identify content or advertising information presumed to correspond to users’ interests. We have entered into a specific agreement with Facebook, the “Controller Addendum” at https://www.facebook.com/legal/controller_addendum, which specifies, in particular, the security measures Facebook must observe at https://www.facebook.com/legal/terms/data_security_terms and under which Facebook has agreed to fulfil data subject rights, meaning that users may, for example, address access or erasure requests directly to Facebook. Note: Where Facebook provides us with measurements, analyses and reports which are aggregated, meaning that they contain no information concerning individual users and are anonymous for us, that processing does not take place under joint controllership, but on the basis of a data processing agreement, the “Data Processing Terms” at https://www.facebook.com/legal/terms/dataprocessing, the “Data Security Terms” at https://www.facebook.com/legal/terms/data_security_terms and, in relation to processing in the USA, Standard Contractual Clauses contained in the “Facebook EU Data Transfer Addendum” at https://www.facebook.com/legal/EU_data_transfer_addendum. Users’ rights, in particular the rights of access, erasure and objection and the right to lodge a complaint with the competent supervisory authority, are not restricted by the arrangements with Facebook; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/.
Elfsight Widgets
We use widgets provided by Elfsight, Elfsight LLC, USA, on our website. The widgets are used to display external content or interactive elements on our website.
When pages on which an Elfsight widget is integrated are accessed, a connection to Elfsight’s servers may be established. In particular, technical access data such as the IP address, browser type, operating system, page accessed and the date and time of access may be processed. According to Elfsight, it uses the cookie elfsight_viewed_recently in order to prevent views within a short period from being counted more than once.
Where content from third-party platforms is integrated through the relevant widget, data may additionally be transmitted to those Third-Party Providers. This applies in particular to widgets relating to social media or video platforms.
The widgets are used on the basis of your consent in accordance with Article 6(1)(a) GDPR and, to the extent that information is stored on or accessed from your device, Section 25(1) of the German Telecommunications and Digital Services Data Protection Act (TDDDG). Consent may be withdrawn at any time through the cookie or privacy settings.
reCAPTCHA: We integrate the “reCAPTCHA” function in order to determine whether entries, for example in online forms, are made by human beings rather than by automated machines known as bots. The data processed may include IP addresses, information concerning operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on websites, websites previously visited, interactions with reCAPTCHA on other websites, in some circumstances cookies, and the results of manual recognition processes, for example answers to questions or the selection of objects in images. The data are processed on the basis of our legitimate interest in protecting our Online Offering against abusive automated crawling and spam; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://www.google.com/recaptcha/; privacy policy: https://policies.google.com/privacy; basis for transfers to third countries: Data Privacy Framework (DPF); objection option (opt-out): opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de; settings for the display of advertising: https://myadcenter.google.com/personalizationoff.
YouTube videos: Video content; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent (Article 6(1)(a) GDPR); website: https://www.youtube.com; privacy policy: https://policies.google.com/privacy; basis for transfers to third countries: Data Privacy Framework (DPF); objection option (opt-out): opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de; settings for the display of advertising: https://myadcenter.google.com/personalizationoff.
YouTube Image CDN / YouTube Thumbnails
Thumbnails for YouTube videos may be integrated into our website via the YouTube Image CDN. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When the thumbnails are loaded, a connection is established to Google or YouTube servers. Technical data such as the IP address, browser information, operating system, referrer URL and the date and time of access may be transmitted to Google. It cannot be ruled out that data may also be transferred to servers operated by Google LLC in the USA.
YouTube thumbnails are integrated in order to present video content on our website in a user-friendly manner. Processing is carried out on the basis of your consent in accordance with Article 6(1)(a) GDPR. To the extent that information is stored on or accessed from your device in connection with the integration, this is additionally carried out on the basis of Section 25(1) TDDDG. Consent may be withdrawn at any time through the cookie or privacy settings.
Further information concerning Google’s processing of data is available in Google’s privacy policy.
Font Awesome (retrieval from the provider’s server): Retrieval of fonts and icons for the purpose of technically secure, maintenance-free and efficient use of fonts and icons, taking into account their currency, loading times, consistent display and any licensing restrictions. The font provider receives the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data such as language settings, screen resolution, operating system and hardware used are transmitted where required in order to provide the fonts according to the devices and technical environment used; service provider: Fonticons, Inc., 6 Porter Road, Apartment 3R, Cambridge, MA 02140, USA; legal basis: legitimate interests (Article 6(1)(f) GDPR); website: https://fontawesome.com/; privacy policy: https://fontawesome.com/privacy.
Application Process
The application process requires applicants to provide us with the data necessary to assess and select them. The information required is stated in the job description or, in the case of online forms, in the information provided there.
