Privacy policy
Preamble
Table of contents
Preamble Person responsible Contact data protection officer Overview of processing Relevant legal bases Security measures Transmission of personal data International data transfers Deletion of data Rights of the data subjects Use of cookies Business services Providers and services used in the course of business activities Payment procedure Provision of the online offer and web hosting Blogs and publication media Contact and inquiry management Chatbots and chat functions Newsletter and electronic notifications Web analysis, monitoring and optimization Online marketing Customer reviews and evaluation process Presence in social networks (social media) Plugins and embedded functions and content Amendment and updating of the privacy policy Definitions of terms
Person responsible
Contact data protection officer
Relevant legal bases
Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) - The data subject has given their consent to the processing of their personal data for one or more specific purposes. Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject. Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
Overview of processing
Types of data processed
Inventory data. Payment data. Location data. Contact details. Content data. Contract data. Usage data. Meta, communication and process data... Contact information (Facebook). Event data (Facebook).
Categories of affected persons
Customers. Interested parties. Communication partner. Users. Business and contractual partners.
Purposes of the processing
Provision of contractual services and customer service. Contact requests and communication. Safety measures. Direct marketing. Reach measurement. Tracking. Office and organizational procedures. Conversion measurement. Click tracking. Target group formation. A/B tests. Managing and responding to inquiries. Feedback. Heatmaps. Marketing. Profiles with user-related information. Provision of our online offer and user-friendliness. Information technology infrastructure.
Security measures
Transmission of personal data
International data transfers
Trans-Atlantic Data Privacy Framework (TADPF): As part of the so-called „Trans-Atlantic Data Privacy Framework” (TADPF), the EU Commission has also recognized the level of data protection for certain companies from the USA. The list of certified companies as well as further information on the TADPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Information in German and other languages can be found on the website of the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_de We also inform you about the companies we use that are certified under the Trans-Atlantic Data Privacy Framework.
Deletion of data
Rights of the data subjects
Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. If the personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. Right to withdraw consent: You have the right to withdraw your consent at any time. Right to information: You have the right to request confirmation as to whether the data in question is being processed and to request information about this data as well as further information and a copy of the data in accordance with the legal requirements. Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the correction of incorrect data concerning you. Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to demand that data concerning you be deleted immediately or, alternatively, to demand that the processing of the data be restricted in accordance with the legal requirements. Right to data portability: You have the right to receive the data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format in accordance with the legal requirements or to request its transmission to another controller. Complaint to supervisory authority: In accordance with the statutory provisions and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you are habitually resident, the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Use of cookies
Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their end device (e.g. browser or mobile application). Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. The user data collected with the help of cookies can also be used to measure reach. If we do not provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and can be stored for up to two years.
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Processing of cookie data on the basis of consent: We use a cookie consent management procedure in which the user's consent to the use of cookies or the processing and providers named in the cookie consent management procedure can be obtained, managed and revoked by the user. The declaration of consent is stored so that it does not have to be requested again and the consent can be proven in accordance with the legal obligation. Consent can be stored on the server and/or in a cookie (so-called opt-in cookie or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following information applies: Consent may be stored for up to two years. A pseudonymous user identifier is created and stored with the time of consent, information on the scope of consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). BorlabsCookie: Cookie consent management; Service provider: Hosted locally on our server, no data transfer to third parties; Website: https://de.borlabs.io/borlabs-cookie/ ;Further information: An individual user ID, language and types of consent and the time they were given are stored on the server and in the cookie on the user's device.
