Preamble
In the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to briefly as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering").
The terms used are not gender-specific.
Last updated: July 12, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Business Services
- Payment Procedures
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Blogs and Publication Media
- Contact and Inquiry Management
- Newsletter and Electronic Notifications
- Promotional Communication via Email, Post, Fax, or Telephone
- Sweepstakes and Contests
- Surveys and Polls
- Web Analytics, Monitoring, and Optimization
- Presence on Social Networks (Social Media)
- Plug-ins and Embedded Functions and Content
- Amendments and Updates
- Definitions
Controller
"Hooked"
Hooked Experiences B.V.
Industrieweg 9,
2254AE Voorschoten, The Netherlands
KvK (Dutch Chamber of Commerce): 42083493
Authorized representative: Max Zarfl
Email address: info@get-hooked.nl
Legal notice (Impressum): https://get-hooked.nl/imprint/
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Categories of data processed
- Inventory data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication, and process data.
- Log data.
Categories of data subjects
- Service recipients and clients.
- Prospective customers.
- Communication partners.
- Users.
- Sweepstakes and contest participants.
- Business and contractual partners.
- Participants.
Purposes of processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organizational procedures.
- Remarketing.
- Audience targeting.
- Organizational and administrative procedures.
- Conducting sweepstakes and contests.
- Feedback.
- Surveys and questionnaires.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and usability.
- Information technology infrastructure.
- Public relations.
- Sales promotion.
- Business processes and administrative procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or registered office. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) — The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) — Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights, and freedoms of the data subject that require protection of personal data.
National data protection regulations in the Netherlands: In addition to the GDPR's data protection regulations, national data protection provisions apply in the Netherlands. This includes, in particular, the "Implementation Act for the General Data Protection Regulation" (Uitvoeringswet Algemene verordening gegevensbescherming – UAVG).
Security Measures
In accordance with statutory requirements and taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to, entry of, disclosure of, and ensuring the availability of and separation of data. We have also established procedures to ensure the exercise of data subject rights, data deletion, and responses to data breaches. Furthermore, we take the protection of personal data into account already at the stage of developing or selecting hardware, software, and procedures, in accordance with the principle of data protection through technology design and through privacy-friendly default settings.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured with an SSL/TLS certificate, this is signaled by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and encrypted.
Transfer of Personal Data
In the course of our processing of personal data, it may occur that such data is transferred to or disclosed to other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content integrated into a website. In such cases, we comply with statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies, or companies (which is evident from the postal address of the respective provider or where the privacy policy expressly refers to the transfer of data to third countries), this always takes place in accordance with statutory requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a safe legal framework by an adequacy decision of the EU Commission dated July 10, 2023. In addition, we have concluded Standard Contractual Clauses with the respective providers, which comply with the EU Commission's requirements and establish contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, while the Standard Contractual Clauses serve as an additional safeguard. Should any changes occur within the framework of the DPF, the Standard Contractual Clauses act as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.
For each individual service provider, we inform you whether they are certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, corresponding safeguards apply, in particular Standard Contractual Clauses, explicit consent, or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found on the EU Commission's information portal: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with statutory provisions as soon as the underlying consent is revoked or no other legal basis for processing exists. This applies in cases where the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the assertion, exercise, or defense of legal claims or to protect the rights of other natural or legal persons, must be archived accordingly.
Our data protection notices contain additional information on the retention and deletion of data that applies specifically to certain processing activities.
In the event of multiple specifications regarding the retention period or deletion deadlines for a given piece of data, the longest period shall always apply. Data that is no longer retained for its originally intended purpose, but is retained due to legal requirements or other reasons, is processed exclusively for the reasons justifying its retention.
Start of the retention period at the end of the year: If a period does not begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the point in time at which the termination or other ending of the legal relationship takes effect.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to information about that data as well as further information and a copy of the data in accordance with statutory requirements.
- Right to rectification: In accordance with statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with statutory requirements, you have the right to request that data concerning you be deleted without delay, or alternatively, in accordance with statutory requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with statutory requirements, in a structured, commonly used, and machine-readable format, or to request its transfer to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of personal data concerning you violates the GDPR.
