Data protection

Pri­va­cy poli­cy

1. data protection at a glance

General information

The fol­lo­wing infor­ma­ti­on pro­vi­des a simp­le over­view of what hap­pens to your per­so­nal data when you visit this web­site. Per­so­nal data is all data with which you can be per­so­nal­ly iden­ti­fied. For detail­ed infor­ma­ti­on about data pro­tec­tion, plea­se refer to our pri­va­cy poli­cy lis­ted below this text.

Data collection on this website

Who is responsible for data collection on this website?

The data pro­ces­sing on this web­site is car­ri­ed out by the web­site ope­ra­tor. Their cont­act details can be found in the „Infor­ma­ti­on about the respon­si­ble par­ty“ sec­tion of this pri­va­cy poli­cy.

How do we collect your data?

Your data is coll­ec­ted in part by you pro­vi­ding it to us. This can, for exam­p­le, include data that you enter into a cont­act form.

Other data is coll­ec­ted auto­ma­ti­cal­ly or with your con­sent when visi­ting the web­site by our IT sys­tems. The­se include pri­ma­ri­ly tech­ni­cal data (such as Inter­net brow­ser, ope­ra­ting sys­tem or time of page visit). The coll­ec­tion of this data occurs auto­ma­ti­cal­ly as soon as you enter this web­site.

What do we use your data for?

Part of the data is coll­ec­ted to ensu­re the flaw­less pro­vi­si­on of the web­site. Other data may be used to ana­ly­ze your user beha­vi­or. If con­tracts can be con­cluded or orde­red through the web­site, the trans­mit­ted data will also be pro­ces­sed for con­tract offers, orders, or other requests for ser­vices.

What rights do you have regarding your data?

You have the right at any time to obtain infor­ma­ti­on free of char­ge about the ori­gin, reci­pi­ents and pur­po­se of your stored per­so­nal data. You also have the right to request the rec­ti­fi­ca­ti­on or dele­ti­on of this data. If you have given your con­sent to data pro­ces­sing, you can revo­ke this con­sent at any time for the future. In addi­ti­on, you have the right to request the rest­ric­tion of the pro­ces­sing of your per­so­nal data in cer­tain cir­cum­s­tances. Fur­ther­mo­re, you have the right to lodge a com­plaint with the com­pe­tent super­vi­so­ry aut­ho­ri­ty.

For this and any other ques­ti­ons regar­ding data pro­tec­tion, you can cont­act us at any time.

Analysis tools and third-party tools

When you visit this web­site, your sur­fing beha­vi­or may be sta­tis­ti­cal­ly eva­lua­ted. This is main­ly done with so-cal­led ana­ly­sis pro­grams.

Detail­ed infor­ma­ti­on about the­se ana­ly­sis pro­grams can be found in the fol­lo­wing pri­va­cy poli­cy.

2. hosting and content delivery networks (CDN)

We host the con­tent of our web­site with the fol­lo­wing pro­vi­der:

External hosting

This web­site is hos­ted extern­al­ly. The per­so­nal data coll­ec­ted on this web­site is stored on the ser­vers of the hoster/s. This may include, but is not limi­t­ed to, IP addres­ses, cont­act requests, meta and com­mu­ni­ca­ti­on data, con­tract data, cont­act data, names, web­site visits, and other data gene­ra­ted through a web­site.

The exter­nal hos­ting is car­ri­ed out for the pur­po­se of ful­fil­ling our con­trac­tu­al obli­ga­ti­ons towards our poten­ti­al and exis­ting cus­to­mers (Art. 6(1)(b) GDPR) and in the inte­rest of pro­vi­ding our online offe­ring in a secu­re, fast and effi­ci­ent man­ner through a pro­fes­sio­nal pro­vi­der (Art. 6(1)(f) GDPR). If appro­pria­te con­sent has been reques­ted, pro­ces­sing takes place sole­ly on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, inso­far as the con­sent includes the sto­rage of coo­kies or access to infor­ma­ti­on on the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. Con­sent may be revo­ked at any time.

Our host will only pro­cess your data to the ext­ent neces­sa­ry to ful­fill its per­for­mance obli­ga­ti­ons and to com­ply with our ins­truc­tions regar­ding this data.

We use the fol­lo­wing host(s):

nex­serv GmbH
Kur­fürs­ten­stra­ße 10
50678 Colo­gne
Ger­ma­ny

Bunny.net CDN

We use the con­tent deli­very net­work Bunny.net. The pro­vi­der is Bun­ny­Way d.o.o., Duna­js­ka ces­ta 165, 1000 Ljublja­na, Slove­nia (her­ein­af­ter „Bunny.net CDN“).

At Bunny.net CDN, it is a glo­bal­ly dis­tri­bu­ted con­tent deli­very net­work. In this way, the infor­ma­ti­on trans­fer bet­ween your brow­ser and our web­site is rou­ted through the con­tent deli­very net­work. This allows us to increase the glo­bal acces­si­bi­li­ty and per­for­mance of our web­site. The CDN coll­ects the IP address, which is howe­ver anony­mi­zed. Addi­tio­nal­ly, the CDN coll­ects per­so­nal data when it is ente­red by the user them­sel­ves (e.g., by sub­mit­ting via a cont­act form on the web­site).

The use of Bunny.net CDN is based on our legi­ti­ma­te inte­rest in pro­vi­ding our web offe­rings in the most error-free and secu­re man­ner (Art. 6(1)(f) GDPR).

