Data privacy

Introduction and overview

We have created this privacy statement (version 10/31/2023-112663980) in order to provide you with the best possible information in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws to explain which personal data (data for short) we as the controller - and the processors (e.g. providers) commissioned by us - process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We inform you comprehensively about data that we process about you.

Privacy statements usually sound very technical and use legal terminology. This privacy statement, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. As far as it is conducive to transparency, technical Terms explained in a reader friendly waylinks to further information are provided, and Graphics has been brought into use. In this way, we provide information in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis. This is certainly not possible with the most succinct, unclear and legalistic explanations possible, as is often standard practice on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or two pieces of information that you did not yet know.
If you still have questions, we would like to ask you to contact the responsible office mentioned below or in the imprint, to follow the existing links and to look at further information on third party sites. Our contact details can of course also be found in the imprint.

Area of application

This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of this privacy policy includes:

  • all online presences (websites, online stores) that we operate
  • Social media appearances and e-mail communication
  • Mobile apps for smartphones and other devices

In short: The privacy policy applies to all areas in which personal data is processed in the company in a structured manner via the channels mentioned. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.

Legal basis

In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal basis of the General Data Protection Regulation, which enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course access this EU General Data Protection Regulation online on EUR-Lex, the access point to EU law, at. https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex32016R0679 read up.

We only process your data if at least one of the following conditions applies:

  1. Consent (Article 6 paragraph 1 lit. a DSGVO): You have given us your consent to process data for a specific purpose. An example would be the storage of your entered data of a contact form.
  2. Contract (Article 6(1)(b) GDPR): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
  3. Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
  4. Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and efficiently. This processing is therefore a legitimate interest.

Other conditions such as recording in the public interest, the exercise of official authority and the protection of vital interests do not generally apply to us. If such a legal basis is relevant, it will be indicated at the appropriate point.

In addition to the EU regulation, national laws also apply:

  • In Austria this is the Federal Act on the Protection of Individuals with regard to the Processing of Personal Data (Data Protection Act), in short DSG.
  • In Germany this applies Federal Data Protection Act, in short BDSG.

If other regional or national laws apply, we will inform you of this in the following sections.

Contact details of the person responsible

If you have any questions about data protection or the processing of personal data, you will find the contact details of the person or body responsible below:
Petra Zoffmann
Banngrabenweg 139g
8041 Graz

E-Mail: petra.zoffmann@kuta-lombok.net
Phone: +43 699 111 60 859
Imprint: https://www.maharani-lombok.com/impressum/

Storage duration

The fact that we only store personal data for as long as is absolutely necessary for the provision of our services and products applies as a general criterion at our company. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are required by law to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.

If you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.

We will inform you about the specific duration of the respective data processing below, provided that we have further information on this.

Rights under the General Data Protection Regulation

In accordance with Articles 13, 14 GDPR, we inform you of the following rights to which you are entitled in order to ensure that data is processed in a fair and transparent manner:

  • According to Article 15 GDPR, you have a right to information as to whether we process your data. If this is the case, you have the right to receive a copy of the data and the following information:
    • the purpose for which we carry out the processing;
    • the categories, i.e. the types of data that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
    • that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
    • the origin of the data if we have not collected it from you;
    • whether profiling is carried out, i.e. whether data is automatically analyzed in order to create a personal profile of you.
  • According to Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors.
  • According to Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the erasure of your data.
  • According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.
  • According to Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a commonly used format upon request.
  • According to Article 21 GDPR, you have the right to object, which will result in a change in the processing after enforcement.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
    • If data is used to conduct direct marketing, you may object to this type of data processing at any time. We may not use your data for direct marketing thereafter.
    • If data is used to perform profiling, you can object to this type of data processing at any time. We may not use your data for profiling thereafter.
  • Under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (e.g. profiling).
  • According to Article 77 GDPR, you have the right to lodge a complaint. This means that you can lodge a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights - do not hesitate to contact the responsible body listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the data protection authority, whose website you can find at https://www.dsb.gv.at/ find. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) contact. The following local data protection authority is responsible for our company:

Austria Data Protection Authority

Head: Mag. Dr. Andrea Jelinek
Address:
Barichgasse 40-42, 1030 Wien
Phone:
+43 1 52 152-0
E-mail address:
dsb@dsb.gv.at
Website:
https://www.dsb.gv.at/

Cookies

Cookies summary
👥 Affected parties: Visitors to the website
🤝 Purpose: depending on the respective cookie. You can find more details on this below or from the manufacturer of the software that sets the cookie.
📓 Processed data: Depending on the cookie used. You can find more details on this below or from the manufacturer of the software that sets the cookie.
📅 Storage duration: depending on the cookie, can vary from hours to years
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit.f GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used so that you can better understand the following privacy policy.

Whenever you surf the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing can't be denied: Cookies are really useful helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other applications. HTTP cookies are small files that are stored on your computer by our website. These cookies are automatically placed in the cookie folder, the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following graphic shows a possible interaction between a web browser such as Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.

HTTP Cookie Interaktion zwischen Browser und Webserver

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our website, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans or other "malware". Cookies also cannot access information on your PC.

Cookie data can look like this, for example:

Name: _ga
Value: GA1.2.1326744211.152112663980-9
Intended use: Differentiation of website visitors
Expiration date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What types of cookies are there?

The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly explain the different types of HTTP cookies.

A distinction can be made between 4 types of cookies:

Essential cookies
These cookies are necessary to ensure basic website functions. For example, these cookies are needed when a user places a product in the shopping cart, then continues surfing on other pages and only goes to the checkout later. These cookies ensure that the shopping cart is not deleted even if the user closes their browser window.

Purposeful cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the loading time and the behavior of the website with different browsers.

Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are saved.

Advertising cookies
These cookies are also called targeting cookies. They are used to deliver customized advertising to the user. This can be very practical, but also very annoying.

When you visit a website for the first time, you are usually asked which of these cookie types you would like to allow. And of course this decision is also stored in a cookie.

If you would like to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, dem Request for Comments der Internet Engineering Task Force (IETF) namens "HTTP State Management Mechanism".

Purpose of processing via cookies

The purpose ultimately depends on the cookie in question. You can find more details on this below or from the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are little helpers for many different tasks. Unfortunately, it is not possible to generalize which data is stored in cookies, but we will inform you about the processed or stored data in the following privacy policy.

Storage duration of cookies

The storage period depends on the cookie in question and is specified below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.

You can also influence the storage period yourself. You can delete all cookies manually at any time via your browser (see also "Right to object" below). Furthermore, cookies that are based on consent will be deleted at the latest after you withdraw your consent, whereby the legality of the storage until then remains unaffected.