Business services
Processed data types: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status), video and audio data from meetings. Persons concerned: Customers; interested parties; business and contractual partners. Purposes of the processing: Provision of contractual services and customer service; security measures; contact requests and communication; office and organizational procedures; managing and responding to requests; optimizing sales processes Legal basis: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Customer account: Customers can create an account within our online offering (e.g. customer or user account, "customer account" for short). If it is necessary to register a customer account, customers will be informed of this and of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration process and subsequent logins and use of the customer account, we store the IP addresses of customers together with the access times in order to be able to prove registration and prevent any misuse of the customer account. If the customer account has been terminated, the customer account data will be deleted after the termination date, unless it is stored for purposes other than provision in the customer account or must be stored for legal reasons (e.g. internal storage of customer data, order processes or invoices). It is the customer's responsibility to back up their data when the customer account is terminated; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Store and e-commerce: We process our customers' data in order to enable them to select, purchase or order the selected products, goods and associated services, as well as their payment and delivery or execution. If necessary for the execution of an order, we use service providers, in particular postal, forwarding and shipping companies, to carry out the delivery or execution for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is marked as such in the order or comparable purchase process and includes the information required for delivery or provision and billing as well as contact information in order to be able to hold any consultations; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Online courses and online training: We process the data of the participants of our online courses and online training courses (uniformly referred to as "participants") in order to be able to provide them with our course and training services. The data processed in this context, the type, scope, purpose and necessity of its processing are determined by the underlying contractual relationship. The data generally includes information on the courses and services used and, if part of our range of services, personal specifications and results of the participants. The forms of processing also include the performance assessment and evaluation of our services and those of the course and training instructors; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Providers and services used in the course of business activities
Processed data types: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, duration, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Customers; interested parties; users (e.g. website visitors, users of online services); business and contractual partners; communication partners. Purposes of the processing: Provision of contractual services and customer support; Office and organizational procedures; Web Analytics (e.g. access statistics, recognition of returning visitors); Profiles with user-related information (Creating user profiles); Direct marketing (e.g. by e-mail or postal); Marketing. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
HubSpot: Chatbot and assistance software and associated services; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .HubSpot: Customer management as well as process and sales support with personalized customer care with multi-channel communication, i.e. management of customer inquiries from different channels as well as with analysis and feedback functions; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .HubSpot: Marketing software for lead generation, marketing automation and analysis; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .HubSpot: E-mail dispatch and automation services; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .HubSpot: Social media publishing, reporting (e.g. traffic sources, access figures, web analysis), contact management (e.g. contact forms, direct communication and user segmentation), landing pages; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .n8n: Automation of processes, consolidation of various services, import and export of personal and contact data and analysis of these processes; Service provider: n8n GmbH, Novalisstr. 10, 10115 Berlin; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://n8n.io ;Privacy policy: https://n8n.io/legal/privacy/ .Glyphic :Automated summaries of sales calls to improve consulting performance and internal sales processes; Service provider: Glyphic AI Limited, One Suffolk Way, Sevenoaks, Kent TN13 1 YL, United Kingdom; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.glyphic.ai ; Privacy policy: https://www.glyphic.ai/privacy-policy ;Appropriateness decision (Ensuring the level of data protection for processing in third countries): https://commission.europa.eu/document/download/a7907f8f-6e1c-4782-a193-d16b2cfe7650_en?filename=JUST_template_comingsoon_standard_26.pdf .Microsoft Teams and Outlook: Provision of calendar, e-mail and meeting functions as well as summary and recording of meetings; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR), Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.microsoft.com/de-de ; Privacy policy https://www.microsoft.com/de-de/privacy?icid=DSM_Footer_Company_Privacy.
Payment procedure
Processed data types: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Customers; interested parties. Purposes of the processing: Provision of contractual services and customer service. Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Giropay: Payment services (technical connection of online payment methods); Service provider: giropay GmbH, An der Welle 4, 60322 Frankfurt, Germany; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.giropay.de ;Privacy policy: https://www.giropay.de/agb/index.html Klarna: Payment services (technical connection of online payment methods); Service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.klarna.com/de ;Privacy policy: https://www.klarna.com/de/datenschutz .PayPal: Payment services (technical connection of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.paypal.com/de ;Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full .Stripe: Payment services (technical connection of online payment methods); Service provider: Stripe, Inc, 510 Townsend Street, San Francisco, CA 94103, USA; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://stripe.com ;Privacy policy: https://stripe.com/de/privacy .
Provision of the online offer and web hosting
Processed data types: Usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status); content data (e.g. entries in online forms). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Provision of our online offer and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.). Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
E-mail dispatch and hosting: The web hosting services we use also include sending, receiving and storing e-mails. For these purposes, the addresses of the recipients and senders as well as other information relating to the sending of e-mails (e.g. the providers involved) and the content of the respective e-mails are processed. The aforementioned data may also be processed for the purpose of detecting SPAM. Please note that e-mails on the Internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but not on the servers from which they are sent and received (unless an end-to-end encryption method is used). We can therefore accept no responsibility for the transmission path of e-mails between the sender and receipt on our server; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Hetzner: Services in the area of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hetzner.com ;Privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz ;Order processing contract: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/ .