You can find more infor­ma­ti­on about Bunny.net CDN here: https://bunny.net/privacy/.

3. General notes and mandatory information

Data protection

The ope­ra­tors of the­se sites take the pro­tec­tion of your per­so­nal data very serious­ly. We tre­at your per­so­nal data con­fi­den­ti­al­ly and in accordance with the legal data pro­tec­tion regu­la­ti­ons as well as this pri­va­cy poli­cy.

When you use this web­site, various per­so­nal data is coll­ec­ted. Per­so­nal data is data with which you can be per­so­nal­ly iden­ti­fied. This pri­va­cy poli­cy explains which data we coll­ect and for what pur­po­ses we use it. It also explains how and for what pur­po­se this is done.

We point out that data trans­mis­si­on over the Inter­net (e.g. when com­mu­ni­ca­ting by e‑mail) can invol­ve secu­ri­ty vul­nerabi­li­ties. A com­ple­te pro­tec­tion of data against access by third par­ties is not pos­si­ble.

Note on the responsible body

The respon­si­ble body for data pro­ces­sing on this web­site is:

KOMOS GmbH
Bahn­hofstras­se 2
07616 Bür­gel

Pho­ne: +49 (0)36692 490 0
Email: sekretariat@komos.de

The respon­si­ble enti­ty is the natu­ral or legal per­son who alo­ne or joint­ly with others deci­des on the pur­po­ses and means of pro­ces­sing per­so­nal data (e.g., names, e‑mail addres­ses, etc.).

Storage duration

Unless a spe­ci­fic sto­rage peri­od is spe­ci­fied within this pri­va­cy poli­cy, your per­so­nal data will remain with us until the pur­po­se for data pro­ces­sing no lon­ger appli­es. If you make a legi­ti­ma­te request for dele­ti­on or revo­ke your con­sent to data pro­ces­sing, your data will be dele­ted unless we have other legal­ly per­mis­si­ble reasons for sto­ring your per­so­nal data (e.g., tax or com­mer­cial reten­ti­on peri­ods); in the lat­ter case, the dele­ti­on will take place upon the lap­se of the­se reasons.

General information on the legal basis for data processing on this website

If you have con­sen­ted to the data pro­ces­sing, we pro­cess your per­so­nal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, pro­vi­ded that spe­cial cate­go­ries of data are pro­ces­sed under Art. 9(1) GDPR. In the event of expli­cit con­sent to the trans­fer of per­so­nal data to third count­ries, data pro­ces­sing also takes place on the basis of Art. 49(1)(a) GDPR. If you have con­sen­ted to the sto­rage of coo­kies or to access infor­ma­ti­on on your end device (e.g., via device fin­ger­prin­ting), data pro­ces­sing also takes place on the basis of § 25(1) TDDDG. Con­sent can be with­drawn at any time. If your data is requi­red for con­tract per­for­mance or for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res, we pro­cess your data on the basis of Art. 6(1)(b) GDPR. Fur­ther­mo­re, we pro­cess your data inso­far as it is neces­sa­ry to ful­fill a legal obli­ga­ti­on pur­su­ant to Art. 6(1)© GDPR. The data pro­ces­sing may also take place on the basis of our legi­ti­ma­te inte­rest pur­su­ant to Art. 6(1)(f) GDPR. The rele­vant legal bases in each indi­vi­du­al case are explai­ned in the fol­lo­wing para­graphs of this pri­va­cy poli­cy.

Data Protection Officer

We have appoin­ted a data pro­tec­tion offi­cer.

Dr. Kum­mer, Jochen age­nos GmbH

Pho­ne: [Data Pro­tec­tion Officer’s pho­ne num­ber]
Email: datenschutz@komos.de

Recipients of personal data

As part of our busi­ness acti­vi­ties, we work with various exter­nal par­ties. In some cases, the trans­mis­si­on of per­so­nal data to the­se exter­nal par­ties is also requi­red. We only pass on per­so­nal data to exter­nal par­ties if this is neces­sa­ry as part of ful­fil­ling a con­trac­tu­al obli­ga­ti­on, if we are legal­ly obli­ged to do so (e.g., the dis­clo­sure of data to tax aut­ho­ri­ties), if we have a legi­ti­ma­te inte­rest in the dis­clo­sure pur­su­ant to Art. 6(1)(f) GDPR, or if ano­ther legal basis per­mits the data trans­fer. When using con­tract pro­ces­sors, we only pass on per­so­nal data of our cus­to­mers on the basis of a valid con­tract for con­tract pro­ces­sing. In the case of joint pro­ces­sing, a con­tract for joint pro­ces­sing is con­cluded.

Revocation of your consent to data processing

Many data pro­ces­sing ope­ra­ti­ons are only pos­si­ble with your express con­sent. You can revo­ke an alre­a­dy given con­sent at any time. The lega­li­ty of data pro­ces­sing car­ri­ed out up to the revo­ca­ti­on remains unaf­fec­ted by the revo­ca­ti­on.

Right of objection to data collection in special cases as well as to direct advertising (Art. 21 GDPR)

IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ARTICLE 6(1)(e) OR (f) OF THE GDPR, YOU HAVE AT ANY TIME THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE EACH AND EVERY LEGAL BASIS ON WHICH PROCESSING IS BASED SHALL BE NOTIFIED IN THIS DATA PROTECTION NOTICE. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, PROVIDED THAT WE CAN PROVE OBJECTIONS WHICH WE BELIEVE TO BE WORTHY OF PROTECTION, WHICH OVERWEIGH THE INTERESTS, RIGHTS AND FREEDOMS OF YOU OR WHICH THE PROCESSING IS NECESSARY FOR THE ASSERTION, THE EXERCISE OR THE DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ARTICLE 21(1) OF THE GDPR).