Business Services
We process the personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers, and other business partners (collectively "contractual partners"), in order to initiate, carry out, and conclude contractual relationships and comparable legal relationships. This also includes pre-contractual measures carried out at the recipient's request, as well as communication related to the respective contractual relationship.
The processing serves in particular to fulfill our primary and ancillary contractual obligations. This includes providing the agreed services, any update and information obligations, handling warranty and other service disruptions, processing cancellations, terminations of continuing obligations, unwinding of contracts, refunds, and processing other contract-related declarations and inquiries. This covers both one-time contracts and ongoing contractual relationships.
We process in particular master data such as name, address, and, if applicable, company name; contact data such as email address and telephone number; contract and service data such as the subject matter of the contract, contract term, order or transaction number; usage and performance data; payment and billing data; as well as communication content and history. Where necessary, we also process data that is disclosed or transmitted to us in the course of carrying out an order.
In addition, we process the data to protect our rights and to comply with legal obligations. This includes, in particular, retention obligations under commercial and tax law, documentation obligations, and, where applicable, verification and accountability obligations. We also process data on the basis of our legitimate interests in proper business management, internal administration, risk control, and IT security, as well as in protecting our business operations and contractual partners against misuse and threats to data, trade secrets, and other legal interests. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisors, or other agents, to the extent necessary for contract performance or to fulfill legal obligations.
Personal data is disclosed to third parties only to the extent necessary for contract performance, to carry out pre-contractual measures, to protect legitimate interests, or to fulfill legal obligations. We inform you separately in this privacy policy about any further processing, in particular for marketing purposes.
We inform contractual partners which data is required in individual cases as part of the data collection process, for example through appropriate labeling in online forms or during personal contact.
Data is deleted as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations apply. Statutory retention periods, in particular under commercial and tax law, may require longer storage. We delete data transmitted in connection with a specific order after the order has been completed and any applicable retention periods have expired, provided no other legal or contractual obligations require further storage.
The legal basis for processing is Art. 6(1)(b) GDPR for carrying out pre-contractual measures and fulfilling the respective contractual relationship, as well as Art. 6(1)(c) GDPR for compliance with legal obligations. Where processing is based on legitimate interests, it is carried out on the basis of Art. 6(1)(f) GDPR. Where processing is based on Art. 6(1)(f) GDPR, it is carried out to protect our legitimate interests in proper and efficient business organization, internal administration and documentation of business processes, the assertion and defense of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations. These interests exist in particular in ensuring a secure and legally compliant business operation and in preserving our entrepreneurial capacity to act.
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; organizational and administrative procedures; business processes and administrative procedures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- Online shop, order forms, e-commerce, and service delivery: We process the data of our customers in order to enable them to select, purchase, or order the chosen products, goods, and related services, as well as their payment and provision, delivery, or performance. Where necessary for the execution of an order, we use service providers, in particular postal, freight, and shipping companies, to deliver or perform services to our customers. We use the services of banks and payment service providers to process payment transactions. The required information is marked as such within the order or comparable purchasing process and includes the information needed for delivery or provision and billing, as well as contact information for follow-up inquiries; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- Project and development services: We process the data of our customers and clients (hereinafter uniformly referred to as "customers") in order to enable them to select, purchase, or commission the chosen services or works, as well as related activities, as well as their payment and provision, execution, or performance.
The required information is marked as such within the order, purchase, or comparable contract conclusion process and includes the information needed for service performance and billing, as well as contact information for follow-up inquiries. To the extent that we obtain access to information about end customers, employees, or other persons, we process this in accordance with statutory and contractual requirements; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Payment Procedures
Within the framework of contractual and other legal relationships, due to statutory obligations, or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, in addition to banks and credit institutions, use other service providers for this purpose (collectively "payment service providers"). Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, so that the data entered is protected from unauthorized access during transmission.