Blogs and publication media
Processed data types: Inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Provision of contractual services and customer service; feedback (e.g. collecting feedback via online form); provision of our online services and user-friendliness. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Contact and inquiry management
Processed data types: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Communication partner. Purposes of the processing: Contact requests and communication; Managing and responding to requests; Feedback (e.g. collecting feedback via online form); Provision of our online services and user-friendliness. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Contact form: If users contact us via our contact form, e-mail or other communication channels, we process the data provided to us in this context to process the communicated request; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). HubSpot: Customer management as well as process and sales support with personalized customer care with multi-channel communication, i.e. management of customer inquiries from different channels as well as with analysis and feedback functions; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .
Chatbots and chat functions
Processed data types: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Communication partner. Purposes of the processing: Contact requests and communication; direct marketing (e.g. by e-mail or post). Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
HubSpot: Chatbot and assistance software and associated services; Service provider: HubSpot, Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.hubspot.de ;Privacy policy: https://legal.hubspot.com/de/privacy-policy ;Order processing contract: https://legal.hubspot.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.hubspot.com/dpa .
Use of Google Maps
Use of reCAPTCHA
Use of Facebook components
Newsletter and electronic notifications
Processed data types: Inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status); usage data (e.g. websites visited, interest in content, access times). Persons concerned: Communication partners; customers; interested parties; users (e.g. website visitors, users of online services). Purposes of the processing: Direct marketing (e.g. by e-mail or post); marketing; reach measurement (e.g. access statistics, recognition of returning visitors). Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Possibility of objection (opt-out): You can cancel the receipt of our newsletter at any time, i.e. revoke your consent or object to further receipt. You will find a link to unsubscribe from the newsletter either at the end of each newsletter or you can use one of the contact options listed above, preferably e-mail.
Measurement of opening and click rates: The newsletters contain a so-called "web-beacon", i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use a mailing service provider, from their server. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This information is used for the technical improvement of our newsletter based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. This information is assigned to the individual newsletter recipients and stored in their profiles until they are deleted. The evaluations help us to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users. the measurement of opening rates and click rates as well as the storage of the measurement results in the profiles of the users and their further processing are based on the consent of the users. Unfortunately, it is not possible to revoke the performance measurement separately; in this case, the entire newsletter subscription must be canceled or objected to. In this case, the stored profile information will be deleted; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Brevo: E-mail dispatch and automation services; Service provider: Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.brevo.com/ ;Privacy policy: https://www.brevo.com/legal/privacypolicy/ ;Order processing contract: Provided by the service provider. Zapier: Automation of processes, consolidation of various services, import and export of personal and contact data and analysis of these processes; Service provider: Zapier, Inc, 548 Market St #62411, San Francisco, California 94104, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://zapier.com ;Privacy policy: https://zapier.com/privacy ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://zapier.com/tos (part of the GTC).