IF YOUR PERSONAL DATA ARE BEING PROCESSED TO CONDUCT DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING, IN WHICH CASE IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED IN CONNECTION WITH SUCH DIRECT MARKETING (OBJECTION IN ACCORDANCE WITH ARTICLE 21(2) OF THE GDPR).

Right to complain to the competent supervisory authority

In the event of vio­la­ti­ons of the GDPR, data sub­jects have the right to file a com­plaint with a super­vi­so­ry aut­ho­ri­ty, in par­ti­cu­lar in the Mem­ber Sta­te of their habi­tu­al resi­dence, place of work, or the place of the alle­ged vio­la­ti­on. This right to file a com­plaint is wit­hout pre­ju­di­ce to any other admi­nis­tra­ti­ve or judi­cial reme­dies.

Right to data portability

You have the right to have data that we pro­cess auto­ma­ti­cal­ly based on your con­sent or in ful­fill­ment of a con­tract han­ded over to you or to a third par­ty in a com­mon­ly used, machi­ne-rea­da­ble for­mat. If you request the direct trans­fer of the data to ano­ther con­trol­ler, this will only be done inso­far as it is tech­ni­cal­ly fea­si­ble.

Information, correction and deletion

Within the frame­work of appli­ca­ble legal regu­la­ti­ons, you have the right at any time to obtain infor­ma­ti­on free of char­ge about your stored per­so­nal data, their ori­gin and reci­pi­ents, and the pur­po­se of data pro­ces­sing, and if appli­ca­ble, the right to cor­rect or dele­te this data. You can cont­act us at any time for this pur­po­se and for any fur­ther ques­ti­ons regar­ding per­so­nal data.

Right to restrict the processing

You have the right to request the rest­ric­tion of the pro­ces­sing of your per­so­nal data. To exer­cise this right, you can cont­act us at any time. The right to rest­rict the pro­ces­sing exists in the fol­lo­wing cases:

  • If you dis­pu­te the accu­ra­cy of the per­so­nal data we store about you, we usual­ly need time to veri­fy this. During this peri­od, you have the right to request that the pro­ces­sing of your per­so­nal data be rest­ric­ted.
  • If the pro­ces­sing of your per­so­nal data occur­red unlawful­ly, you may request the rest­ric­tion of data pro­ces­sing ins­tead of the dele­ti­on.
  • If we no lon­ger need your per­so­nal data, but you need it to exer­cise, defend or estab­lish legal claims, you have the right to request that the pro­ces­sing of your per­so­nal data be rest­ric­ted ins­tead of being dele­ted.
  • If you have filed a com­plaint under Artic­le 21(1) GDPR, a balan­ce must be struck bet­ween your inte­rests and ours. As long as it is not yet clear who­se inte­rests pre­vail, you have the right to request the rest­ric­tion of the pro­ces­sing of your per­so­nal data.

If you have rest­ric­ted the pro­ces­sing of your per­so­nal data, the­se data may only be pro­ces­sed – apart from their sto­rage – with your con­sent or to estab­lish, exer­cise or defend legal claims or to pro­tect the rights of ano­ther natu­ral or legal per­son or for reasons of an important public inte­rest of the Euro­pean Uni­on or a Mem­ber Sta­te.

SSL or TLS encryption

For secu­ri­ty reasons and to pro­tect the trans­mis­si­on of con­fi­den­ti­al con­tent, such as orders or inqui­ries that you send to us as the web­site ope­ra­tor, this page uses SSL or TLS encryp­ti­on. You can reco­gni­ze an encrypt­ed con­nec­tion by the fact that the brow­ser address bar chan­ges from „http://“ http://„ to “https://”https://“ and by the lock sym­bol in your brow­ser bar.

If SSL or TLS encryp­ti­on is enab­led, the data you trans­mit to us can­not be read by third par­ties.

Objection to advertising e‑mails

The use of cont­act details published under the imprint obli­ga­ti­on for the pur­po­se of sen­ding unso­li­ci­ted adver­ti­sing and infor­ma­tio­nal mate­ri­al is her­eby denied. The ope­ra­tors of the sites express­ly reser­ve the right to take legal action in the event of unso­li­ci­ted sen­ding of adver­ti­sing infor­ma­ti­on, for exam­p­le through spam emails.

4. data collection on this website

Cookies

Our web­sites use so-cal­led „coo­kies“. Coo­kies are small data packa­ges that do not cau­se any dama­ge to your device. They are eit­her tem­po­r­a­ri­ly stored on your device for the dura­ti­on of a ses­si­on (ses­si­on coo­kies) or per­ma­nent­ly (per­ma­nent coo­kies). Ses­si­on coo­kies are dele­ted auto­ma­ti­cal­ly after the end of your visit. Per­ma­nent coo­kies remain stored on your device until you dele­te them yours­elf or an auto­ma­tic dele­ti­on is per­for­med by your web brow­ser.

Coo­kies can be gene­ra­ted by us (first-par­ty coo­kies) or by third par­ties (so-cal­led third-par­ty coo­kies). Third-par­ty coo­kies enable the inte­gra­ti­on of cer­tain ser­vices from third par­ties within web­sites (e.g., coo­kies for pro­ces­sing pay­ment ser­vices).