Right to object - how can I delete cookies?

You decide how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option of deleting, deactivating or only partially allowing cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to find out which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, activate and manage cookies in Chrome

Safari: Managing cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have stored on your computer

Internet Explorer: Deleting and managing cookies

Microsoft Edge: Deleting and managing cookies

If you generally do not want to have cookies, you can set up your browser so that it always informs you when a cookie is to be set. You can then decide for each individual cookie whether or not to allow it. The procedure differs depending on the browser. It is best to search for the instructions in Google using the search term "delete cookies Chrome" or "deactivate cookies Chrome" in the case of a Chrome browser.

Legal basis

The so-called "cookie guidelines" have been in place since 2009. This stipulates that the storage of cookies is a Consent (Article 6(1)(a) GDPR) from you. However, there are still very different reactions to these directives within the EU countries. In Austria, however, this directive was implemented in Section 96 (3) of the Telecommunications Act (TKG). In Germany, the cookie directives have not been implemented as national law. Instead, this directive was largely implemented in Section 15 (3) of the Telemedia Act (TMG).

For strictly necessary cookies, even if no consent has been given, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to provide visitors to the website with a pleasant user experience and certain cookies are often absolutely necessary for this.

If cookies that are not absolutely necessary are used, this will only take place with your consent. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR.

In the following sections, you will be informed in more detail about the use of cookies if the software used uses cookies.

Webhosting introduction

Web hosting summary
👥 Affected parties: Visitors to the website
🤝 Purpose: professional hosting of the website and securing its operation
📓 Processed data: IP address, time of website visit, browser used and other data. You can find more details on this below or from the web hosting provider used.
📅 Storage period: depends on the respective provider, but usually 2 weeks
⚖️ Legal basis: Art. 6 para. 1 lit.f GDPR (legitimate interests)

What is web hosting?

What is web hosting? When you visit websites these days, certain information - including personal data - is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, by the way, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) to the very last subpage (like this one). By domain we mean, for example, example.de or example.com.

If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We'll call it browser or web browser for short.

To display the website, the browser must connect to another computer where the website code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why this is usually done by professional providers. They offer web hosting and thus ensure reliable and error-free storage of website data. A lot of technical terms, but please stay tuned, it will get even better!

When the browser on your computer (desktop, laptop, tablet or smartphone) connects and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time in order to ensure proper operation.

A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the Internet and the hosting provider.

Browser und Webserver

Why do we process personal data?

The purposes of data processing are:

  1. Professional website hosting and operational security
  2. to maintain operational and IT security
  3. Anonymous evaluation of access behavior to improve our offer and, if necessary, for criminal prosecution or prosecution of claims

What data is processed?

Even while you are currently visiting our website, our web server, i.e. the computer on which this website is stored, usually automatically saves data such as

  • the complete Internet address (URL) of the website accessed
  • Browser and browser version (e.g. Chrome 87)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
  • the host name and IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
  • Date and time
  • in files, the so-called web server log files

How long is data stored?

As a rule, the above-mentioned data is stored for two weeks and then automatically deleted. We do not pass this data on, but we cannot rule out the possibility of this data being viewed by the authorities in the event of unlawful conduct.

In short: Your visit is logged by our provider (company that runs our website on special computers (servers)), but we do not pass on your data without your consent!

Legal basis

The lawfulness of the processing of personal data in the context of web hosting results from Art. 6 para. 1 lit. f GDPR (protection of legitimate interests), because the use of professional hosting with a provider is necessary in order to present the company on the Internet in a secure and user-friendly manner and to be able to pursue attacks and claims from this if necessary.

As a rule, there is a contract between us and the hosting provider for order processing in accordance with Art. 28 f. GDPR, which ensures compliance with data protection and guarantees data security.

World4You privacy policy

It is quite possible that you have already heard of the web hosting provider World4You. The web host is particularly popular in Austria. The service provider is the Austrian company World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria.

What is World4You?

The company from the Upper Austrian capital has been active in the web hosting sector since 1998. World4You operates several of its own data centers in Austria and uses its own in-house technology. This ensures fail-safe operation and a fast server connection. As you may have already read in our introduction to web hosting, your data is also transferred to World4You's servers and processed there. This primarily involves technical data such as browser version or operating system, but personal data such as your IP address is also processed.

Why do we use World4You?

Like you, we probably value reliability, speed and security in a website. Even if you call up our website in the middle of the night or we already have a lot of visitors, it has to work perfectly. When you click on subpages, it must not take half an eternity for the page to load completely. And if problems do occur, there should be a good backup system that backs up our content and protects all data. To ensure that everything works to our satisfaction, we naturally need a reliable web host. In World4You, we believe we have found a partner that meets our requirements. World4You has its own data centers and therefore a fixed bandwidth, which makes a website quickly accessible. We also appreciate the company's personal support.

Of course, you can also use this support if you have specific questions about data protection at World4You. We also recommend the website's privacy policy, which you can find at https://www.world4you.com/de/unternehmen/datenschutzerklaerung.html find. The FAQs under https://www.world4you.com/faq/de/dsgvo.html have their own GDPR section, where you can also find lots of useful information.

Website modular systems Introduction

Website builder systems Privacy policy summary
👥 Affected parties: Visitors to the website
🤝 Purpose: Optimization of our service performance
📓 Processed data: Data such as technical usage information such as browser activity, clickstream activity, session heatmaps as well as contact details, IP address or your geographical location. You can find more details on this below in this privacy policy and in the providers' privacy policies.
📅 Storage duration: depends on the provider
⚖️ Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interests), Art. 6 para. 1 lit. a GDPR (consent)

What are website builder systems?

We use a modular website system for our website. Modular systems are special forms of a content management system (CMS). With a modular system, website operators can create a website very easily and without programming knowledge. In many cases, web hosters also offer modular systems. By using a modular system, your personal data can also be collected, stored and processed. In this data protection text, we provide you with general information about data processing by modular systems. You can find more detailed information in the provider's data protection declarations.

Why do we use website builder systems for our website?

The biggest advantage of a modular system is its ease of use. We want to offer you a clear, simple and well-organized website that we can easily operate and maintain ourselves - without external support. A modular system now offers many helpful functions that we can use even without programming knowledge. This allows us to design our web presence according to our wishes and offer you an informative and enjoyable time on our website.

What data is stored by a modular system?

Exactly which data is stored depends, of course, on the website builder system used. Each provider processes and collects different data from the website visitor. As a rule, however, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your website visit are collected. Tracking data (e.g. browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Personal data may also be collected and stored. This usually involves contact data such as email address, telephone number (if you have provided this), IP address and geographical location data. You can find out exactly which data is stored in the provider's privacy policy.