As a general rule, the required information includes personal details such as the applicant’s name and address, a means of contact and evidence of the qualifications required for a position. We will also be pleased to provide information on request concerning the details required.
Where available, applicants are welcome to submit their applications using our online form, which is encrypted in accordance with the state of the art. Alternatively, applications may be sent to us by email. We would, however, point out that emails sent over the internet are generally not encrypted. Although emails are usually encrypted during transmission, they are not encrypted on the servers from which they are sent and received. We are therefore unable to accept responsibility for the security of an application while it is being transmitted between the sender and our server.
For the purposes of searching for applicants, receiving applications and selecting applicants, and subject to compliance with the statutory requirements, we may use applicant management or recruitment software, platforms and third-party services.
Applicants are welcome to contact us concerning the method of submitting their application or to send their application to us by post.
Processing of special categories of data: Where special categories of personal data within the meaning of Article 9(1) GDPR, for example health data such as information concerning severe disability, or data concerning ethnic origin, are requested from or disclosed by applicants in connection with the application process, such data are processed so that the controller or the data subject may exercise rights and comply with obligations arising from employment law and the law governing social security and social protection; where processing is necessary to protect the vital interests of applicants or other persons; or for the purposes of preventive or occupational medicine, the assessment of an employee’s working capacity, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services.
Erasure of data: Where an application is successful, the data provided by applicants may be further processed by us for the purposes of the employment relationship. Otherwise, where an application for a position is unsuccessful, the applicant’s data will be erased. Applicant data will also be erased where an application is withdrawn, which applicants may do at any time. Subject to a justified withdrawal request by the applicant, the data will be erased no later than six months after the end of the application process, so that we can respond to any subsequent questions concerning the application and comply with our evidential obligations under the legislation governing equal treatment of applicants. Invoices relating to any reimbursement of travel expenses are archived in accordance with tax-law requirements.
Inclusion in an applicant pool: Where an applicant pool is offered, inclusion in that pool takes place on the basis of consent. Applicants are informed that consent to inclusion in the talent pool is voluntary, has no effect on the ongoing application process and may be withdrawn at any time with effect for the future.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); applicant data (for example, personal information, postal and contact addresses, application documents and the information they contain, such as covering letters, curricula vitae and references, as well as other information concerning the applicant’s person or qualifications disclosed by applicants in relation to a specific position or voluntarily).
Data subjects: Applicants.
Purposes of processing: Application process (establishment and any subsequent performance, as well as possible subsequent termination, of the employment relationship).
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal basis: Application process as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR).
Privacy Information for Whistleblowers
This section explains how we handle data relating to persons who submit reports (Whistleblowers), as well as affected and involved parties, within our whistleblowing procedure. Our aim is to provide a straightforward and secure means of reporting possible misconduct by us, our employees or service providers, particularly conduct that breaches the law or ethical guidelines. We also ensure that reports are appropriately processed and handled.
Categories of data processed:
When receiving and processing reports and during the subsequent whistleblowing procedure, we may collect various data. These include, in particular, data provided by a Whistleblower, such as:
Name, contact details and location of the person submitting the report,
Names and data concerning potential witnesses or persons affected by the report,
Names and data concerning the persons against whom the report is directed,
Data concerning the alleged misconduct,
Further relevant details, where provided by the Whistleblower.
For the purposes of examining the facts and conducting the further procedure, we also process the following personal data:
Unique identifier of the report,
Contact details of the person submitting the report, where provided,
Personal data of persons named in the report, where provided,
Personal data of persons indirectly affected by the examination of the facts, where applicable,
Personal data of persons from other companies involved, for example in the context of legal advice, where relevant,
Further data relating to the circumstances reported.
Special categories of personal data:
In the course of our activities, we may collect special categories of personal data, particularly where these are communicated by a Whistleblower. These include:
Data concerning a person’s health,
Data concerning a person’s racial or ethnic origin,
Information concerning a person’s religious or philosophical beliefs,
Information concerning a person’s sexual orientation.
These data are processed only where they are relevant to handling the relevant report and have been expressly provided by the Whistleblower.
Use of our online forms: Please note that reports may be submitted anonymously. To safeguard the security of your data when using our online forms, we recommend accessing them in your browser’s “incognito mode”. You can open an incognito window as follows: a) on a Windows PC, open your browser and press Ctrl+Shift+N; b) on a Mac, open your browser and press Command+Shift+N; c) on a mobile device, switch to private mode using the tab menu.
When our website is accessed in normal mode, your browser automatically sends certain information to our server, such as the browser type and version and the date and time of access. This also includes the IP address of your device. These data are temporarily stored in a log file and automatically erased after no more than 30 days.