The data processed by payment service providers includes inventory data, such as name and address; bank details, such as account or credit card numbers; passwords, TANs, and checksums; as well as contract-, amount-, and recipient-related information. This information is required to carry out the transactions. However, the data entered is only processed and stored by the payment service providers. This means we do not receive any account- or credit card-related information, but only confirmation or non-confirmation of payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit reporting agencies. This transmission serves the purpose of identity and creditworthiness checks. For this purpose, we refer to the terms and conditions and privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers apply to payment transactions, which can be accessed on their respective websites or transaction applications. We also refer to these for further information and for exercising rights of withdrawal, access, and other data subject rights.
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved); contact data (e.g., postal and email addresses or telephone numbers).
- Data subjects: Service recipients and clients; business and contractual partners; prospective customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; business processes and administrative procedures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- American Express: Payment services (technical integration of online payment methods); Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://www.americanexpress.com/de/. Privacy Policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
- Apple Pay: Payment services (technical integration of online payment methods); Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://www.apple.com/de/apple-pay/. Privacy Policy: https://www.apple.com/legal/privacy/de-ww/.
- Google Pay: Payment services (technical integration of online payment methods); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://pay.google.com/intl/de_de/about/. Privacy Policy: https://business.safety.google/privacy/.
- Mastercard: Payment services (technical integration of online payment methods); Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://www.mastercard.de/de-de.html. Privacy Policy: https://www.mastercard.com/de/de/datenschutz.html.
- PayPal: Payment services (technical integration of online payment methods) (e.g., PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://www.paypal.com/de. Privacy Policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
- Stripe: Payment services (technical integration of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://stripe.com; Privacy Policy: https://stripe.com/de/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
- Visa: Payment services (technical integration of online payment methods); Service provider: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, UK; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Website: https://www.visa.de. Privacy Policy: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung.html.
Provision of the Online Offering and Web Hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary in order to deliver the content and functions of our online services to the user's browser or terminal device.
- Categories of data processed: Usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved); log data (e.g., log files relating to logins or data retrieval or access times); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and usability; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity, and software rented or otherwise obtained from a corresponding server provider (also known as a "web host"); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, date and time of access, amounts of data transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files can be used for security purposes, for example, to avoid overloading the servers (particularly in the event of malicious attacks, so-called DDoS attacks), and also to ensure the servers' capacity utilization and stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally resolved.
- Email sending and hosting: The web hosting services we use also include the sending, receiving, and storage of emails. For these purposes, the addresses of recipients and senders, as well as further information relating to email transmission (e.g., the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for purposes of spam detection. Please note that emails are generally not sent encrypted over the internet. As a rule, emails are encrypted during transmission but not (unless so-called end-to-end encryption is used) on the servers from which they are sent and received. We can therefore assume no responsibility for the transmission path of emails between the sender and receipt on our server; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Use of Cookies
The term "cookies" refers to functions that store and retrieve information on users' devices. Cookies may be used for various purposes, such as functionality, security, and comfort of online offerings, as well as the creation of visitor traffic analyses. We use cookies in accordance with statutory requirements. Where necessary, we obtain prior consent from users. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential in order to provide expressly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We clearly inform you of the scope and which cookies are used.
Notes on data protection legal bases: Whether we process personal data using cookies depends on your consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.
Retention period: With regard to retention period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their device (e.g., browser or mobile application).
- Persistent cookies: Persistent cookies remain stored even after the device is closed. For example, login status can be saved and preferred content displayed directly when the user visits a website again. Likewise, user data collected using cookies may be used for reach measurement purposes. If we do not provide users with explicit information about the type and storage duration of cookies (e.g., when obtaining consent), users should assume that these are persistent and that the storage period may be up to two years.
General notes on withdrawal and objection (opt-out): Users can withdraw their consent at any time and may also object to the processing in accordance with statutory requirements, including via their browser's privacy settings.
- Categories of data processed: Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR).