WhatsApp Business
Web analysis, monitoring and optimization
Processed data types: Usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles); provision of our online offer and user-friendliness; tracking (e.g. interest/behavior-related profiling, use of cookies); click tracking; A/B tests; heat maps (mouse movements by users that are combined into an overall picture). Safety measures: IP masking (pseudonymization of the IP address). Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Google Analytics 4: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or e-mail addresses. It is used to assign analysis information to an end device in order to recognize which content users have called up within one or more usage processes, which search terms they have used, which they have called up again or which they have interacted with our online offering. The time of use and its duration are also stored, as well as the sources of the users who refer to our online offering and technical aspects of their end devices and browsers. Pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. In Google Analytics, data on geographical location is processed at a higher level by collecting the following metadata based on the IP search: "city" (and the derived latitude and longitude of the city), "continent", "country", "region", "subcontinent" (and the ID-based equivalents). To ensure the protection of user data in the EU, Google receives and processes all user data via domains and servers within the EU. The IP address of users is not logged and is shortened by the last two digits by default. The IP address is shortened on EU servers for EU users. In addition, all sensitive data collected from users in the EU is deleted before it is collected via EU domains and servers; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/ ;Privacy policy: https://policies.google.com/privacy ;Order processing contract: https://business.safety.google/adsprocessorterms/ ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://business.safety.google/adsprocessorterms ;Possibility of objection (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de Settings for the display of advertisements: https://adssettings.google.com/authenticated ;Further information: https://privacy.google.com/businesses/adsservices (Types of processing and data processed). Google Tag Manager: Google Tag Manager is a solution with which we can manage so-called website tags via an interface and thus integrate other services into our online offering (please refer to further information in this privacy policy). The Tag Manager itself (which implements the tags) does not create user profiles or store cookies, for example. Google only learns the IP address of the user, which is necessary to run the Google Tag Manager; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com ;Privacy policy: https://policies.google.com/privacy ;Order processing contract: https://business.safety.google/adsprocessorterms ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://business.safety.google/adsprocessorterms .Hotjar Observe: Software for the analysis and optimization of online offers on the basis of pseudonymous measurements and analyses of user behavior, which may include in particular A/B tests (measurement of the popularity and user-friendliness of different content and functions), measurement of click paths and interaction with content and functions of the online offer (so-called heat maps and recordings); Service provider: Hotjar Ltd, 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta ; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.hotjar.com ;Privacy policy: https://www.hotjar.com/legal/policies/privacy ;Deletion of data: The cookies that Hotjar uses have different "lifespans"; some remain valid for up to 365 days, some only during the current visit; Cookie Policy: https://www.hotjar.com/legal/policies/cookie-information ;Possibility of objection (opt-out): https://www.hotjar.com/legal/compliance/opt-out .Use of an AI-supported chatbot: A chatbot is used on our website, which is provided by the "AI Engine" software and accesses the language models of OpenAI Inc (USA). User input is processed via our server and forwarded to OpenAI in order to generate a suitable response. Personal data that you voluntarily provide in the chat may be processed. The data is transferred to a service provider in a third country (USA) for which there is no adequate level of data protection. The legal basis for the processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time. To do so, please use the page https://privacy.openai.com/policies from OpenAI.
Online marketing
Processed data types: Content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status); event data (Facebook) ("event data" is data that can be transmitted by us to Facebook via Facebook pixels (via apps or other means), for example, and relates to people or their actions; the data includes, for example, information about visits to websites, interactions with content, installations of apps, purchases of products, etc.; the event data is used to form target groups for content and advertising information (custom audiences). The data includes, for example, information about visits to websites, interactions with content, functions, app installations, product purchases, etc.; the event data is processed for the purpose of creating target groups for content and advertising information (custom audiences); event data does not include the actual content (such as comments written), no login information and no contact information (i.e. no names, email addresses and telephone numbers). Event data will be deleted by Facebook after a maximum of two years, the target groups formed from them with the deletion of our Facebook account); contact information (Facebook) ("contact information" is data that (clearly) identifies data subjects, such as names, e-mail addresses and telephone numbers, which can be transmitted to Facebook, e.g. via Facebook pixels or uploads for matching purposes for the purpose of creating custom audiences; after matching for the purpose of creating target groups, the contact information is deleted). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behavioral profiling, use of cookies); conversion measurement (measurement of the effectiveness of marketing measures); target group formation; marketing; profiles with user-related information (creation of user profiles); provision of our online offer and user-friendliness; click tracking. Safety measures: IP masking (pseudonymization of the IP address). Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Possibility of objection (opt-out): We refer to the data protection notices of the respective providers and the opt-out options provided by the providers. If no explicit opt-out option has been specified, you have the option of deactivating cookies in your browser settings. However, this may restrict the functions of our online offer. We therefore recommend the following additional opt-out options, which are summarized for the respective areas: a) Europe: https://www.youronlinechoices.eu . b) Canada: https://www.youradchoices.ca/choices . c) USA: https://www.aboutads.info/choices . d) Cross-territory: https://optout.aboutads.info .