The IP address is processed for technical and administrative purposes in connection with establishing a connection to our website. This ensures the security, stability and functionality of the whistleblowing form and is an important element of our measures to ensure that reports can be submitted confidentially.
The processing of logged data is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the need for security and the necessity of ensuring the technical conditions required for reports to be submitted smoothly and without disruption.
Provision of names: You may submit reports anonymously. However, to the extent that national legislation does not prohibit this, we recommend that you provide your name and contact details. This enables us to follow up the report more effectively and, where appropriate, contact you directly.
Where you provide your name and contact details, your identity will be treated as strictly confidential. Exceptions to this confidentiality apply only where we are legally required to disclose your identity. This may be necessary in order to protect or defend our rights or the rights of our employees, customers, suppliers or business partners. A further exception applies where it is established that the allegations were made with malicious intent.
Disclosure of data to third parties: We disclose data relating to reports to third parties only in certain circumstances. This takes place either a) where you have given us your explicit consent to do so, or b) where there is a legal obligation to disclose the data. Potential third parties include public authorities and government, regulatory or tax authorities where disclosure is necessary in order to comply with a legal or regulatory obligation. We may also instruct lawyers and other professional advisers in accordance with the law. They may examine suspected misconduct and take necessary action following an investigation, such as initiating disciplinary or judicial proceedings. Carefully selected and monitored service providers may also receive data for these purposes, for example operators of a web-based reporting system. However, those service providers are contractually required, as processors, to comply with the applicable data protection provisions.
Data retention and erasure: Personal data are processed only for as long as necessary to fulfil the purposes of processing described above. Where the data are no longer necessary for those purposes, they are erased. In certain circumstances, however, the data may be retained for longer in order to comply with statutory requirements, provided that this remains necessary and proportionate. In such cases, the data are erased as soon as they are no longer required for those purposes.
Technical and organisational measures: We have implemented the necessary contractual, technical and organisational measures to ensure the security of all data processed by us. Those data are processed solely for the specified purposes. Incoming reports are handled by authorised persons who are given access to the relevant reports and conduct the subsequent examination of the facts. Our employees are specifically trained and instructed in the proper conduct of factual investigations and are bound to observe the strictest confidentiality.
Categories of data processed: Master data (for example, full name, residential address, contact details, customer number, etc.); employee data (information concerning employees and other persons in an employment relationship); contact data (for example, postal and email addresses or telephone numbers); content data (for example, textual or visual messages and posts and related information, such as authorship details or the date and time of creation); usage data (for example, page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, and interactions with content and functions).
Data subjects: Employees (for example, members of staff, applicants, temporary workers and other workers); third parties; Whistleblowers.
Purposes of processing: Whistleblower protection.
Retention and erasure: Erasure in accordance with the information provided in the section “General Information on Data Retention and Erasure”.
Legal bases: Consent (Article 6(1)(a) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Changes and Updates
Please review the content of this Privacy Policy regularly. We will amend the Privacy Policy whenever changes to the processing activities carried out by us make this necessary. We will inform you where the changes require action on your part, for example consent, or another form of individual notification.
Where we provide addresses and contact information for companies and organisations in this Privacy Policy, please note that addresses may change over time and check the information before making contact.
Definitions
This section provides an overview of the terms used in this Privacy Policy. Where terms are defined by law, their statutory definitions apply. The explanations below are intended primarily to aid understanding.
A/B testing: A/B testing is used to improve the user-friendliness and performance of online offerings. Users are shown, for example, different versions of a website or its elements, such as input forms, in which the placement of content or the wording of navigation elements may differ. Users’ behaviour, such as spending longer on the website or interacting with elements more frequently, can then be used to determine which websites or elements better meet users’ needs.
Employees: Employees are persons in an employment relationship, whether as workers, salaried employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee established by an employment contract or agreement. It entails an obligation on the employer to pay the employee remuneration in return for the employee’s work. The employment relationship comprises various stages, including its establishment, when the employment contract is concluded; its performance, when the employee carries out their work; and its termination, whether by notice, a termination agreement or otherwise. Employee data comprise all information relating to these persons in the context of their employment. This includes matters such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance assessments.
Master data: Master data comprise essential information required to identify and administer Contractual Partners, user accounts, profiles and comparable assignments. These data may include personal and demographic information such as names, contact details, including addresses, telephone numbers and email addresses, dates of birth and specific identifiers such as user IDs. Master data form the basis of formal interactions between persons and services, institutions or systems by enabling unique identification and communication.
Heatmaps: “Heatmaps” comprise users’ mouse movements consolidated into an overall representation which may be used, for example, to identify which website elements users access preferentially and which they favour less.