Additional notes on processing activities, procedures, and services:
- Processing of cookie data on the basis of consent: We use a consent management solution to obtain users' consent to the use of cookies, or to the procedures and providers named within the consent management solution. This process serves to obtain, log, manage, and withdraw consent, particularly with regard to the use of cookies and comparable technologies used to store, read, and process information on users' devices. As part of this process, users' consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers named in the consent management process. Users also have the option of managing and withdrawing their consent. Consent declarations are stored to avoid repeated requests and to provide proof of consent in accordance with statutory requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or using comparable technologies, in order to be able to assign the consent to a specific user or their device. Unless specific information about the providers of consent management services is provided, the following general information applies: The consent is stored for up to two years. A pseudonymous user identifier is created and stored together with the time consent was given, information on the scope of consent (e.g., relevant categories of cookies and/or service providers), and information about the browser, system, and device used; Legal bases: Consent (Art. 6(1)(a) GDPR).
Blogs and Publication Media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is processed for the purposes of the publication medium only to the extent necessary for its presentation and communication between authors and readers, or for security reasons. Otherwise, we refer to the information on the processing of visitors to our publication medium within this privacy policy.
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g., collecting feedback via an online form); provision of our online offering and usability.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Contact and Inquiry Management
When contacting us (e.g., by mail, contact form, email, telephone, or via social media), as well as within the context of existing user and business relationships, the information provided by the inquiring parties is processed to the extent necessary to respond to the inquiries and any requested measures.
- Categories of data processed: Contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via an online form); provision of our online offering and usability.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Additional notes on processing activities, procedures, and services:
- Contact form: When you contact us via our contact form, email, or other means of communication, we process the personal data transmitted to us in order to respond to and process the respective inquiry. This typically includes information such as name, contact details, and, where applicable, other information provided to us that is necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Newsletter and Electronic Notifications
We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") only with the recipients' consent or on the basis of a legal permission. Where the content of the newsletter is described as part of registration, this description is decisive for user consent. As a rule, providing your email address is sufficient to register for our newsletter. However, in order to provide you with a personalized service, we may ask for your name for personal address in the newsletter, or for other information if required for the purpose of the newsletter.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests, before deleting them, in order to be able to prove that consent was previously given. Processing of this data is limited to the purpose of potential defense against claims. An individual deletion request is possible at any time, provided that the former existence of consent is confirmed at the same time. In the event of obligations to permanently observe objections, we reserve the right to store the email address for this purpose alone on a blocklist.
The registration process is logged on the basis of our legitimate interests for the purpose of proving that it was carried out properly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.
Content:Information about us, our services, promotions, and offers.
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g., by email or post).
- Legal bases: Consent (Art. 6(1)(a) GDPR).
- Right to object (opt-out): You can cancel receipt of our newsletter at any time, i.e., withdraw your consent or object to further receipt. You will find a link to unsubscribe from the newsletter either at the end of each newsletter, or you can use one of the contact options listed above, preferably email.
Additional notes on processing activities, procedures, and services:
- Measuring open and click rates: The newsletters contain a so-called "web beacon," i.e., a pixel-sized file that is retrieved from our server, or from a dispatch service provider's server if we use one, when the newsletter is opened. As part of this retrieval, technical information, such as details about your browser and system, as well as your IP address and the time of retrieval, are initially collected. This information is used to technically improve our newsletter based on the technical data or the target groups and their reading behavior based on their locations of access; Legal bases: Consent (Art. 6(1)(a) GDPR).
Promotional Communication via Email, Post, Fax, or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels such as email, telephone, mail, or fax, in accordance with statutory requirements.
Recipients have the right to withdraw any consent given at any time, or to object to promotional communication at any time free of charge via the contact options listed above.
After withdrawal or objection, we store the data necessary to prove prior authorization for contact or dispatch for up to three years after the end of the year in which the withdrawal or objection was made, on the basis of our legitimate interests. Processing of this data is limited to the purpose of possible defense against claims. On the basis of the legitimate interest in permanently observing users' withdrawal or objection, we also store the data necessary to prevent renewed contact (e.g., depending on the communication channel, the email address, telephone number, or name).
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g., by email or post); marketing; sales promotion.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Sweepstakes and Contests
We process the personal data of participants in sweepstakes and contests only in compliance with applicable data protection regulations, to the extent that processing is contractually necessary to provide, conduct, and settle the sweepstakes, the participants have consented to the processing, or the processing serves our legitimate interests (e.g., in the security of the sweepstakes or the protection of our interests against misuse through possible collection of IP addresses when entries are submitted).