Coo­kies have various func­tions. Num­e­rous coo­kies are tech­ni­cal­ly neces­sa­ry becau­se cer­tain web­site func­tions would not work wit­hout them (e.g., the shop­ping cart func­tion or the dis­play of vide­os). Other coo­kies can be used to ana­ly­ze user beha­vi­or or for adver­ti­sing pur­po­ses.

Coo­kies that are neces­sa­ry for the imple­men­ta­ti­on of the elec­tro­nic com­mu­ni­ca­ti­on pro­cess, for the pro­vi­si­on of cer­tain func­tions that you wish to use (e.g., for the shop­ping cart func­tion), or for opti­mi­zing the web­site (e.g., coo­kies for mea­su­ring web traf­fic) are stored based on Art. 6(1)(f) GDPR, unless ano­ther legal basis is spe­ci­fied. The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in sto­ring neces­sa­ry coo­kies for the tech­ni­cal­ly error-free and opti­mi­zed pro­vi­si­on of its ser­vices. If con­sent has been reques­ted for the sto­rage of coo­kies and simi­lar reco­gni­ti­on tech­no­lo­gies, the pro­ces­sing will take place sole­ly on the basis of this con­sent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); the con­sent can be revo­ked at any time.

You can set your brow­ser to be infor­med about the set­ting of coo­kies and to allow coo­kies only in indi­vi­du­al cases, to exclude the accep­tance of coo­kies for cer­tain cases or gene­ral­ly, and to auto­ma­ti­cal­ly dele­te the coo­kies when you clo­se the brow­ser. When coo­kies are deac­ti­va­ted, the func­tion­a­li­ty of this web­site may be limi­t­ed.

You can find infor­ma­ti­on about the coo­kies and ser­vices used on this web­site in this pri­va­cy poli­cy.

CCM19

Our web­site uses CCM19 to obtain your con­sent to store cer­tain coo­kies on your device or to use cer­tain tech­no­lo­gies and to docu­ment the­se in a data pro­tec­tion-com­pli­ant man­ner. The pro­vi­der of this tech­no­lo­gy is Papoo Soft­ware & Media GmbH, August­str. 4, 53229 Bonn (her­ein­af­ter „CCM19“).

When you visit our web­site, a con­nec­tion is estab­lished with the ser­vers of CCM19 to obtain your con­sent and other decla­ra­ti­ons regar­ding the use of coo­kies. Sub­se­quent­ly, CCM19 stores a coo­kie in your brow­ser to be able to assign the cons­ents gran­ted to you or their revo­ca­ti­on. The data coll­ec­ted in this way is stored until you request us to dele­te it, you dele­te the CCM19 coo­kie yours­elf, or the pur­po­se for data sto­rage no lon­ger appli­es. Com­pul­so­ry sta­tu­to­ry reten­ti­on obli­ga­ti­ons remain unaf­fec­ted.

The use of CCM19 is inten­ded to obtain the cons­ents requi­red by law for the use of coo­kies. The legal basis for this is Artic­le 6(1)© of the GDPR.

Order processing

We have con­cluded a con­tract for the pro­ces­sing of orders (AVV) for the use of the afo­re­men­tio­ned ser­vice. This is a con­tract requi­red by data pro­tec­tion law that ensu­res that this ser­vice pro­ces­ses the per­so­nal data of our web­site visi­tors only in accordance with our ins­truc­tions and in com­pli­ance with the GDPR.

Contact form

If you send us inqui­ries via the cont­act form, your details from the inquiry form, inclu­ding the cont­act infor­ma­ti­on you pro­vi­de the­re, will be stored by us for the pur­po­se of pro­ces­sing the inquiry and in the event of fol­low-up ques­ti­ons. We will not share this data wit­hout your con­sent.

The pro­ces­sing of this data is car­ri­ed out on the basis of Art. 6(1)(b) GDPR, pro­vi­ded that your request is rela­ted to the per­for­mance of a con­tract or is neces­sa­ry for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res. In all other cases, the pro­ces­sing is based on our legi­ti­ma­te inte­rest in effec­tively pro­ces­sing the requests sub­mit­ted to us (Art. 6(1)(f) GDPR) or on your con­sent (Art. 6(1)(a) GDPR), pro­vi­ded that it has been reques­ted; the con­sent is revo­ca­ble at any time.

The data you enter in the cont­act form will remain with us until you request us to dele­te it, revo­ke your con­sent to its sto­rage, or the pur­po­se for data sto­rage no lon­ger appli­es (e.g., after your request has been com­ple­ted). Com­pul­so­ry legal pro­vi­si­ons – in par­ti­cu­lar reten­ti­on peri­ods – remain unaf­fec­ted.

Request by e‑mail, phone or fax

If you cont­act us by e‑mail, tele­pho­ne or fax, your request, inclu­ding all per­so­nal data deri­ved from it (name, request), will be stored and pro­ces­sed by us for the pur­po­se of pro­ces­sing your request. We will not dis­c­lo­se this data wit­hout your con­sent.

The pro­ces­sing of this data is car­ri­ed out on the basis of Art. 6(1)(b) GDPR, pro­vi­ded that your request is rela­ted to the per­for­mance of a con­tract or is neces­sa­ry for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res. In all other cases, the pro­ces­sing is based on our legi­ti­ma­te inte­rest in effec­tively pro­ces­sing the requests sub­mit­ted to us (Art. 6(1)(f) GDPR) or on your con­sent (Art. 6(1)(a) GDPR), pro­vi­ded that it has been reques­ted; the con­sent is revo­ca­ble at any time.