Facebook pixel and target group formation (Custom Audiences): With the help of the Facebook pixel (or comparable functions, for the transmission of event data or contact information by means of interfaces in apps), Facebook is able to determine the visitors of our online offer as a target group for the display of ads (so-called "Facebook ads"). Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to such users on Facebook and within the services of the partners cooperating with Facebook (so-called "Audience Network"). https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who have certain characteristics (e.g. interest in certain topics or products that can be seen from the websites visited) that we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and are not annoying. With the help of the Facebook pixel, we can also track the effectiveness of Facebook ads for statistical and market research purposes by seeing whether users have been redirected to our website after clicking on a Facebook ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.facebook.com ;Privacy policy: https://www.facebook.com/about/privacy ;Further information: Event user data, i.e. behavioral and interest data, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint responsibility ("Addendum for Responsible Parties", https://www.facebook.com/legal/controller_addendum ) is processed. The joint controllership is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.) Advanced matching for the Facebook pixel: In addition to the processing of event data as part of the use of the Facebook pixel (or comparable functions, e.g. in apps), contact information (data identifying individual persons, such as names, email addresses and telephone numbers) is also collected by Facebook within our online offering or transmitted to Facebook. The processing of contact information is used to create target groups (so-called "custom audiences") for the display of content and advertising information based on the presumed interests of users. The collection, transmission and comparison with data available on Facebook is not carried out in plain text, but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After the comparison for the purpose of creating target groups, the contact information is deleted. The contact information is processed on the basis of an order processing contract withMeta Platforms Ireland Limited ("Data Processing Terms ", https://www.facebook.com/legal/terms/dataprocessing ), the "Data security conditions" ( https://www.facebook.com/legal/terms/data_security_terms ) and with regard to processing in the USA on the basis of standard contractual clauses ("Facebook-EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum ). Further information on the processing of contact information can be found in the "Terms of Use for Facebook Business Tools", https://www.facebook.com/legal/technology_terms. ;Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Facebook - target group education via data upload: Creation of target groups for marketing purposes - We transmit contact information (names, email addresses and telephone numbers) in list form to Facebook for the purpose of creating target groups (so-called "custom audiences") for the display of content and advertising information based on the presumed interests of users. The transmission and comparison with data available on Facebook does not take place in plain text, but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After the comparison for the purpose of creating target groups, the contact information is deleted. The contact information is processed on the basis of an order processing contract withMeta Platforms Ireland Limited ("Data Processing Terms ", https://www.facebook.com/legal/terms/dataprocessing ), the "Data security conditions" ( https://www.facebook.com/legal/terms/data_security_terms ) and with regard to processing in the USA on the basis of standard contractual clauses ("Facebook-EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum ). Further information on the processing of contact information can be found in the "Terms of use for Custom Audiences with customer list", https://www.facebook.com/legal/terms/customaudience ;Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.facebook.com ;Privacy policy: https://www.facebook.com/about/privacy ;Order processing contract: https://www.facebook.com/legal/terms/dataprocessing ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum .Facebook ads: Placement of ads within the Facebook platform and evaluation of the ad results; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.facebook.com ;Privacy policy: https://www.facebook.com/about/privacy ;Possibility of objection (opt-out): We refer to the data protection and advertising settings in the user's profile on the Facebook platform as well as in the context of Facebook's consent procedure and Facebook's contact options for exercising information and other data subject rights in Facebook's privacy policy; Further information: Event user data, i.e. behavioral and interest data, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint responsibility ("Addendum for Responsible Parties", https://www.facebook.com/legal/controller_addendum ) is processed. The joint controllership is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.) Google Ads and conversion measurement: Online marketing processes for the purpose of placing content and ads within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who are presumed to be interested in the ads. In addition, we measure the conversion of the ads, i.e. whether users have taken them as an opportunity to interact with the ads and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://marketingplatform.google.com ;Privacy policy: https://policies.google.com/privacy ;Further information: Types of processing and the data processed: https://privacy.google.com/businesses/adsservices Data processing conditions between controllers and standard contractual clauses for third country transfers of data: https://business.safety.google/adscontrollerterms .Extended conversions for Google Ads: When customers click on our Google ads and subsequently use the advertised service (so-called "conversion"), the data entered by the user, such as the e-mail address, name, home address or telephone number, can be transmitted to Google. The hash values are then compared with users' existing Google accounts in order to better evaluate and improve user interaction with the ads (e.g. clicks or views) and thus their performance; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://support.google.com/google-ads/answer/9888656 .Google Adsense with personalized ads: We use the Google Adsense service with personalized ads, with the help of which ads are displayed within our online offer and we receive remuneration for their display or other use; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com ;Privacy policy: https://policies.google.com/privacy ;Further information: Types of processing and the data processed: https://privacy.google.com/businesses/adsservices ; Data processing conditions for Google advertising products: Information on the services Data processing terms between controllers and standard contractual clauses for third country transfers of data: https://business.safety.google/adscontrollerterms .Google Adsense with non-personalized ads: We use the Google Adsense service with non-personalized ads, with the help of which ads are displayed within our online offer and we receive remuneration for their display or other use; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com ;Privacy policy: https://policies.google.com/privacy ;Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices Google Ads Controller-Controller Data Protection Terms and standard contractual clauses for data transfers to third countries: https://business.safety.google/adscontrollerterms .Instagram ads: Placement of advertisements within the Instagram platform and evaluation of the advertising results; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.instagram.com ;Privacy policy: https://instagram.com/about/legal/privacy ;Possibility of objection (opt-out): We refer to the data protection and advertising settings in the user's profile on the Instagram platform as well as in the context of Instagram's consent procedure and Instagram's contact options for exercising information and other data subject rights in Instagram's privacy policy; Further information: Event user data, i.e. behavioral and interest data, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint responsibility ("Addendum for Responsible Parties", https://www.facebook.com/legal/controller_addendum ) is processed. The joint controllership is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.) LinkedIn: Insights tag / conversion measurement; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.linkedin.com ;Privacy policy: https://www.linkedin.com/legal/privacy-policy Cookie Policy: https://www.linkedin.com/legal/cookie_policy ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.linkedin.com/dpa ;Possibility of objection (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out .UTM parameters: Analyzing sources and user actions based on an extension of web addresses referring to us with an additional parameter, the "UTM" parameter. For example, a UTM parameter "utm_source=platformX &utm_medium=video" can tell us that a person clicked the link on platform X within a video. The UTM parameters provide information about the source of the link, the medium used (e.g. social media, website, newsletter), the type of campaign or the content of the campaign (e.g. post, link, image and video). We can use this information, for example, to check our visibility on the internet or the effectiveness of our campaigns; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). TikTok Ads, conversion tracking and target groups We use TikTok's advertising services to display advertisements for our offer on TikTok, to measure their success and to form suitable target groups. Provider Within the European Economic Area, the advertising services are provided by TikTok Technology Limited, The Sandyford Building, Sandyford Business District, Dublin 18, Ireland, together with TikTok Information Technologies UK Limited. TikTok's privacy policy is available at https://www.tiktok.com/legal/page/eea/privacy-policy/de .TikTok Pixel and Events API We use the TikTok pixel and the Events API to record user actions on our website (e.g. page views, registrations for consultations, requests for information material). This event data is transmitted to TikTok in order to measure and optimize the delivery and success of our ads. We have concluded a joint controllership agreement with TikTok for the joint processing that takes place within the scope of the pixel (available at https://www.tiktok.com/legal/page/global/tiktok-analytics-joint-controller-addendum/de ). Event data is stored in accordance with TikTok's specifications and then deleted. Contact information (matching) To ensure that our advertising is as targeted as possible, we transmit contact information from our customer management system (in particular e-mail addresses, telephone numbers or names) to TikTok in pseudonymized form (SHA-256 hash). TikTok does not receive any clear data. The hash values are compared with the hashes stored at TikTok. Data that does not lead to a match is deleted by TikTok after the comparison has been completed. Custom audiences (target groups from customer lists) We transmit contact information in list form to TikTok to form target groups („Custom Audiences“). On this basis, we can target existing interested parties or, conversely, exclude them from advertising delivery in order to avoid duplicate approaches. Lookalike Audiences Based on these target groups, we also have TikTok calculate statistical twin groups („lookalike audiences“), i.e. user groups that are similar to our existing interested parties. No additional clear data from the data transmitted by us is passed on to third parties for this purpose. Conversion feedback from the CRM When interested parties reach certain stages in our CRM (e.g. consultation appointment attended, offer received, booking), we transmit the associated events to TikTok in pseudonymized form so that TikTok can link this conversion to the original ad. Legal basis Processing is based on your consent, which you can give via our cookie banner. You can revoke this consent at any time with effect for the future. In the event of revocation, we will automatically remove you from the TikTok target groups. Third country transfer Insofar as personal data is transferred to countries outside the European Economic Area, this is done on the basis of the EU standard contractual clauses. The relevant contractual documents of TikTok are available at https://ads.tiktok.com/i18n/official/policy/data-processing-terms .Objection and further information You can object to the processing of your data for advertising purposes at any time by adjusting your consent in the cookie banner or by contacting us. You can find information on the advertising settings for your TikTok account at https://support.tiktok.com/de/account-and-privacy/account-privacy-settings/ad-settings .
