Link to the imprint:
Types of processed data
– Inventory data (e.g., person master data, name or address).
– contact details (e.g., e-mail).
– content data (e.g., text input, photographs, videos).
– usage data (e.g., websites visited, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).
Categories of affected persons
Visitors and users of the online offer (hereinafter we refer to the affected persons as “users”).
Purpose of processing
– Provision of the online offer, its functions and contents.
– Answering contact requests and communicating with users.
– Safety measures.
– Reach Measurement / Marketing
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter the “data subject”); a natural person is considered as identifiable, which can be identified directly or indirectly, in particular by means of assignment to an identifier such as a name, to an identification number, to location data, to an online identifier (e.g. cookie) or to one or more special features, are the expression of the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person.
“Processing” means any process performed with or without the aid of automated procedures, or any such process associated with personal data. The term covers a wide range and covers practically every handling of data.
“Pseudonymisation” means the processing of personal data in such a way that the personal data can no longer be assigned to a specific data subject without additional information being provided, provided that such additional information is kept separate and subject to technical and organizational measures to ensure that the personal data not assigned to an identified or identifiable natural person.
“Profiling” means any kind of automated processing of personal data which involves the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular aspects relating to job performance, economic situation, health, personal To analyze or predict preferences, interests, reliability, behavior, whereabouts, or relocation of that natural person.
‘Responsible person’ means the natural or legal person, public authority, body or body which, alone or in concert with others, decides on the purposes and means of processing personal data.
Relevant legal bases
In accordance with Art. 13 GDPR, we inform you about the legal basis of our data processing. For users within the scope of the General Data Protection Regulation (GDPR), i. the EU and the EEC, if the legal basis in the data protection declaration is not mentioned, the following applies:
The legal basis for obtaining consent is Article 6 (1) lit. a and Art. 7 GDPR;
The legal basis for the processing for the performance of our services and the execution of contractual measures as well as the response to inquiries is Art. 6 para. 1 lit. b GDPR.
The legal basis for processing in order to fulfill our legal obligations is Art. 6 (1) lit. c GDPR;
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR as legal basis.
The legal basis for the processing required to carry out a task in the public interest or in the exercise of official authority which has been delegated to the controller is Article 6 (1) lit. e GDPR.
The legal basis for processing in order to safeguard our legitimate interests is Article 6 (1) lit. f GDPR.
The processing of data for purposes other than those for which they were collected is governed by the provisions of Article 6 (4) GDPR.
The processing of special categories of data (pursuant to Art. 9 (1) GDPR) is governed by the provisions of Art. 9 (2) GDPR.
We comply with legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different likelihood and severity of the risk to the rights and freedoms of natural persons, appropriate technical and organizational Measures to ensure a level of protection appropriate to the risk.
Measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as their access, input, disclosure, availability and disconnection. In addition, we have established procedures to ensure the enjoyment of data subject rights, the erasure of data and the response to data compromise. Furthermore, we consider the protection of personal data already in the development, or selection of hardware, software and procedures, according to the principle of data protection through technology design and privacy-friendly default settings.
Collaboration with contract processors, joint controllers and third parties
“Processor” means a natural or legal person, public authority, body or body that processes personal data on behalf of the controller.
If, in the context of our processing, we disclose data to other persons and companies (contract processors, joint controllers or third parties), transmit them to them or otherwise grant access to the data, this will only be done on the basis of a legal permission (eg if the data has been transmitted to third parties, such as payment service providers, to fulfill the contract), users have consented to a legal obligation to do so or on the basis of our legitimate interests (eg the use of agents, webhosters, etc.).
Insofar as we disclose data to other companies in our group, convey it or otherwise grant access to it, this is done in particular for administrative purposes as a legitimate interest and, moreover, on a basis that complies with the legal requirements.
Transfers to third countries
If we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA) or the Swiss Confederation) or in the context of the use of third party services or disclosure, or transmission of data to other persons or companies This will only happen if it is to fulfill our (pre) contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to express consent or contractually required transmission, we process or disclose the data only in third countries with a recognized level of privacy, including those certified under the Privacy Shield, or on the basis of specific warranties, such as limited liability. contractual obligation by so-called standard protection clauses of the European Commission, the existence of certifications or binding internal data protection regulations (Art. 44 to 49 GDPR, information page of the European Commission).
Rights of data subjects
You have the right to ask for confirmation as to whether such data is being processed and for information about this data, as well as for further information and copy of the data in accordance with legal requirements.
In accordance with the statutory provisions, you have the right to demand the completion of the data concerning you or the correction of the incorrect data concerning you.
In accordance with the legal requirements, they have the right to demand that the relevant data be deleted immediately, or alternatively to demand a restriction of the processing of the data in accordance with the statutory provisions.
You have the right to request that the data relating to you provided to us be obtained in accordance with the statutory requirements and to request their transmission to other persons responsible.
They also have the right, in accordance with the statutory provisions, to submit a complaint to the competent supervisory authority.
You have the right to revoke granted consent with effect for the future.
Right of objection
You may object to the future processing of your data in accordance with legal requirements at any time. The objection may in particular be made against processing for direct marketing purposes.