The data you send to us via cont­act requests remains with us until you request us to dele­te it, revo­ke your con­sent to its sto­rage, or the pur­po­se for sto­ring the data no lon­ger appli­es (e.g., after your request has been pro­ces­sed). Com­pul­so­ry sta­tu­to­ry pro­vi­si­ons – in par­ti­cu­lar sta­tu­to­ry reten­ti­on peri­ods – remain unaf­fec­ted.

Registration with Facebook Connect

Ins­tead of regis­tering direct­ly on this web­site, you can regis­ter using Face­book Con­nect. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ire­land. Howe­ver, accor­ding to Face­book, the data coll­ec­ted is also trans­fer­red to the USA and other third count­ries.

If you choo­se to regis­ter using Face­book Con­nect and click the „Log­in with Facebook”/„Connect with Face­book” but­ton, you will auto­ma­ti­cal­ly be redi­rec­ted to the Face­book plat­form. The­re you can log in using your user data. This will link your Face­book pro­fi­le with this web­site or our ser­vices. Through this link, we gain access to the data you have stored on Face­book. This includes:

  • Face­book name
  • Face­book pro­fi­le and cover pho­to
  • Face­book cover image
  • E‑mail address regis­tered on Face­book
  • Face­book ID
  • Face­book fri­end lists
  • Face­book Likes („Like“ state­ments)
  • Bir­th­day
  • Gen­der
  • Sta­te
  • Lan­guage

This data is used to set up, pro­vi­de, and per­so­na­li­ze your account.

Regis­tra­ti­on with Face­book Con­nect and the asso­cia­ted data pro­ces­sing ope­ra­ti­ons are car­ri­ed out based on your con­sent (Art. 6(1)(a) GDPR). You can revo­ke this con­sent at any time with effect for the future.

As far as per­so­nal data is coll­ec­ted on our web­site using the tool descri­bed here and for­ward­ed to Face­book, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land are joint­ly respon­si­ble for this data pro­ces­sing (Artic­le 26 GDPR). In this case, the joint respon­si­bi­li­ty is limi­t­ed sole­ly to the coll­ec­tion of the data and its for­war­ding to Face­book. The pro­ces­sing car­ri­ed out by Face­book after for­war­ding is not part of the joint respon­si­bi­li­ty. The obli­ga­ti­ons shared by us have been set out in a joint pro­ces­sing agree­ment. The text of the agree­ment can be found here: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for pro­vi­ding the pri­va­cy infor­ma­ti­on when using the Face­book tool and for imple­men­ting the tool in a data pro­tec­tion-com­pli­ant man­ner on our web­site. Face­book is respon­si­ble for the data secu­ri­ty of the Face­book pro­ducts. Affec­ted rights (e.g. requests for infor­ma­ti­on) regar­ding the data pro­ces­sed by Face­book can be asser­ted direct­ly with Face­book. If you assert the affec­ted rights with us, we are obli­ged to for­ward them to Face­book.

The data trans­fer to the USA is based on the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.

For more infor­ma­ti­on, plea­se refer to the Face­book Terms of Use and the Face­book Pri­va­cy Poli­cy, which can be found at: https://de-de.facebook.com/about/privacy/ and https://de-de.facebook.com/legal/terms/.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

5. Social media

Facebook

This web­site includes ele­ments of the social net­work Face­book. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, Mer­ri­on Road, Dub­lin 4, D04 X2K5, Ire­land. Howe­ver, accor­ding to Face­book, the data coll­ec­ted is also trans­fer­red to the USA and other third count­ries.

An over­view of the Face­book social media ele­ments can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE.

When the social media ele­ment is acti­ve, a direct con­nec­tion is estab­lished bet­ween your end device and the Face­book ser­ver. Face­book thus recei­ves the infor­ma­ti­on that you have visi­ted this web­site using your IP address. If you click the Face­book „Like“ but­ton while log­ged into your Face­book account, you can link the con­tent of this web­site to your Face­book pro­fi­le. This allows Face­book to asso­cia­te the visit to this web­site with your user account. Plea­se note that we, as the pro­vi­der of the pages, have no know­ledge of the con­tent of the trans­mit­ted data or its use by Face­book. For more infor­ma­ti­on, plea­se refer to Facebook’s pri­va­cy poli­cy at: https://de-de.facebook.com/privacy/explanation.

The use of this ser­vice is based on your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. The con­sent can be revo­ked at any time.

As far as per­so­nal data is coll­ec­ted on our web­site using the tool descri­bed here and for­ward­ed to Face­book, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land are joint­ly respon­si­ble for this data pro­ces­sing (Artic­le 26 GDPR). In this case, the joint respon­si­bi­li­ty is limi­t­ed sole­ly to the coll­ec­tion of the data and its for­war­ding to Face­book. The pro­ces­sing car­ri­ed out by Face­book after for­war­ding is not part of the joint respon­si­bi­li­ty. The obli­ga­ti­ons shared by us have been set out in a joint pro­ces­sing agree­ment. The text of the agree­ment can be found here: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for pro­vi­ding the pri­va­cy infor­ma­ti­on when using the Face­book tool and for imple­men­ting the tool in a data pro­tec­tion-com­pli­ant man­ner on our web­site. Face­book is respon­si­ble for the data secu­ri­ty of the Face­book pro­ducts. Affec­ted rights (e.g. requests for infor­ma­ti­on) regar­ding the data pro­ces­sed by Face­book can be asser­ted direct­ly with Face­book. If you assert the affec­ted rights with us, we are obli­ged to for­ward them to Face­book.