How long and where is the data stored?

We will inform you about the duration of data processing below in connection with the website building block system used, if we have further information on this. You can find detailed information about this in the provider's privacy policy. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. The provider may store your data according to its own specifications, over which we have no influence.

Right of objection

You always have the right to information, correction and deletion of your personal data. If you have any questions, you can also contact the person responsible for the website builder system used at any time. Contact details can be found either in our privacy policy or on the website of the relevant provider.

You can delete, deactivate or manage cookies that providers use for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.

Legal basis

We have a legitimate interest in using a website building block system to optimize our online service and to present it to you in an efficient and user-friendly manner. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use the modular system if you have given your consent.

Insofar as the processing of data is not absolutely necessary for the operation of the website, the data will only be processed on the basis of your consent. This applies in particular to tracking activities. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR.

In this privacy policy, we have provided you with the most important general information about data processing. If you would like more detailed information in this regard, you will find further information - if available - in the following section or in the provider's privacy policy.

WordPress.com privacy policy

We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc, 60 29th Street #343, San Francisco, CA 94110, USA.

Was ist WordPress?

The company saw the light of day in 2003 and quickly became one of the best-known content management systems (CMS) in the world. A CMS is a piece of software that helps us design our website and present content in a beautiful and organized way. Content can be text, audio, and video.
By using WordPress, your personal data may also be collected, stored and processed. As a rule, mainly technical data such as operating system, browser, screen resolution or hosting provider are stored. However, personal data such as IP address, geographical data or contact details may also be processed.

Why do we use WordPress?

Programming is not one of our core competencies. Nevertheless, we want to have a powerful and attractive website that we can also manage and maintain ourselves. With a modular website system or a content management system such as WordPress, we can do just that. With WordPress, we don't have to be programming aces to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without prior technical knowledge. If technical problems occur or we have special requests for our website, there are always our specialists who feel at home in HTML, PHP, CSS and co.

How secure is data transfer with WordPress?

WordPress also processes your data in the USA, among other places. WordPress is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

WordPress also uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, WordPress undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The data processing conditions (Data Processing Agreements), which correspond to the standard contractual clauses, can be found at https://wordpress.com/support/data-processing-agreements/.

You can find out more about the data processed through the use of WordPress.com in the privacy policy on https://automattic.com/de/privacy/.

Social media introduction

Social Media Datenschutzerklärung Zusammenfassung
👥 Affected parties: Visitors to the website
🤝 Purpose: Presentation and optimization of our services, contact with visitors, interested parties, etc., advertising
📓 Processed data: Data such as telephone numbers, email addresses, contact details, user behavior data, information about your device and your IP address.
You can find more details on this in the respective social media tool used.
📅 Storage duration: depending on the social media platforms used
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is social media?

In addition to our website, we are also active on various social media platforms. User data may be processed so that we can target users who are interested in us via the social networks. In addition, elements of a social media platform may also be embedded directly in our website. This is the case, for example, if you click on a social button on our website and are forwarded directly to our social media presence. Social media refers to websites and apps that registered members can use to produce content, share content openly or in specific groups and network with other members.

Why do we use social media?

For years, social media platforms have been the place where people communicate and get in touch online. Our social media presence allows us to bring our products and services closer to interested parties. The social media elements integrated on our website help you to switch to our social media content quickly and without complications.

The data that is stored and processed through your use of a social media channel is primarily for the purpose of carrying out web analyses. The aim of these analyses is to be able to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, the evaluated data can be used to draw conclusions about your interests and create user profiles. This also enables the platforms to present you with customized advertisements. Cookies are usually set in your browser for this purpose, which store data on your usage behavior.

As a rule, we assume that we remain responsible under data protection law, even if we use the services of a social media platform. However, the European Court of Justice has ruled that in certain cases the operator of the social media platform may be jointly responsible with us within the meaning of Art. 26 GDPR. If this is the case, we will point this out separately and work on the basis of an agreement to this effect. The essence of the agreement is then reproduced below for the platform concerned.

Please note that when using the social media platforms or our built-in elements, your data may also be processed outside the European Union, as many social media channels, such as Facebook or Twitter, are American companies. As a result, you may not be able to claim or enforce your rights in relation to your personal data as easily.

What data is processed?

Exactly which data is stored and processed depends on the respective provider of the social media platform. However, it usually involves data such as telephone numbers, email addresses, data that you enter in a contact form, user data such as which buttons you click, who you like or follow, when you visited which pages, information about your device and your IP address. Most of this data is stored in cookies. Data can be linked to your profile, especially if you have a profile on the social media channel you are visiting and are logged in.

All data that is collected via a social media platform is also stored on the provider's servers. This means that only the providers have access to the data and can provide you with the appropriate information or make changes.

If you want to know exactly what data is stored and processed by social media providers and how you can object to data processing, you should carefully read the company's privacy policy. We also recommend that you contact the provider directly if you have any questions about data storage and data processing or wish to assert corresponding rights.

Duration of data processing

We will inform you about the duration of data processing below if we have further information on this. For example, the social media platform Facebook stores data until it is no longer required for its own purposes. However, customer data that is compared with our own user data is deleted within two days. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. If required by law, for example in the case of accounting, this storage period may be exceeded.

Right of objection

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers such as embedded social media elements at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.

As social media tools may use cookies, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

Legal basis

If you have consented to your data being processed and stored by integrated social media elements, this consent is the legal basis for data processing (Art. 6 Abs. 1 lit. a DSGVO). In principle, your data will also be processed on the basis of our legitimate interest if you have given your consent. (Art. 6 Abs. 1 lit. f DSGVO) We store and process your data for the purpose of fast and good communication with you or other customers and business partners. Nevertheless, we only use these tools if you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our data protection text on cookies carefully and consult the privacy policy or cookie guidelines of the respective service provider.

Information on specific social media platforms - if available - can be found in the following sections.

Facebook privacy policy

Facebook privacy policy summary
👥 Affected parties: Visitors to the website
🤝 Purpose: Optimization of our service performance
📓 Processed data: Data such as customer data, user behavior data, information about your device and your IP address.
Mehr Details dazu finden Sie weiter unten in der Datenschutzerklärung.
📅 Storage period: until the data is no longer useful for Facebook's purposes
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What are Facebook tools?

We use selected tools from Facebook on our website. Facebook is a social media network of Meta Platforms Inc. or, for the European region, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. With the help of these tools, we can offer you and people who are interested in our products and services the best possible offer.