Cookies and right to object to direct mail
“Cookies” are small files that are stored on users’ computers. Different information can be stored within the cookies. A cookie serves primarily to store the information about a user (or the device on which the cookie is stored) during or after his visit to an online offer. Temporary cookies, or “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online service and closes his browser. In such a cookie, e.g. the contents of a shopping cart are stored in an online shop or a login status. “Persistent” or “persistent” refers to cookies that remain stored even after the browser has been closed. Thus, e.g. the login status will be saved if users visit it after several days. Likewise, in such a cookie the interests of the users can be stored, which are used for range measurement or marketing purposes. A “third-party cookie” refers to cookies that are offered by providers other than the person responsible for providing the online offer (otherwise, if only their cookies are called “first-party cookies”).
If users do not want cookies stored on their machine, they will be asked to disable the option in their browser’s system settings. Saved cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.
Deletion of data
The data processed by us will be deleted or restricted in accordance with legal requirements. Unless explicitly stated in this privacy statement, the data stored by us will be deleted as soon as they are no longer necessary for their intended purpose and the deletion does not conflict with any statutory storage requirements.
Unless the data is deleted because it is required for other and legally permitted purposes, its processing will be restricted. That the data is blocked and not processed for other purposes. This applies, for example for data that must be kept for commercial or tax reasons.
In addition, we process
– contract data (e.g., subject, term, customer category).
– Payment data (e.g., bank details, payment history)
by our customers, prospects and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.
Participation in Affiliate Affiliate Programs
Within our online offer, we rely on our legitimate interests (i.e., interest in the analysis, optimization and economical operation of our online offer) acc. Art. 6 para. 1 lit. f GDPR industry-standard tracking measures as required for the operation of the affiliate system. Below we clarify the users about the technical background.
The services offered by our contractual partners can also be advertised and linked to other websites (so-called affiliate links or after-buy systems, if, for example, links or services of third parties are offered after conclusion of a contract). The operators of the respective websites receive a commission if users follow the affiliate links and then take advantage of the offers.
In conclusion, our online offering requires us to be able to keep track of whether users who are interested in affiliate links and/or the offers available to us, then take advantage of the offers on the affiliate links or our online platform. For this, the affiliate links and our offers are supplemented by certain values that are part of the link or otherwise, e.g. in a cookie, can be set. The values include in particular the source website (referrer), time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user, as well as tracking specific values such as Ad ID, affiliate ID, and categorizations.
The online user IDs used by us are pseudonymous values. That the online identifiers themselves do not contain personal data such as names or e-mail addresses. They only help us to determine if the same user who clicked on an affiliate link or was interested in an offer through our online offer, perceived the offer, i. e.g. has signed a contract with the provider. However, the online identification is personal insofar as the partner company and also us, the online identification together with other user data are available. Only in this way can the partner company tell us whether the user has taken up the offer and we, e.g. can pay the bonus.
Comments and posts
If users leave comments or other contributions, their IP addresses based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR be stored for 7 days. This is for our own safety, if someone leaves illegal content in comments and contributions (insults, prohibited political propaganda, etc.). In this case, we may be sued for the comment or post and are therefore interested in the identity of the author.
Furthermore, we reserve the right, in accordance with our legitimate interests. Art. 6 para. 1 lit. f. GDPR to process the information of users for the purpose of spam detection.
The information provided in the comments and contributions to the person, any contact and website information as well as the content information, are stored by us until the opposition of the users permanently.
Akismet anti-spam check
Our online offering uses the “Akismet” service offered by Automattic Inc., 60 29th Street # 343, San Francisco, CA 94110, USA. The use is based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f) GDPR. With the help of this service, comments of real people are distinguished from spam comments. All comment information is sent to a server in the US, where it is analyzed and stored for four days for comparison. If a comment has been classified as spam, the data will be stored beyond that time. This information includes the name entered, the email address, the IP address, the comment content, the referrer, details of the browser used, the computer system and the time of the entry.
For more information about the collection and use of data by Akismet, see the Automattic Privacy Notice: https://automattic.com/privacy/.
Users are welcome to use pseudonyms or refrain from entering the name or email address *. You can completely prevent the transfer of data by not using our commenting system. That would be a shame, but unfortunately we see no other alternatives that work equally effectively.
Get profile pictures from Gravatar
We use the Gravatar service of Automattic Inc., 60 29th Street # 343, San Francisco, CA 94110, USA, within our online offering and specifically on the blog.
Gravatar is a service that allows users to log in and submit profile pictures and their email addresses. If users with the respective e-mail address on other online sites (especially in blogs) leave posts or comments, so their profile pictures can be displayed next to the posts or comments. For this purpose, the e-mail address communicated by the users to Gravatar is transmitted in encrypted form in order to check whether a profile has been stored for it. This is the sole purpose of sending the e-mail address and it will not be used for other purposes, but will be deleted afterwards.
The use of Gravatar is based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f) GDPR, because with the help of Gravatar we offer the post and comment writers the opportunity to personalize their posts with a profile picture.