The data trans­fer to the USA is based on the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

6. Analysis tools and advertising

Google Tag Manager

We use the Goog­le Tag Mana­ger. The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

The Goog­le Tag Mana­ger is a tool with which we can inte­gra­te track­ing or sta­tis­ti­cal tools and other tech­no­lo­gies on our web­site. The Goog­le Tag Mana­ger its­elf does not crea­te user pro­files, does not store coo­kies, and does not per­form any inde­pen­dent ana­ly­sis. It ser­ves sole­ly to mana­ge and dis­play the tools inte­gra­ted through it. Howe­ver, the Goog­le Tag Mana­ger does coll­ect your IP address, which may also be trans­fer­red to the parent com­pa­ny of Goog­le in the United Sta­tes.

The use of the Goog­le Tag Mana­ger is based on Art. 6(1)(f) GDPR. The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in the quick and easy inte­gra­ti­on and manage­ment of various tools on its web­site. If appro­pria­te con­sent has been reques­ted, pro­ces­sing takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, inso­far as the con­sent includes the sto­rage of coo­kies or access to infor­ma­ti­on on the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. Con­sent can be revo­ked at any time.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Hotjar

This web­site uses Hot­jar. The pro­vi­der is Hot­jar Ltd, Level 2, St Juli­ans Busi­ness Cent­re, 3, Elia Zam­mit Street, St Juli­ans STJ 1000, Mal­ta, Euro­pe (Web­site: https://www.hotjar.com).

Hot­jar is a tool for ana­ly­zing your user beha­vi­or on this web­site. With Hot­jar, we can, among other things, record your mou­se move­ments and scrol­ling and clicks. Hot­jar can also deter­mi­ne how long you remain with the mou­se cur­sor on a spe­ci­fic area. Based on this infor­ma­ti­on, Hot­jar crea­tes so-cal­led heat­maps that show which are­as of the web­site are pre­fer­red by the web­site visi­tor.

Fur­ther­mo­re, we can deter­mi­ne how long you stay­ed on a page and when you left it. We can also deter­mi­ne at which point you inter­rupt­ed your input in a cont­act form (so-cal­led con­ver­si­on fun­nels).

Fur­ther­mo­re, Hot­jar can coll­ect direct feed­back from web­site visi­tors. This func­tion is used to impro­ve the web­site operator’s web offe­rings.

Hot­jar uses tech­no­lo­gies that enable the reco­gni­ti­on of the user for the pur­po­se of ana­ly­zing user beha­vi­or (e.g., coo­kies or the use of device fin­ger­prin­ting).

Pro­vi­ded that con­sent has been obtai­ned, the use of the afo­re­men­tio­ned ser­vice is exclu­si­ve­ly based on Art. 6(1)(a) GDPR and § 25 TDDDG. Con­sent can be revo­ked at any time. In the absence of con­sent, the use of this ser­vice is based on Art. 6(1)(f) GDPR; the web­site ope­ra­tor has a legi­ti­ma­te inte­rest in ana­ly­zing user beha­vi­or in order to opti­mi­ze both its web offe­rings and its adver­ti­sing.

Deactivating Hotjar

If you want to disable data coll­ec­tion by Hot­jar, click on the fol­lo­wing link and fol­low the ins­truc­tions the­re: https://www.hotjar.com/policies/do-not-track/

Plea­se note that the deac­ti­va­ti­on of Hot­jar must be per­for­med sepa­ra­te­ly for each brow­ser or device.

For more infor­ma­ti­on about Hot­jar and the data coll­ec­ted, plea­se refer to Hotjar’s pri­va­cy poli­cy at the fol­lo­wing link: https://www.hotjar.com/privacy

Order processing

We have con­cluded a con­tract for the pro­ces­sing of orders (AVV) for the use of the afo­re­men­tio­ned ser­vice. This is a con­tract requi­red by data pro­tec­tion law that ensu­res that this ser­vice pro­ces­ses the per­so­nal data of our web­site visi­tors only in accordance with our ins­truc­tions and in com­pli­ance with the GDPR.

Google Ads

The web­site ope­ra­tor uses Goog­le Ads. Goog­le Ads is an online adver­ti­sing pro­gram of Goog­le Ire­land Limi­t­ed („Goog­le“), Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

Goog­le Ads allows us to dis­play adver­ti­se­ments in the Goog­le search engi­ne or on third-par­ty web­sites when the user enters cer­tain search terms into Goog­le (key­word tar­ge­ting). Fur­ther­mo­re, tar­ge­ted adver­ti­se­ments can be dis­play­ed based on the user data available at Goog­le (e.g., loca­ti­on data and inte­rests) (demo­gra­phic tar­ge­ting). As a web­site ope­ra­tor, we can quan­ti­ta­tively eva­lua­te this data by, for exam­p­le, ana­ly­zing which search terms led to the dis­play of our adver­ti­se­ments and how many ads resul­ted in cor­re­spon­ding clicks.

The use of this ser­vice is based on your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. The con­sent can be revo­ked at any time.