If data is collected and forwarded from you via our embedded Facebook elements or via our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this. Facebook is solely responsible for the further processing of this data. Our joint obligations have also been set out in a publicly accessible agreement at https://www.facebook.com/legal/controller_addendum anchored. It states, for example, that we must clearly inform you about the use of Facebook tools on our website. Furthermore, we are also responsible for ensuring that the tools are securely integrated into our website in accordance with data protection law. Facebook, on the other hand, is responsible for the data security of Facebook products, for example. If you have any questions about data collection and data processing by Facebook, you can contact the company directly. If you address the question to us, we are obliged to forward it to Facebook.

Below we provide an overview of the various Facebook tools, what data is sent to Facebook and how you can delete this data.

In addition to many other products, Facebook also offers the so-called "Facebook Business Tools". This is the official name of Facebook. However, as the term is hardly known, we have decided to simply call them Facebook tools. These include, among others:

  • Facebook pixel
  • social plug-ins (such as the "Like" or "Share" button)
  • Facebook Login
  • Account Kit
  • APIs (programming interface)
  • SDKs (collection of programming tools)
  • Platform integrations
  • Plugins
  • Codes
  • Specifications
  • Documentations
  • Technologies and services

Through these tools, Facebook expands services and has the ability to obtain information about user activity outside of Facebook.

Why do we use Facebook tools on our website?

We only want to show our services and products to people who are really interested in them. With the help of advertisements (Facebook ads), we can reach precisely these people. However, Facebook needs information about people's wishes and needs in order to show users suitable advertising. The company is therefore provided with information about user behavior (and contact details) on our website. As a result, Facebook collects better user data and can show interested people suitable advertising about our products or services. The tools thus enable customized advertising campaigns on Facebook.

Facebook calls data about your behavior on our website "event data". This is also used for measurement and analysis services. Facebook can thus create "campaign reports" on our behalf about the impact of our advertising campaigns. Furthermore, analytics give us a better insight into how you use our services, website or products. This allows us to optimize your user experience on our website with some of these tools. For example, you can use the social plug-ins to share content on our site directly on Facebook.

What data is stored by Facebook tools?

By using individual Facebook tools, personal data (customer data) can be sent to Facebook. Depending on the tools used, customer data such as name, address, telephone number and IP address may be sent.

Facebook uses this information to compare the data with the data it has about you (if you are a Facebook member). Before customer data is transmitted to Facebook, it is hashed. This means that a data set of any size is transformed into a character string. This is also used to encrypt data.

In addition to the contact data, "event data" is also transmitted. "Event data" refers to the information that we receive about you on our website. For example, which subpages you visit or which products you buy from us. Facebook does not share the information it receives with third parties (such as advertisers) unless the company has explicit permission or is legally obliged to do so. "Event data" can also be linked to contact details. This allows Facebook to offer better personalized advertising. After the aforementioned matching process, Facebook deletes the contact data again.

In order to deliver optimized ads, Facebook only uses the event data if it has been combined with other data (collected by Facebook in other ways). Facebook also uses this event data for security, protection, development and research purposes. Much of this data is transferred to Facebook via cookies. Cookies are small text files that are used to store data or information in browsers. Depending on the tools used and whether you are a Facebook member, different numbers of cookies are stored in your browser. We go into more detail about individual Facebook cookies in the descriptions of the individual Facebook tools. You can also find general information about the use of Facebook cookies at https://www.facebook.com/policies/cookies.

How long and where is the data stored?

In principle, Facebook stores data until it is no longer needed for its own services and Facebook products. Facebook has servers all over the world where its data is stored. However, customer data is deleted within 48 hours after it has been compared with the company's own user data.

How can I delete my data or prevent data storage?

In accordance with the General Data Protection Regulation, you have the right to information, correction, transferability and deletion of your data.

The data will only be completely deleted if you delete your Facebook account completely. And this is how deleting your Facebook account works:

1) Click on Settings on the right-hand side of Facebook.

2) Then click on "Your Facebook information" in the left-hand column.

3) Now click on "Deactivation and deletion".

4) Now select "Delete account" and then click on "Continue and delete account"

5) Now enter your password, click on "Next" and then on "Delete account"

The data that Facebook receives via our site is stored using cookies (e.g. for social plugins). You can deactivate, delete or manage individual or all cookies in your browser. Depending on which browser you use, this works in different ways. In the "Cookies" section, you will find the relevant links to the instructions for the most popular browsers.

If you generally do not want to have cookies, you can set up your browser so that it always informs you when a cookie is to be set. This allows you to decide for each individual cookie whether you want to allow it or not.

Legal basis

If you have consented to your data being processed and stored by integrated Facebook tools, this consent is the legal basis for data processing (Art. 6 Abs. 1 lit. a DSGVO). In principle, your data will also be processed on the basis of our legitimate interest if you have given your consent. (Art. 6 Abs. 1 lit. f DSGVO) We store and process your data for the purpose of fast and good communication with you or other customers and business partners. Nevertheless, we only use these tools if you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you read our privacy policy about cookies carefully and take a look at Facebook's privacy policy or cookie guidelines.

Facebook also processes your data in the USA, among other places. Facebook or Meta Platforms is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

Facebook also uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Facebook undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Facebook data processing conditions, which refer to the standard contractual clauses, can be found at https://www.facebook.com/legal/terms/dataprocessing.

We hope we have provided you with the most important information about the use and data processing by the Facebook tools. If you would like to find out more about how Facebook uses your data, we recommend that you read the data guidelines on https://www.facebook.com/privacy/policy/.

Facebook Login Privacy Policy

We have integrated the practical Facebook login on our website. This allows you to easily log in with your Facebook account without having to create another user account. If you decide to register via the Facebook login, you will be redirected to the Facebook social media network. There you can log in using your Facebook user data. Through this login procedure, data about you or your user behavior is stored and transmitted to Facebook.

Facebook uses various cookies to store the data. Below we show you the most important cookies that are set in your browser or already exist when you log in to our site via the Facebook login:

Name: fr
Value: 0jieyh4c2GnlufEJ9..Bde09j…1.0.Bde09j
Intended use: This cookie is used to ensure that the social plugin on our website works as well as possible.
Expiration date: after 3 months

Name: datr
Value: 4Jh7XUA2112663980SEmPsSfzCOO4JFFl
Intended use: Facebook sets the "datr" cookie when a web browser accesses facebook.com, and the cookie helps identify login activity and protect users.
Expiration date: after 2 years

Name: _js_datr
Value: deleted
Intended use: Facebook sets this session cookie for tracking purposes, even if you do not have a Facebook account or are logged out.
Expiration date: after the end of the meeting

Remark: The cookies listed are only a small selection of the cookies available to Facebook. Other cookies are, for example, _ fbp, sb or wd. A complete list is not possible, as Facebook has a large number of cookies and uses them variably.