If participants' contributions are published as part of the sweepstakes (e.g., in the context of a vote or presentation of entries or winners, or reporting on the sweepstakes), please note that participants' names may also be published in this context. Participants may object to this at any time.
If the sweepstakes takes place within an online platform or a social network (e.g., Facebook or Instagram, hereinafter referred to as "online platform"), the terms of use and privacy policies of the respective platforms also apply. In these cases, we note that we are responsible for the information provided by participants as part of the sweepstakes, and inquiries regarding the sweepstakes should be directed to us.
Participants' data is deleted as soon as the sweepstakes or contest has ended and the data is no longer required to notify winners, or because further inquiries about the sweepstakes are no longer expected. As a general rule, participants' data is deleted no later than 6 months after the end of the sweepstakes. Winners' data may be retained longer, for example, to answer inquiries about prizes or to fulfill prize obligations; in this case, the retention period depends on the type of prize and may be up to three years for goods or services, for example, to handle warranty claims. Furthermore, participants' data may be stored longer, for example, in the form of reporting on the sweepstakes in online and offline media.
If data was also collected for other purposes as part of the sweepstakes, its processing and retention period are governed by the privacy notices for that use (e.g., in the case of newsletter registration as part of a sweepstakes).
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation).
- Data subjects: Sweepstakes and contest participants.
- Purposes of processing and legitimate interests: Conducting sweepstakes and contests.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Surveys and Polls
We conduct surveys and polls in order to gather information for the respective communicated survey or polling purpose. The surveys and polls we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is processed only to the extent necessary to provide and technically carry out the surveys (e.g., processing the IP address to display the survey in the user's browser, or using a cookie to enable the survey to be resumed).
- Categories of data processed: Inventory data (e.g., full name, home address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
- Data subjects: Participants.
- Purposes of processing and legitimate interests: Feedback (e.g., collecting feedback via an online form); surveys and questionnaires (e.g., surveys with input fields, multiple-choice questions).
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as "reach measurement") serves to evaluate visitor traffic on our online offering and may include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. Reach analysis allows us to identify, for example, at what times our online offering or its functions or content are used most frequently, or invite reuse. It also allows us to determine which areas need optimization.
In addition to web analytics, we may also use testing procedures to test and optimize different versions of our online offering or its components.
Unless stated otherwise below, profiles — i.e., data combined into a usage process — may be created for these purposes, and information may be stored in and read from a browser or terminal device. Information collected typically includes visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and usage time information. If users have consented to the collection of their location data with us or with the providers of the services we use, the processing of location data is also possible.
In addition, users' IP addresses are stored. However, we use IP masking (i.e., pseudonymization by shortening the IP address) to protect users. Generally, no plain-text user data (such as email addresses or names) is stored for the purposes of web analytics, A/B testing, and optimization, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we also refer you to the information on the use of cookies in this privacy policy.
- Categories of data processed: Usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); remarketing.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion"; storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- Matomo: Matomo is software used for web analytics and reach measurement purposes. When Matomo is used, cookies are generated and stored on users' devices. The user data collected through the use of Matomo is processed only by us and is not shared with third parties. Cookies are stored for a maximum period of 13 months: https://matomo.org/faq/general/faq_146/; Legal bases: Consent (Art. 6(1)(a) GDPR). Data deletion: Cookies are stored for a maximum period of 13 months.
Presence on Social Networks (Social Media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with users active there or to provide information about ourselves.
Please note that in doing so, user data may be processed outside the European Union. This may pose risks to users, for example, because it could make it more difficult to enforce user rights.
Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on usage behavior and resulting user interests. These profiles may in turn be used, for example, to place advertisements within and outside the networks that are presumed to correspond to users' interests. For this purpose, cookies are generally stored on users' computers, in which their usage behavior and interests are stored. In addition, data may also be stored in user profiles independently of the devices used by the users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and options for objection (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
Even in the case of requests for information and the exercise of data subject rights, we note that these can be asserted most effectively with the providers. Only the providers have access to the user data and can take appropriate action and provide information directly. If you nevertheless require assistance, please feel free to contact us.