The data trans­fer to the USA is based on the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google Ads Remarketing

This web­site uses the fea­tures of Goog­le Ads Remar­ke­ting. The pro­vi­der is Goog­le Ire­land Limi­t­ed („Goog­le“), Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

With Goog­le Ads Remar­ke­ting, we can assign spe­ci­fic tar­get groups to peo­p­le who inter­act with our online offe­ring in order to sub­se­quent­ly dis­play inte­rest-based adver­ti­sing in the Goog­le adver­ti­sing net­work (remar­ke­ting or retar­ge­ting).

Fur­ther­mo­re, the adver­ti­sing audi­en­ces crea­ted with Goog­le Ads Remar­ke­ting can be lin­ked to Google’s cross-device fea­tures. In this way, inte­rest-based, per­so­na­li­zed adver­ti­sing mes­sa­ges that have been adapt­ed to you based on your pre­vious usa­ge and brow­sing beha­vi­or on one device (e.g., mobi­le pho­ne) can also be dis­play­ed on ano­ther of your devices (e.g., tablet or PC).

If you have a Goog­le account, you can object to per­so­na­li­zed adver­ti­sing at the fol­lo­wing link: https://adssettings.google.com/anonymous?hl=de.

The use of this ser­vice is based on your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. The con­sent can be revo­ked at any time.

Fur­ther infor­ma­ti­on and the data pro­tec­tion regu­la­ti­ons can be found in the Goog­le pri­va­cy poli­cy at: https://policies.google.com/technologies/ads?hl=de.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Meta Pixel (formerly Facebook Pixel)

This web­site uses the Visi­tor Action Pixel from Meta for con­ver­si­on mea­su­re­ment. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ire­land. Accor­ding to Meta, the data coll­ec­ted is also trans­fer­red to the USA and other third count­ries.

This allows the beha­vi­or of site visi­tors to be tra­cked after they have been redi­rec­ted to the provider’s web­site by cli­cking on a meta ad. This enables the effec­ti­ve­ness of the meta ads to be eva­lua­ted for sta­tis­ti­cal and mar­ket rese­arch pur­po­ses and future adver­ti­sing mea­su­res to be opti­mi­zed.

The coll­ec­ted data is anony­mous to us as the ope­ra­tor of this web­site; we can­not draw any con­clu­si­ons about the iden­ti­ty of the users. Howe­ver, the data is stored and pro­ces­sed by Meta, so that a con­nec­tion to the respec­ti­ve user pro­fi­le on Face­book or Insta­gram is pos­si­ble, and Meta uses the data for its own adver­ti­sing pur­po­ses, in accordance with the Meta Data Use Poli­cy (https://de-de.facebook.com/about/privacy/) can use. This allows Meta to enable the dis­play of adver­ti­se­ments on Face­book or Insta­gram pages and other adver­ti­sing chan­nels. This use of the data can­not be influen­ced by us as the site ope­ra­tor.

The use of this ser­vice is based on your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. The con­sent can be revo­ked at any time.

To the ext­ent that per­so­nal data is coll­ec­ted on our web­site using the tool descri­bed here and for­ward­ed to Meta, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land are joint­ly respon­si­ble for this data pro­ces­sing (Artic­le 26 GDPR). In this case, the joint respon­si­bi­li­ty is limi­t­ed sole­ly to the coll­ec­tion of the data and their trans­mis­si­on to Meta. The pro­ces­sing car­ri­ed out by Meta after trans­mis­si­on is not part of the joint respon­si­bi­li­ty. The obli­ga­ti­ons we joint­ly have are set out in a joint pro­ces­sing agree­ment. The text of the agree­ment can be found here: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for pro­vi­ding the pri­va­cy infor­ma­ti­on when using the Meta tool and for imple­men­ting the tool in a data pro­tec­tion-com­pli­ant man­ner on our web­site. Meta is respon­si­ble for the data secu­ri­ty of the Meta pro­ducts. Affec­ted rights (e.g. access requests) regar­ding the data pro­ces­sed by Face­book or Insta­gram can be asser­ted direct­ly with Meta. When you assert the affec­ted rights with us, we are obli­ged to for­ward them to Meta.

The data trans­fer to the USA is based on the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

You can find fur­ther infor­ma­ti­on about pro­tec­ting your pri­va­cy in Meta’s pri­va­cy poli­cy: https://de-de.facebook.com/about/privacy/.

You can also use the „Cus­tom Audi­en­ces” remar­ke­ting fea­ture in the “Adver­ti­sing set­tings” sec­tion under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deac­ti­va­te. To do this, you must be log­ged in to Face­book.

If you do not have an account on Face­book or Insta­gram, you can disable usa­ge-based adver­ti­sing from Meta on the web­site of the Euro­pean Inter­ac­ti­ve Digi­tal Adver­ti­sing Alli­ance: http://www.youronlinechoices.com/de/praferenzmanagement/.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

7. Newsletter

Newsletter data

If you wish to recei­ve the news­let­ter offe­red on the web­site, we requi­re an email address from you as well as infor­ma­ti­on that allows us to veri­fy that you are the owner of the spe­ci­fied email address and that you agree to recei­ve the news­let­ter. No other data is coll­ec­ted, or only on a vol­un­t­a­ry basis. We use this data exclu­si­ve­ly for the deli­very of the reques­ted infor­ma­ti­on and do not dis­c­lo­se it to third par­ties.

The pro­ces­sing of the data ente­red into the news­let­ter regis­tra­ti­on form takes place sole­ly on the basis of your con­sent (Artic­le 6(1)(a) GDPR). You may revo­ke the con­sent given to store the data, the email address, and to use it to send the news­let­ter at any time, for exam­p­le via the „unsub­scri­be“ link in the news­let­ter. The lega­li­ty of the data pro­ces­sing ope­ra­ti­ons that have alre­a­dy taken place remains unaf­fec­ted by the revo­ca­ti­on.