The Facebook login offers you a quick and easy registration process on the one hand, and on the other hand it gives us the opportunity to share data with Facebook. This allows us to better tailor our offers and advertising campaigns to your interests and needs. Data that we receive from Facebook in this way is public data such as

  • Your Facebook name
  • Your Facebook name
  • a stored e-mail address
  • Friends lists
  • Buttons information (e.g. "Like" button)
  • Date of birth
  • Language
  • Place of residence

In return, we provide Facebook with information about your activities on our website. This includes information about the device you use, which subpages you visit or which products you have purchased from us.

By using Facebook Login, you consent to data processing. You may revoke this Agreement at any time. If you would like to find out more information about data processing by Facebook, we recommend that you read Facebook's privacy policy at https://www.facebook.com/privacy/policy/.

If you are logged in to Facebook, you can change your settings for advertisements under https://www.facebook.com/adpreferences/advertisers/?entry_product=ad_settings_screen to change themselves.

Facebook social plug-ins privacy policy

Social plug-ins from Meta Platforms Inc. are integrated on our website. You can recognize these buttons by the classic Facebook logo, such as the "Like" button (the hand with a raised thumb) or by a clear "Facebook plug-in" label. A social plug-in is a small part of Facebook that is integrated into our site. Each plug-in has its own function. The most commonly used functions are the familiar "Like" and "Share" buttons.

The following social plug-ins are offered by Facebook:

  • "Save" button
  • "Like" button, share, send and quote
  • Page plug-in
  • Comments
  • Messenger plug-in
  • Embedded contributions and video player
  • Group plug-in

On https://developers.facebook.com/docs/plugins you will find more detailed information on how to use the individual plug-ins. On the one hand, we use the social plug-ins to offer you a better user experience on our site, and on the other hand, because they allow Facebook to optimize our advertisements.

If you have a Facebook account, or https://www.facebook.com/ Facebook has already set at least one cookie in your browser. In this case, your browser sends information to Facebook via this cookie as soon as you visit our site or interact with social plug-ins (e.g. .dem the "Like" button).

The information received will be deleted or anonymized within 90 days. According to Facebook, this data includes your IP address, which website you visited, the date, time, and other information about your browser.

In order to prevent Facebook from collecting a lot of data during your visit to our website and combining it with Facebook data, you must log out of Facebook during your visit to the website.

If you are not logged in to Facebook or do not have a Facebook account, your browser will send less information to Facebook because you have fewer Facebook cookies. Nevertheless, data such as your IP address or which website you visit may be transmitted to Facebook. We would like to point out that we do not know exactly what the data is. However, according to our current state of knowledge, we try to inform you as much as possible about data processing. You can also find out how Facebook uses the data in the company's data policy at https://www.facebook.com/about/privacy/update read up.

At a minimum, the following cookies are set in your browser when you visit a website with Facebook social plug-ins:

Name: dpr
Value: not specified
Intended use: This cookie is used to make the social plug-ins on our website work.
Expiration date: after the end of the meeting

Name: fr
Value: 0jieyh4112663980c2GnlufEJ9..Bde09j…1.0.Bde09j
Intended use: The cookie is also necessary for the plug-ins to function properly.
Expiration date:: after 3 months

Remark: These cookies have been set after a test, even if you are not a Facebook member.

If you are logged in to Facebook, you can change your settings for advertisements under https://www.facebook.com/adpreferences/advertisers/ change yourself. If you are not a Facebook user, you can go to https://www.youronlinechoices.com/de/praferenzmanagement/?tid=112663980 basically manage your usage-based online advertising. There you have the option to deactivate or activate providers.

If you would like to learn more about Facebook's data protection, we recommend that you consult the company's own data policies https://www.facebook.com/privacy/policy/.

Cookie Consent Management Platform Summary
👥 Affected: Website visitors
🤝 Purpose: Obtaining and managing consent to certain cookies and thus the use of certain tools
📓 Data processed: Data to manage the cookie settings such as IP address, time of consent, type of consent, individual consents. You can find more details about this in the respective tool used.
📅 Storage period: Depends on the tool used, you have to be prepared for periods of several years
⚖️ Legal basis: Art. 6 Para. 1 lit. a GDPR (consent), Art. 6 Para. 1 lit. f GDPR (legitimate interests)

What is a Cookie Consent Management Platform?

We use Consent Management Platform (CMP) software on our website, which makes it easier for us and you to handle the scripts and cookies used correctly and safely. The software automatically creates a cookie popup, scans and controls all scripts and cookies, provides you with the necessary cookie consent under data protection law and helps us and you to keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide for yourself whether and which scripts and cookies you allow or disallow. The following graphic shows the relationship between browser, web server and CMP.

Consent Management Platform Überblick

Why do we use a cookie management tool?

Our goal is to offer you the best possible transparency in the area of data protection. We are also legally obliged to do so. We want to inform you as much as possible about all the tools and all the cookies that can store and process your data. It is also your right to decide for yourself which cookies you accept and which you do not. In order to grant you this right, we must first know exactly which cookies ended up on our website. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we know about all cookies and can provide you with GDPR-compliant information about them. You can then accept or reject cookies via the consent system.

What data is processed?

As part of our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. The declaration of your consent will be saved so that we do not have to ask you every time you visit our website and we can also prove your consent if legally required. This is stored either in an opt-in cookie or on a server. Depending on the provider of the cookie management tool, the storage period for your cookie consent varies. This data (such as pseudonymous user ID, time of consent, detailed information on cookie categories or tools, browser, device information) is usually stored for up to two years.

Duration of data processing

We will inform you below about the duration of data processing if we have further information. In general, we only process personal data for as long as it is absolutely necessary to provide our services and products. Data stored in cookies is stored for different lengths of time. Some cookies are deleted after you leave the website, others can be stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases you should be prepared for a storage period of several years. You will usually receive detailed information about the duration of data processing in the respective data protection declarations of the individual providers.

Right of objection

You also have the right and the opportunity to revoke your consent to the use of cookies at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating or deleting cookies in your browser.

Information about special cookie management tools, if available, can be found in the following sections.

Legal basis

If you agree to cookies, your personal data will be processed and stored via these cookies. If we get through your Consent (Article 6 Para. 1 lit. a GDPR) may use cookies, this consent is also the legal basis for the use of cookies or the processing of your data. In order to be able to manage the consent to cookies and to enable you to give your consent, a cookie consent management platform software is used. The use of this software allows us to operate the website in an efficient, legally compliant manner, which is a berechtigtes Interesse (Artikel 6 Abs. 1 lit. f DSGVO) darstellt.