Customer reviews and evaluation process
Processed data types: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Customers; users (e.g. website visitors, users of online services). Purposes of the processing: Feedback (e.g. collecting feedback via online form); marketing. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Google customer reviews: Service for obtaining and/or presenting customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); AGB: https://support.google.com/merchants/topic/7259129?hl=de&ref_topic=7257954 ;Privacy policy: https://policies.google.com/privacy ;Further information: As part of the collection of customer reviews, an identification number and time for the business transaction to be evaluated, in the case of review requests sent directly to customers, the customer's e-mail address and their country of residence as well as the review details themselves are processed; further information on the types of processing and the data processed: https://privacy.google.com/businesses/adsservices ; Data processing conditions for Google advertising products: Information on the services Data processing terms between controllers and standard contractual clauses for third country transfers of data: https://business.safety.google/adscontrollerterms .Trustpilot: Evaluation platform; Service provider: Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://de.trustpilot.com ;Privacy policy: https://de.legal.trustpilot.com/end-user-privacy-terms .
Presence in social networks (social media)
Processed data types: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Contact requests and communication; feedback (e.g. collecting feedback via online form); marketing. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Instagram: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com ;Privacy policy: https://instagram.com/about/legal/privacy .Facebook pages: Profiles within the social network Facebook - We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data from visitors to our Facebook page (so-called "fan page"). This data includes information about the types of content users view or interact with, or the actions they take (see "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy ), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see "Device information" in the Facebook Data Policy: https://www.facebook.com/policy ). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, known as "Page Insights", to Page owners to help them understand how people interact with their Pages and the content associated with them. We have concluded a special agreement with Facebook ("Information on Page Insights", https://www.facebook.com/legal/terms/page_controller_addendum ), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfill the rights of data subjects (i.e. users can, for example, send information or deletion requests directly to Facebook). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Information on Page Insights" ( https://www.facebook.com/legal/terms/information_about_page_insights_data );Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.facebook.com ;Privacy policy: https://www.facebook.com/about/privacy ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum ;Further information: Agreement on joint responsibility: https://www.facebook.com/legal/terms/information_about_page_insights_data . The joint responsibility is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.) LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.linkedin.com ;Privacy policy: https://www.linkedin.com/legal/privacy-policy ;Order processing contract: https://legal.linkedin.com/dpa ;Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.linkedin.com/dpa ;Possibility of objection (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out .Twitter: Social network; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland, parent company: Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Privacy policy: https://twitter.com/privacy , (Settings: https://twitter.com/personalization ).Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.xing.de ;Privacy policy: https://privacy.xing.com/de/datenschutzerklaerung .