- Categories of data processed: Contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as related information, such as authorship details or time of creation); usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g., collecting feedback via an online form); public relations.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- Instagram: Social network, enables sharing of photos and videos, commenting on and favoriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
- Facebook pages: Profiles within the Facebook social network — The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data from visitors to our Facebook page ("fan page"). This includes, in particular, information about user behavior (e.g., content viewed or interacted with, actions taken) as well as device information (e.g., IP address, operating system, browser type, language settings, cookie data). Further details can be found in the Facebook Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical analyses via the "Page Insights" service, which provide information on how people interact with our page and its content. This is based on an agreement with Facebook ("Information about Page Insights Data": https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users can therefore direct requests for information or deletion directly to Facebook. The rights of users (in particular access, deletion, objection, and complaint to a supervisory authority) remain unaffected by this. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for further processing, including any transfer of data to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- LinkedIn: Social network — We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not further processing) of visitor data used to generate "Page Insights" (statistics) for our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as the actions they take. Details about the devices used are also collected, such as IP addresses, operating system, browser type, language settings, and cookie data, as well as information from user profiles, such as job function, country, industry, seniority level, company size, and employment status. Data protection information regarding LinkedIn's processing of user data can be found in LinkedIn's privacy notice: https://www.linkedin.com/legal/privacy-policy.
We have entered into a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum," https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe, and in which LinkedIn has agreed to fulfill data subjects' rights (i.e., users can, for example, submit requests for information or deletion directly to LinkedIn). The rights of users (in particular the right to access, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, particularly with regard to the transfer of data to its parent company, LinkedIn Corporation, in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.linkedin.com/legal/privacy-policy). Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Privacy Policy: https://business.safety.google/privacy/; Basis for third-country transfers: Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos, or maps (hereinafter uniformly referred to as "content").
Integration always requires that the third-party providers of this content process the user's IP address, as without the IP address they would not be able to send the content to the user's browser. The IP address is therefore required to display this content or functions. We strive to use only content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. These "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may include technical information about the browser and operating system, referring websites, visit time, and other information about the use of our online offering, but may also be combined with information from other sources.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we also refer you to the information on the use of cookies in this privacy policy.
- Categories of data processed: Usage data (e.g., page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and usability; reach measurement (e.g., access statistics, recognition of returning visitors); tracking (e.g., interest-/behavior-based profiling, use of cookies); audience targeting; marketing.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion"; storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Additional notes on processing activities, procedures, and services:
- Google Fonts (self-hosted): Provision of font files for a user-friendly presentation of our online offering; Service provider: The Google Fonts are hosted on our own server; no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- OpenStreetMap: We integrate maps from the "OpenStreetMap" service, offered by the OpenStreetMap Foundation (OSMF) under the Open Data Commons Open Database License (ODbL). User data is used by OpenStreetMap solely for the purpose of displaying map functions and temporarily storing selected settings. This data may include, in particular, users' IP addresses and location data, which are not collected without their consent (typically obtained via their device or browser settings); Service provider: OpenStreetMap Foundation (OSMF); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.openstreetmap.de. Privacy Policy: https://osmfoundation.org/wiki/Privacy_Policy.
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.youtube.com; Privacy Policy: https://business.safety.google/privacy/; Basis for third-country transfers: Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, ad personalization settings: https://myadcenter.google.com/personalizationoff.
- YouTube videos: Our online offering includes embedded videos that are stored on YouTube. These YouTube videos are integrated via a special domain using the "youtube-nocookie" component in the so-called "enhanced privacy mode." In "enhanced privacy mode," until the video starts, only information such as your IP address and details about your browser and device can be stored on your device via cookies or comparable methods, which YouTube requires for the display, control, and optimization of video playback. Once you play the videos, YouTube may also process additional information to analyze usage behavior, store it in a user profile, and personalize content and advertisements. Cookie retention may be up to two years; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.youtube.com; Privacy Policy: https://business.safety.google/privacy/; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://support.google.com/youtube/answer/171780?hl=en.
Amendments and Updates
We ask that you regularly inform yourself about the content of our privacy policy. We will adjust the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your participation (e.g., consent) or other individual notification.