Web design introduction

Web Design Privacy Policy Summary
👥 Affected parties: Visitors to the website
🤝 Purpose: To improve user experience
📓 Data processed: What data is processed depends heavily on the services used. In most cases, this includes IP address, technical data, language settings, browser version, screen resolution and browser name. More details can be found in the respective web design tools used.
📅 Storage duration: depends on the tools used
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is web design?

We use various tools on our website that serve our web design. Web design is not, as is often assumed, just about making our website look pretty, but also about functionality and performance. But of course the right look of a website is also one of the major goals of professional web design. Web design is a sub-area of media design and deals with the visual as well as the structural and functional design of a website. The aim is to use web design to improve your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience refers to all the impressions and experiences that website visitors experience on a website. A sub-point of the user experience is usability. This is about the user-friendliness of a website. The main emphasis here is on ensuring that content, subpages or products are clearly structured and that you can find what you are looking for easily and quickly. In order to offer you the best possible experience on our website, we also use so-called third-party web design tools. In this data protection declaration, the “web design” category includes all services that improve the design of our website. These can be, for example, fonts, various plugins or other integrated web design functions.

Why do we use web design tools?

How you absorb information on a website depends very much on the structure, functionality and visual perception of the website. Therefore, good and professional web design became more and more important for us. We are constantly working on improving our website and see this as an extended service for you as a website visitor. Furthermore, a beautiful and functioning website also has economic advantages for us. After all, you will only visit us and take advantage of our offers if you feel completely comfortable.

What data are stored by web design tools?

When you visit our website, web design elements may be integrated into our pages, which can also process data. Exactly what data is involved, of course, depends heavily on the tools used. Below you can see exactly which tools we use for our website. We recommend that you read the respective data protection declaration of the tools used for more information about data processing. You will usually find out what data is being processed, whether cookies are being used and how long the data is being kept. Fonts such as Google Fonts also automatically transmit information such as language settings, IP address, browser version, browser screen resolution and browser name to the Google servers.

Duration of data processing

When you visit our website, web design elements may be integrated into our pages, which can also process data. Exactly what data is involved, of course, depends heavily on the tools used. Below you can see exactly which tools we use for our website. We recommend that you read the respective data protection declaration of the tools used for more information about data processing. You will usually find out what data is being processed, whether cookies are being used and how long the data is being kept. Fonts such as Google Fonts also automatically transmit information such as language settings, IP address, browser version, browser screen resolution and browser name to the Google servers.

Right of objection

When you visit our website, web design elements may be integrated into our pages, which can also process data. Exactly what data is involved, of course, depends heavily on the tools used. Below you can see exactly which tools we use for our website. We recommend that you read the respective data protection declaration of the tools used for more information about data processing. You will usually find out what data is being processed, whether cookies are being used and how long the data is being kept. Fonts such as Google Fonts also automatically transmit information such as language settings, IP address, browser version, browser screen resolution and browser name to the Google servers. https://support.google.com/?hl=de.

Legal basis

If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Art. 6 (1) (a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as it may occur when collected by web design tools. We also have a legitimate interest in improving the web design on our website. After all, this is the only way we can provide you with a beautiful and professional web offer. The corresponding legal basis for this is Art. 6 (1) (f) GDPR (legitimate interests). Nevertheless, we only use web design tools if you have given your consent. In any case, we want to emphasize that again here.

Information about special web design tools - if available - can be found in the following sections.

Google Fonts privacy policy

Google Fonts Datenschutzerklärung Zusammenfassung
👥 Affected parties: Visitors to the website
🤝 Purpose: Optimization of our service performance
📓 Data processed: Data such as IP address and CSS and font requests
More details can be found below in this Privacy Policy.
📅 Storage period: Font files are stored by Google for one year
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What are Google Fonts?

We use Google Fonts on our website. These are the “Google Fonts” from Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.

You do not need to register or provide a password to use Google fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts/fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google Account, you do not need to worry that your Google Account information will be transmitted to Google while using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will take a closer look at what data storage looks like.

Google Fonts (formerly Google Web Fonts) is a directory with over 800 fonts that Google make it available to your users free of charge.

Many of these fonts are released under the SIL Open Font License, while others are released under the Apache License. Both are free software licenses.

Why do we use Google Fonts on our website?

With Google Fonts we can use fonts on our own website and do not have to upload them to our own server. Google Fonts is an important component in keeping the quality of our website high. All Google fonts are automatically optimized for the web and this saves data volume and is a big advantage, especially for use on mobile devices. When you visit our site, the low file size ensures a fast loading time. Furthermore, Google Fonts are secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors. Such errors can visually distort some texts or entire websites. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can display our entire online service as beautifully and consistently as possible.

What data does Google store?

When you visit our website, the fonts are downloaded via a Google server. Through this external call, data is transmitted to the Google servers. This is how Google also recognizes that you or your IP address visits our website. The Google Fonts API is designed to reduce the use, storage, and collection of end-user data to what is necessary for proper font delivery. By the way, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.

Google Fonts stores CSS and font requests securely on Google and is therefore protected. By collecting usage figures, Google can determine how well the individual fonts are received. Google publishes the results on internal analysis sites, such as Google Analytics. Google also uses data from its own web crawler to determine which websites use Google fonts. This data is published in the Google Fonts BigQuery database. Entrepreneurs and developers use the Google web service BigQuery to examine and move large amounts of data.

However, it should also be remembered that with every Google Font request, information such as language settings, IP address, browser version, browser screen resolution and browser name are automatically transmitted to the Google servers. Whether this data is also stored cannot be clearly determined or is not clearly communicated by Google.

How long and where is the data stored?

Google stores requests for CSS assets for one day on its servers, which are mainly located outside the EU. This allows us to use the fonts using a Google stylesheet. A style sheet is a format template that you can use to quickly and easily change the design or font of a website, for example.

The font files are stored by Google for one year. Google's goal is to fundamentally improve the loading time of websites. When millions of websites reference the same fonts, they are cached after the first visit and immediately appear on all other websites visited later. Sometimes Google updates font files to reduce file size, increase language coverage, and improve design.

How can I delete my data or prevent data storage?

The data that Google stores for a day or a year cannot simply be deleted. The data is automatically transmitted to Google when the page is accessed. In order to delete this data early, you must contact Google Support https://support.google.com/?hl=de&tid=112663980 contact. In this case, you can only prevent data storage if you do not visit our site.

Unlike other web fonts, Google allows us unlimited access to all fonts. So we have unlimited access to a sea of fonts and get the best for our website. You can find out more about Google Fonts and other questions at https://developers.google.com/fonts/faq?tid=112663980. Although Google addresses data protection-related matters there, it does not contain any really detailed information about data storage. It is relatively difficult to get really precise information about stored data from Google.