Plugins and embedded functions and content
Processed data types: Usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time data, identification numbers, consent status); inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); location data (information on the geographical position of a device or person). Persons concerned: Users (e.g. website visitors, users of online services). Purposes of the processing: Provision of our online services and user-friendliness; provision of contractual services and customer service. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate software into our online offering that we retrieve from servers of other providers (e.g. function libraries that we use for the purpose of displaying or user-friendliness of our online offering). The respective providers collect the IP address of the users and can process it for the purpose of transmitting the software to the user's browser and for security purposes, as well as for the evaluation and optimization of their offer. - We integrate software into our online offering that we retrieve from servers of other providers (e.g. function libraries that we use for the purpose of displaying or user-friendliness of our online offering). The respective providers collect the IP address of the user and can process it for the purpose of transmitting the software to the user's browser and for security purposes, as well as for the evaluation and optimization of their offer; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Google Fonts (provision on own server): Provision of font files for the purpose of a user-friendly presentation of our online offer; Service provider: The Google Fonts are hosted on our server, no data is transmitted to Google; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Google Maps: We integrate the maps of the "Google Maps" service provided by Google. The processed data may include, in particular, IP addresses and user location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://mapsplatform.google.com/ ;Privacy policy: https://policies.google.com/privacy .reCAPTCHA: We integrate the "reCAPTCHA" function in order to be able to recognize whether entries (e.g. in online forms) are made by humans and not by automatically acting machines (so-called "bots"). The processed data may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keyboard strokes, time spent on websites, previously visited websites, interactions with ReCaptcha on other websites, possibly cookies and results of manual recognition processes (e.g. answering questions asked or selecting objects in images). Data processing is carried out on the basis of our legitimate interest in protecting our online offering from abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.google.com/recaptcha/ ;Privacy policy: https://policies.google.com/privacy ;Possibility of objection (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de Settings for the display of advertisements: https://adssettings.google.com/authenticated .YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.youtube.com ;Privacy policy: https://policies.google.com/privacy ;Possibility of objection (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de Settings for the display of advertisements: https://adssettings.google.com/authenticated .Font Awesome (obtained from the provider's server): Obtaining fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation and consideration of possible licensing restrictions. The provider of the fonts is informed of the user's IP address so that the fonts can be made available in the user's browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) are transmitted that are necessary for the provision of the fonts depending on the devices used and the technical environment; Service provider: Fonticons, Inc. 6 Porter Road Apartment 3R, Cambridge, MA 02140, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://fontawesome.com/ ;Privacy policy: https://fontawesome.com/privacy .3Q GmbH: Provision of videos; Service provider: 3Q GmbHBelfortstr. 581667 Munich; Website: https://3q.video/ .
Amendment and updating of the privacy policy
Definitions of terms
A/B tests: A/B tests are used to improve the user-friendliness and performance of online offers. For example, users are shown different versions of a website or its elements, such as input forms, on which the placement of the content or the labels of the navigation elements can differ. The behavior of the users, e.g. longer time spent on the website or more frequent interaction with the elements, can then be used to determine which of these websites or elements are more likely to meet the needs of the users. Heatmaps: "Heatmaps" are mouse movements of users that are summarized into an overall picture, which can be used, for example, to recognize which website elements are preferred and which website elements users prefer less. Click tracking: Click tracking allows us to monitor the movements of users within an entire online offering. As the results of these tests are more accurate if the interaction of users can be tracked over a certain period of time (e.g. so that we can find out whether a user likes to return), cookies are usually stored on the user's computer for these test purposes. Conversion measurement: Conversion measurement (also known as "visit action evaluation") is a process that can be used to determine the effectiveness of marketing measures. For this purpose, a cookie is usually stored on the user's device within the websites on which the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the ads we placed on other websites were successful. Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Profiles with user-related information: The processing of "profiles with user-related information", or "profiles" for short, includes any type of automated processing of personal data that consists of using this personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information relating to demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behavior on a website or location). Cookies and web beacons are often used for profiling purposes. Reach measurement: Reach measurement (also known as web analytics) is used to evaluate the flow of visitors to an online offering and can include the behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, website owners can, for example, recognize at what time visitors visit their website and what content they are interested in. This allows them to better adapt the content of the website to the needs of their visitors, for example. For the purposes of reach analysis, pseudonymous cookies and web beacons are often used to recognize returning visitors and thus obtain more precise analyses of the use of an online offer. Location data: Location data is generated when a mobile device (or another device with the technical requirements for location determination) connects to a radio cell, a WLAN or similar technical means and functions of location determination. Location data is used to indicate the geographically determinable position on earth at which the respective device is located. Location data can be used, for example, to display map functions or other location-dependent information. Tracking: The term "tracking" is used when the behavior of users can be tracked across several online offerings. As a rule, behavioral and interest information is stored in cookies or on the servers of the providers of the tracking technologies with regard to the online offers used (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to correspond to their interests. Responsible person: The "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collection, analysis, storage, transmission or deletion. Target group formation: Custom audiences are defined as target groups for advertising purposes, e.g. the display of advertisements. For example, based on a user's interest in certain products or topics on the Internet, it can be concluded that this user is interested in advertisements for similar products or the online store in which they viewed the products. In turn, "lookalike audiences" (or similar target groups) are when the content deemed suitable is displayed to users whose profiles or interests presumably correspond to the users for whom the profiles were created. Cookies and web beacons are generally used for the purpose of creating custom audiences and lookalike audiences.