Where we provide addresses and contact information for companies and organizations in this privacy policy, please note that this information may change over time, and we ask that you verify the details before making contact.
Definitions
This section provides an overview of the terms used in this privacy policy. Where terms are legally defined, their statutory definitions apply. The explanations below are primarily intended to aid understanding.
- Inventory data: Inventory data includes essential information necessary for identifying and managing contractual partners, user accounts, profiles, and similar assignments. This data may include personal and demographic information such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between individuals and services, institutions, or systems by enabling unique identification and communication.
- Content data: Content data includes information generated in the course of creating, editing, and publishing content of any kind. This category of data may include text, images, videos, audio files, and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself but also includes metadata that provides information about the content, such as tags, descriptions, author information, and publication dates.
- Contact data: Contact data is essential information that enables communication with individuals or organizations. This includes, among other things, telephone numbers, postal addresses, and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication, and process data: Meta, communication, and process data are categories that contain information about how data is processed, transmitted, and managed. Metadata, also known as data about data, includes information describing the context, origin, and structure of other data. It may include details such as file size, creation date, document author, and change history. Communication data records the exchange of information between users via various channels, such as email traffic, call logs, social network messages, and chat histories, including the persons involved, timestamps, and transmission paths. Process data describes the processes and workflows within systems or organizations, including workflow documentation, transaction and activity logs, and audit logs used for tracking and reviewing processes.
- Usage data: Usage data refers to information that records how users interact with digital products, services, or platforms. This data encompasses a wide range of information showing how users use applications, which features they prefer, how long they spend on certain pages, and the paths they take through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experience, personalizing content, and improving products or services. In addition, usage data plays a crucial role in identifying trends, preferences, and potential problem areas within digital offerings.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Profiles with user-related information: The processing of "profiles with user-related information," or "profiles" for short, encompasses any type of automated processing of personal data that consists of using this personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may involve different information relating to demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g., interests in certain content or products, click behavior on a website, or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities logged in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details about system usage or operation. Log data is often used for analyzing system problems, security monitoring, or generating performance reports.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate visitor traffic on an online offering and may include visitors' behavior or interests in particular information, such as website content. Using reach analysis, operators of online offerings can, for example, determine when users visit their websites and which content interests them. This allows them, for example, to better adapt website content to visitors' needs. Pseudonymous cookies and web beacons are often used for reach analysis purposes in order to recognize returning visitors and thus obtain more accurate analyses of the use of an online offering.
- Remarketing: "Remarketing" or "retargeting" refers to the practice of, for example, recording for advertising purposes which products a user was interested in on a website, in order to remind the user of these products on other websites, e.g., through advertisements.
- Tracking: "Tracking" refers to the ability to trace user behavior across multiple online offerings. As a rule, behavioral and interest information relating to the online offerings used is stored in cookies or on the servers of tracking technology providers (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
- Controller: The "controller" is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, whether collecting, evaluating, storing, transmitting, or deleting it.
- Contract data: Contract data is specific information relating to the formalization of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged, or sold. This category of data is essential for managing and fulfilling contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the contract's start and end dates, the type of services or products agreed upon, pricing agreements, payment terms, termination rights, renewal options, and special terms or clauses. It serves as the legal basis for the relationship between the parties and is essential for clarifying rights and obligations, enforcing claims, and resolving disputes.
- Payment data: Payment data includes all information required to process payment transactions between buyers and sellers. This data is crucial for e-commerce, online banking, and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction dates, verification numbers, and billing information. Payment data may also include information about payment status, chargebacks, authorizations, and fees.
- Audience targeting: Audience targeting (also known as "custom audiences") refers to determining target groups for advertising purposes, e.g., displaying advertisements. For example, a user's interest in certain products or topics on the internet may be used to infer that this user is interested in advertisements for similar products or the online shop where they viewed the products. "Lookalike audiences" (or similar audiences) refers to displaying content deemed suitable to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are typically used for the purposes of creating custom audiences and lookalike audiences.
Created with the privacy policy generator Datenschutz-Generator.de from Dr. Thomas Schwenke (translated from the original German text).