Legal basis

If you have consented to the use of Google Fonts, the legal basis for the corresponding data processing is this consent. This consent states loudly Art. 6 Paragraph 1 Letter a GDPR (consent) represents the legal basis for the processing of personal data, as may occur when it is collected by Google Fonts.

We also have a legitimate interest in using Google Font to optimize our online service. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). However, we only use Google Font if you have given your consent.

Google also processes your data in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

Google also uses so-called standard contractual clauses (= Art. 46 Paragraphs 2 and 3 GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the resolution and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

You can also see which data is generally collected by Google and what this data is used for https://www.google.com/intl/de/policies/privacy/ read up.

Google Fonts Local Privacy Policy

On our website we use Google Fonts from Google Inc. The company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for Europe. We have integrated the Google fonts locally, i.e. on our web server - not on Google's servers. This means there is no connection to Google servers and therefore no data transfer or storage.

What are Google Fonts?

Google Fonts used to be called Google Web Fonts. This is an interactive directory with over 800 fonts Google provided free of charge. With Google Fonts you could use fonts without uploading them to your own server. However, in order to prevent any information transfer to Google servers, we have downloaded the fonts to our server. In this way, we act in accordance with data protection regulations and do not send any data to Google Fonts.

Online map services introduction

Online Map Services Privacy Policy Summary
👥 Affected parties: Visitors to the website
🤝 Purpose: To improve user experience
📓 Processed data: Which data is processed depends largely on the services used. This usually involves IP address, location data, search items and/or technical data. You can find more details about the tools used in each case.
📅 Storage duration: depends on the tools used
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What are online mapping services?

We also use online map services as an extended service for our website. Google Maps is probably the service you are most familiar with, but there are also other providers that specialize in creating digital maps. Such services make it possible to display locations, route maps or other geographical information directly via our website. Thanks to an integrated map service, you no longer have to leave our website, for example to view the route to a location. So that the online map works on our website, map sections are integrated using HTML code. The services can then display road maps, the earth's surface or aerial or satellite images. If you use the built-in map offer, data will also be transferred to the tool used and stored there. This data may also include personal data.

Why do we use online mapping services on our website?

Generally speaking, our aim is to offer you a pleasant time on our website. And of course your time will only be pleasant if you can easily find your way around our website and find all the information you need quickly and easily. We therefore thought that an online card system could be a significant optimization of our service on the website. Without leaving our website, you can easily view route descriptions, locations or even sights using the map system. Of course, it's also super practical that you can see at a glance where our company headquarters are, so you can find us quickly and safely. As you can see, there are simply many advantages and we clearly consider online mapping services on our website as part of our customer service.

What data is stored by online mapping services?

If you open a page on our website that has an online map function built in, personal data may be transmitted to the relevant service and stored there. This is usually your IP address, which can also be used to determine your approximate location. In addition to the IP address, data such as entered search terms and longitude and latitude coordinates are also stored. For example, if you enter an address for route planning, this data will also be saved. The data is not stored by us, but on the servers of the integrated tools. You can think of it something like this: you are on our website, but when you interact with a mapping service, that interaction actually happens on their website. In order for the service to function properly, at least one cookie is usually set in your browser. For example, Google Maps also uses cookies to record user behavior and thus optimize its own service and be able to display personalized advertising. You can find out more about cookies in our “Cookies” section.

How long and where is the data stored?

Every online mapping service processes different user data. If we have further information, we will inform you about the duration of data processing below in the relevant sections for the individual tools. In principle, personal data is only retained for as long as is necessary to provide the service. Google Maps, for example, stores certain data for a set period of time, but you have to delete other data yourself. With Mapbox, for example, the IP address is stored for 30 days and then deleted. You see, every tool stores data for a different amount of time. We therefore recommend that you take a close look at the data protection declarations of the tools used.

The providers also use cookies to store data about your user behavior with the map service. You can find more general information about cookies in our “Cookies” section, but you can also find out which cookies can be used in the data protection texts of the individual providers. In most cases, however, this is only an exemplary list and is not complete.

Right of objection

You always have the opportunity and right to access your personal data and to object to its use and processing. You can also revoke the consent you have given us at any time. As a rule, the easiest way to do this is to use the cookie consent tool. But there are also other opt-out tools you can use. You can also manage, delete or deactivate possible cookies that are set by the providers used with just a few mouse clicks. However, it may then happen that some functions of the service no longer work as usual. How you manage cookies in your browser also depends on the browser you use. In the “Cookies” section you will also find links to the instructions for the main browsers.

Legal basis

If you have consented to the use of an online mapping service, the legal basis for the corresponding data processing is this consent. According to Article 6 Paragraph 1 Letter a of the GDPR (consent), this consent represents the legal basis for the processing of personal data, as may occur when it is collected by an online mapping service.

We also have a legitimate interest in using an online mapping service to optimize our service on our website. The corresponding legal basis for this is Article 6 Paragraph 1 Letter f GDPR (legitimate interests). However, we only use an online mapping service if you have given your consent. We definitely want to record this again at this point.

Information about special online map services - if available - can be found in the following sections.

Google Maps privacy policy

Google Maps Privacy Policy Summary
👥 Affected parties: Visitors to the website
🤝 Purpose: Optimization of our service performance
📓 Data processed: Data such as search terms entered, your IP address and also the latitude or longitude coordinates.
More details can be found below in this Privacy Policy.
📅 Storage period: depending on the stored data
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)

What is Google Maps?

We use Google Maps from Google Inc. on our website. For Europe, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Maps we can show you locations better and thus adapt our service to your needs. By using Google Maps, data is transmitted to Google and stored on Google servers. Here we want to go into more detail about what Google Maps is, why we use this Google service, what data is stored and how you can prevent this.

Google Maps is an Internet mapping service from Google. Google Maps lets you find exact locations of cities, attractions, accommodations or businesses online using a PC, tablet or app. If companies are represented on Google My Business, other information about the company is displayed in addition to the location. In order to show how to get there, map sections of a location can be integrated into a website using HTML code. Google Maps shows the earth's surface as a road map or as an aerial or satellite image. Thanks to the Street View images and the high-quality satellite images, very precise representations are possible.

Why do we use Google Maps on our website?

All our efforts on this site aim to offer you a useful and meaningful time on our website. By integrating Google Maps, we can provide you with the most important information about various locations. You can see at a glance where our headquarters are. The directions always show you the best or fastest way to get to us. You can get directions for routes by car, public transport, walking or cycling. For us, providing Google Maps is part of our customer service.

What data does Google Maps store?