Content data: Content data comprise information generated in the course of creating, editing and publishing content of any kind. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data are not limited to the content itself, but also include metadata providing information about the content, such as tags, descriptions, author information and publication dates.
Click tracking: Click tracking makes it possible to obtain an overview of users’ movements throughout an Online Offering. As the results of these tests are more accurate where users’ interactions can be tracked over a certain period, for example so that we can determine whether a user is likely to return, cookies are generally stored on users’ computers for these testing purposes.
Contact data: Contact data are essential information enabling communication with persons or organisations. They include telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
Conversion measurement: Conversion measurement, also referred to as conversion tracking, is a procedure used to determine the effectiveness of marketing measures. As a general rule, a cookie is stored on users’ devices within the websites on which the marketing measures are carried out and is then accessed again on the target website. This enables us, for example, to determine whether advertisements placed by us on other websites were successful.
Meta, communication and procedural data: Meta, communication and procedural data are categories containing information about how data are processed, transmitted and managed. Metadata, also known as data about data, comprise information describing the context, origin and structure of other data. They may include details such as file size, creation date, the author of a document and amendment histories. Communication data record the exchange of information between users via various channels, such as email correspondence, call logs, social network messages and chat histories, including the persons involved, time stamps and transmission channels. Procedural data describe processes and workflows within systems or organisations, including workflow documentation, records of transactions and activities and audit logs used to trace and review operations.
Usage data: Usage data refer to information recording how users interact with digital products, services or platforms. These data comprise a broad range of information showing how users use applications, which functions they prefer, how long they remain on particular pages and the paths by which they navigate through an application. Usage data may also include frequency of use, activity time stamps, IP addresses, device information and location data. They are particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Usage data also play an important role in identifying trends, preferences and potential problem areas within digital offerings.
Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, for example a cookie, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Profiles containing user-related information: Processing of “profiles containing user-related information”, or “profiles” for short, includes any form of automated processing of personal data consisting of the use of those personal data to analyse, evaluate or predict certain personal aspects relating to a natural person. Depending on the type of profiling, this may include different information concerning demographics, behaviour and interests, such as interactions with websites and their content, in order to analyse, assess or predict matters such as interests in particular content or products, click behaviour on a website or a person’s location. Cookies and web beacons are frequently used for profiling purposes.
Log data: Log data are information concerning events or activities recorded in a system or network. These data typically contain information such as time stamps, IP addresses, user actions, error messages and other details concerning the use or operation of a system. Log data are often used to analyse system problems, monitor security or prepare performance reports.
Audience measurement: Audience measurement, also referred to as web analytics, is used to evaluate visitor traffic to an Online Offering and may include visitors’ behaviour or interests in particular information, such as website content. Audience analysis enables operators of online offerings to identify, for example, the times at which users visit their websites and the content in which they are interested. This allows them, for example, to adapt website content more effectively to visitors’ needs. Pseudonymous cookies and web beacons are frequently used for audience analysis in order to recognise returning visitors and thereby obtain more accurate analyses of the use of an Online Offering.
Tracking: “Tracking” means that users’ behaviour can be traced across multiple online offerings. As a general rule, behavioural and interest information relating to the online offerings used is stored in cookies or on the servers of tracking technology providers, a process known as profiling. This information may subsequently be used, for example, to display advertisements to users which are likely to correspond to their interests.
Controller: The “controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, including collection, analysis, storage, transmission and erasure.
Contract data: Contract data comprise specific information relating to the formalisation of an agreement between two or more parties. They document the terms on which services or products are provided, exchanged or sold. This category of data is essential for administering and fulfilling contractual obligations and includes both the identification of the parties to the contract and the specific terms and conditions of the agreement. Contract data may include the contract’s commencement and end dates, the nature of the agreed services or products, price arrangements, payment terms, termination rights, renewal options and specific terms or clauses. They provide the legal basis for the relationship between the parties and are essential for clarifying rights and obligations, enforcing claims and resolving disputes.
Payment data: Payment data comprise all information required to process payment transactions between buyers and sellers. These data are essential for e-commerce, online banking and any other form of financial transaction. They include details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and billing information. Payment data may also include information concerning payment status, chargebacks, authorisations and fees.
Audience targeting: “Audience targeting”, also known as “Custom Audiences”, means identifying audiences for advertising purposes, for example for the display of advertisements. A user’s interest in particular products or topics on the internet may, for example, be used to infer that the user is interested in advertisements for similar products or for the online shop in which the products were viewed. “Lookalike Audiences”, or similar audiences, are created where content considered suitable is displayed to users whose profiles or presumed interests correspond to those of users for whom profiles have been created. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.