By displaying the images, Gravatar has learned the IP address of the users, as this is necessary for communication between a browser and an online service. For more information about Gravatar’s collection and use of data, see the Automattic Privacy Notice: https://automattic.com/privacy/.
If users do not want a user picture linked to their email address on Gravatar to appear in the comments, you should use an email address that is not registered with Gravatar to comment. We also point out that it is also possible to use an anonymous or even no e-mail address if the users do not want their own e-mail address to be sent to Gravatar. Users can completely prevent the transfer of data by not using our commenting system.
Retrieval of emojis and smilies
Within our WordPress blog, graphic emojis (or smilies), i. small graphical files expressing feelings used by external servers. Here, the providers of the server, the IP addresses of the users. This is necessary so that the emojie files can be transmitted to the users’ browsers. The Emojie service is offered by Automattic Inc., 60 29th Street # 343, San Francisco, CA 94110, USA. Automattic Privacy Notice: https://automattic.com/privacy/. The server domains used are sworg and twemoji.maxcdn.com, which to our knowledge are so-called content delivery networks, that is, servers that only provide fast and secure transmission of the files and users’ personal data be deleted after transmission.
The use of emojis is based on our legitimate interests, i. Interest in an attractive design of our online offer acc. Art. 6 para. 1 lit. f. GDPR.
Hosting and e-mailing
The hosting services we use are designed to provide the following services: infrastructure and platform services, computing capacity, storage and database services, e-mail delivery, security and technical maintenance services we use to operate this online service.
Here we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer acc. Art. 6 para. 1 lit. f GDPR i.V.m. Art. 28 GDPR (conclusion of contract processing contract).
Collection of access data and log files
We, or our hosting provider, collects on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR Data on every access to the server on which this service is located (so-called server log files). The access data includes the name of the retrieved web page, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider,
Logfile information is stored for security purposes (for example, to investigate abusive or fraudulent activities) for a maximum of 7 days and then deleted. Data whose further retention is required for evidential purposes are excluded from the erasure until the final clarification of the incident.
Google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on the activities within this online offering and to provide us with further services related to the use of this online offer and the internet usage. In this case, pseudonymous user profiles of the processed data can be created.
We only use Google Analytics with activated IP anonymization. This means that the IP address of the users is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there.
The IP address submitted by the user’s browser will not be merged with other data provided by Google. Users can prevent the storage of cookies by setting their browser software accordingly; Users may also prevent the collection by Google of the data generated by the cookie and related to their use of the online offer as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http: // tools .google.com / dlpage / gaoptout? hl = en.
If we ask users for consent (for example, in the context of a cookie consent), the legal basis of this processing is Art. 6 (1) lit. a. GDPR. Otherwise, the personal data of the users are processed on the basis of our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Article 6 (1) (f) of the GDPR).
As far as data is processed in the US, we point out that Google is certified under the Privacy Shield Agreement, thereby ensuring compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active) ,
The personal data of users will be deleted or anonymized after 14 months.
Online presence in social media
We maintain online presence within social networks and platforms in order to communicate with customers, prospects and users active there and to inform them about our services.
We point out that data of the users outside the area of the European Union can be processed. This may result in risks to users because, e.g. the enforcement of user rights could be made more difficult. With respect to US providers certified under the Privacy Shield, we point out that they are committed to respecting EU privacy standards.
Furthermore, the data of the users are usually processed for market research and advertising purposes. Thus, e.g. user profiles are created from the user behavior and the resulting interests of the users. The usage profiles may in turn be used to e.g. Place advertisements inside and outside the platforms that are allegedly in line with users’ interests. For these purposes, cookies are usually stored on the computers of the users, in which the user behavior and the interests of the users are stored. Furthermore, in the usage profiles, data can also be stored independently of the devices used by the users (in particular if the users are members of the respective platforms and logged in to them).
The processing of personal data of users is based on our legitimate interests in an effective information of users and communication with users in accordance with. Art. 6 para. 1 lit. f. GDPR. If the users are asked by the respective providers of the platforms for a consent to the above-described data processing, the legal basis of the processing is Art. 6 para. 1 lit. a., Art. 7 GDPR.
For a detailed description of the respective processing and the possibilities of contradiction (opt-out), we refer to the following linked information of the provider.
Also in the case of requests for information and the assertion of user rights *, we point out that these can be claimed most effectively from the providers. Only the providers have access to the data of the users and can directly take appropriate measures and provide information. If you still need help, then you can contact us.
Integration of services and contents of third parties
Based on our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 (1) lit. GDPR), we make use of content or services offered by third-party providers in order to provide their content and services Services, such as Include videos or fonts (collectively referred to as “content”).
This always presupposes that the third-party providers of this content perceive the IP address of the users, since they could not send the content to their browser without the IP address. The IP address is therefore required for the presentation of this content. We endeavor to use only content whose respective providers use the IP address only for the delivery of the content. Third parties may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information, such as visitor traffic, on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may include, but is not limited to, technical information about the browser and operating system, referring web pages, time of visit, and other information regarding the use of our online offer.
Automatically translated by Google Translator. Adjusted by Sonja Kuhl.