In order for Google Maps to fully offer its service, the company must record and store data from you. This includes, among other things, the search terms entered, your IP address and also the latitude and longitude coordinates. If you use the route planner function, the start address entered is also saved. However, this data storage happens on the Google Maps websites. We can only inform you about this, but have no influence. Since we have integrated Google Maps into our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google primarily uses this data to optimize its services and to provide you with individual, personalized advertising.

The following cookie is set in your browser due to the integration of Google Maps:

Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ112663980-5
Intended use: NID is used by Google to tailor advertisements to your Google searches. With the help of the cookie, Google “remembers” your most frequently entered search queries or your previous interaction with ads. This means you always get tailor-made advertisements. The cookie contains a unique ID that Google uses to collect your personal preferences for advertising purposes.
Expiration date: after 6 months

Remark: We cannot guarantee the completeness of the stored data. Changes can never be ruled out, especially when using cookies. In order to identify the cookie NID, a separate test page was created where only Google Maps was integrated.

How long and where is the data stored?

Google servers are located in data centers around the world. However, most of the servers are located in America. For this reason, your data is increasingly stored in the USA. Here you can read exactly where the Google data centers are located: https://www.google.com/about/datacenters/locations/?hl=de

Google distributes the data on various storage media. This means that the data can be accessed more quickly and is better protected against any attempts at manipulation. Each data center also has specific emergency programs. For example, if there are problems with Google's hardware or a natural disaster shuts down the servers, the data will almost certainly remain protected.

Google stores some data for a set period of time. For other data, Google only offers the option of deleting it manually. The company also anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months.

How can I delete my data or prevent data storage?

With the automatic deletion of location and activity data introduced in 2019, location and web/app activity information is stored for either 3 or 18 months, depending on your choice, and then deleted. You can also manually delete this data from your history at any time using your Google account. If you want to completely prevent your location tracking, you must pause the “Web and app activity” section in your Google Account. Click “Data and Personalization” and then click the “Activity Settings” option. Here you can turn the activities on or off.

You can also deactivate, delete or manage individual cookies in your browser. Depending on which browser you use, this always works a little differently. Under the “Cookies” section you will find the corresponding links to the relevant instructions for the most popular browsers.

If you generally do not want to have cookies, you can set up your browser so that it always informs you when a cookie is to be set. This allows you to decide for each individual cookie whether you want to allow it or not.

Legal basis

If you have consented to Google Maps being used, the legal basis for the corresponding data processing is this consent. This consent states loudly Art. 6 Paragraph 1 Letter a GDPR (consent) represents the legal basis for the processing of personal data, as may occur when it is collected by Google Maps.

We also have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). However, we only use Google Maps if you have given your consent.

Google also processes your data in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information about this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

Google also uses so-called standard contractual clauses (= Art. 46 Paragraphs 2 and 3 GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the resolution and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

If you would like to find out more about Google's data processing, we recommend that you read the company's own privacy policy at https://policies.google.com/privacy?hl=de.

Explanation of terms used

We always strive to make our data protection declaration as clear and understandable as possible. However, this is not always easy, especially when it comes to technical and legal issues. It often makes sense to use legal terms (such as personal data) or certain technical terms (such as cookies, IP address). But we don't want to use them without explanation. Below you will find an alphabetical list of important terms used that we may not have addressed sufficiently in the previous data protection declaration. If these terms were taken from the GDPR and they are definitions, we will also cite the GDPR texts here and add our own explanations if necessary.

Processor

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

Processor a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller;

Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to those responsible, there can also be so-called processors. This includes every company or person who processes personal data on our behalf. In addition to service providers such as tax consultants, processors can also include hosting or cloud providers, payment or newsletter providers or large companies such as Google or Microsoft.

Consent

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

Consent to the data subject, any voluntary, specific, informed and unambiguous indication of his or her wishes, in the form of a statement or other clear affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her;

Explanation: As a rule, such consent is given on websites via a cookie consent tool. You probably know that. Whenever you visit a website for the first time, you will usually be asked via a banner whether you agree to data processing. You can usually also make individual settings and decide for yourself which data processing you allow and which not. If you do not consent, no personal data about you may be processed. In principle, consent can of course also be given in writing, i.e. not via a tool.

Personal Data

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

personal data any information relating to an identified or identifiable natural person (hereinafter “data subject”); A natural person is considered to be identifiable if he or she can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person;

Explanation: Personal data is all data that can identify you as a person. This is usually data such as:

  • Name
  • Address
  • E-mail address
  • Postal address
  • Telephone number
  • Date of birth
  • Identification numbers such as social security number, tax identification number, ID card number or matriculation number
  • Bank details such as account number, credit information, account balances and much more.

According to the European Court of Justice (ECJ), yours also counts IP address for the personal data. Using your IP address, IT experts can at least determine the approximate location of your device and subsequently you as the connection owner. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that is particularly worthy of protection. These include:

  • racial and ethnic origins
  • political opinions
  • religious or ideological beliefs
  • union membership
  • genetic data such as data collected from blood or saliva samples
  • biometric data (this is information about psychological, physical or behavioral characteristics that can identify a person).
    Health data
  • Data on sexual orientation or sex life

Profiling

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

„Profiling“ any type of automated processing of personal data, which consists in using such personal data to evaluate certain personal aspects relating to a natural person, in particular aspects relating to work performance, economic situation, health, personal preferences, interests , analyze or predict the reliability, behavior, location or movements of that natural person;

Explanation: Profiling involves collecting various information about a person in order to learn more about that person. In the web sector, profiling is often used for advertising purposes or for credit checks. Web or advertising analysis programs, for example, collect data about your behavior and interests on a website. This results in a special user profile that can be used to target advertising to a specific target group.

Person in charge

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

Person in charge the natural or legal person, public authority, agency or other body which, alone or jointly with others, decides on the purposes and means of processing personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

Explanation: In our case, we are responsible for the processing of your personal data and therefore the “controller”. If we pass on collected data to other service providers for processing, they are “processors”. To do this, an “order processing agreement (AVV)” must be signed.

Processing

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:

Processing any operation or series of operations carried out with or without the aid of automated procedures in connection with personal data, such as the collection, recording, organization, structuring, storage, adaptation or modification, reading, querying, use, disclosure by transmission, distribution or other form of provision, alignment or association, restriction, deletion or destruction;

Remark: When we talk about processing in our privacy policy, we mean any type of data processing. As mentioned above in the original GDPR declaration, this includes not only collecting but also storing and processing data.

All texts are copyrighted.

Source: Created with the Privacy Generator by AdSimple

To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and related consents, we use the Consent Tool Real Cookie Banner one. For details on how Real Cookie Banner works, see follow this link.

The legal basis for the processing of personal data in this context is Article 6 (1) (c) GDPR and Article 6 (1) (f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.

The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.