The data you pro­vi­de to us for the pur­po­se of sub­scrib­ing to the news­let­ter will be stored by us until you unsub­scri­be from the news­let­ter, or after the news­let­ter has been dele­ted for any other reason. We reser­ve the right to dele­te or block email addres­ses from our news­let­ter dis­tri­bu­ti­on list at our dis­cre­ti­on within the scope of our legi­ti­ma­te inte­rest under Art. 6(1)(f) GDPR.

Data that was stored with us for other pur­po­ses remains unaf­fec­ted by this.

After you are remo­ved from the news­let­ter dis­tri­bu­ti­on list, your email address may be stored in a black­list with us or the news­let­ter ser­vice pro­vi­der, if neces­sa­ry to pre­vent future mai­lings. The data from the black­list is only used for this pur­po­se and not com­bi­ned with other data. This ser­ves both your and our inte­rests in com­ply­ing with legal requi­re­ments regar­ding the sen­ding of news­let­ters (legi­ti­ma­te inte­rest within the mea­ning of Art. 6(1)(f) GDPR). The sto­rage in the black­list is not time-limi­t­ed. You can object to the sto­rage if your inte­rests out­weigh our legi­ti­ma­te inte­rest.

8. Plugins and Tools

Google Maps

This page uses the Goog­le Maps map­ping ser­vice. The pro­vi­der is Goog­le Ire­land Limi­t­ed („Goog­le“), Gor­don House, Bar­row Street, Dub­lin 4, Ire­land. With the help of this ser­vice, we can embed map mate­ri­al on our web­site.

To use the func­tions of Goog­le Maps, it is neces­sa­ry to store your IP address. This infor­ma­ti­on is usual­ly trans­mit­ted to a Goog­le ser­ver in the USA and stored the­re. The pro­vi­der of this page has no influence on this data trans­mis­si­on. When Goog­le Maps is acti­va­ted, Goog­le can use Goog­le Fonts for uni­form dis­play of fonts. When you call up Goog­le Maps, your brow­ser loads the requi­red web fonts into its brow­ser cache to dis­play text and fonts cor­rect­ly.

The use of Goog­le Maps is done in the inte­rest of an appe­al­ing pre­sen­ta­ti­on of our online offe­rings and of easy fin­ding of the places indi­ca­ted by us on the web­site. This con­sti­tu­tes a legi­ti­ma­te inte­rest within the mea­ning of Art. 6(1)(f) GDPR. If appro­pria­te con­sent has been reques­ted, the pro­ces­sing takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, inso­far as the con­sent includes the sto­rage of coo­kies or access to infor­ma­ti­on on the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of TDDDG. The con­sent is revo­ca­ble at any time.

The data trans­fer to the USA is based on the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

For more infor­ma­ti­on about how user data is hand­led, plea­se see Google’s pri­va­cy poli­cy: https://policies.google.com/privacy?hl=de.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google reCAPTCHA

We use „Goog­le reCAPTCHA“ (her­ein­af­ter „reCAPTCHA“) on this web­site. The pro­vi­der is Goog­le Ire­land Limi­t­ed („Goog­le“), Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

reCAPTCHA is used to veri­fy whe­ther the data ent­ry on this web­site (e.g. in a cont­act form) is per­for­med by a human or by an auto­ma­ted pro­gram. To do this, reCAPTCHA ana­ly­zes the beha­vi­or of the web­site visi­tor based on various cha­rac­te­ristics. This ana­ly­sis beg­ins auto­ma­ti­cal­ly as soon as the web­site visi­tor enters the web­site. To ana­ly­ze the data, reCAPTCHA eva­lua­tes various infor­ma­ti­on (e.g. IP address, dura­ti­on of the web­site visit by the visi­tor or mou­se move­ments made by the user). The data coll­ec­ted during the ana­ly­sis is for­ward­ed to Goog­le.

The reCAPTCHA ana­ly­ses run enti­re­ly in the back­ground. Web­site visi­tors are not infor­med that an ana­ly­sis is taking place.

The sto­rage and ana­ly­sis of the data is car­ri­ed out in accordance with Art. 6(1)(f) GDPR. The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in pro­tec­ting its web offe­rings from abu­si­ve auto­ma­ted spy­ing and spam. If appro­pria­te con­sent has been reques­ted, the pro­ces­sing takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, inso­far as the con­sent includes the sto­rage of coo­kies or access to infor­ma­ti­on on the user’s device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. Con­sent may be revo­ked at any time.

For more infor­ma­ti­on about Goog­le reCAPTCHA, plea­se refer to the Goog­le Pri­va­cy Poli­cy and the Goog­le Terms of Ser­vice at the fol­lo­wing links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.

The com­pa­ny is cer­ti­fied under the „EU-US Data Pri­va­cy Frame­work“ (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the United Sta­tes that is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards when pro­ces­sing data in the United Sta­tes. Any com­pa­ny cer­ti­fied under the DPF is requi­red to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der via the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

9. E‑commerce and payment providers

Processing of customer and contract data

We coll­ect, pro­cess, and use per­so­nal cus­to­mer and con­trac­tu­al data to estab­lish, struc­tu­re, and modi­fy our con­trac­tu­al rela­ti­onships. We only coll­ect, pro­cess, and use per­so­nal data regar­ding the use of this web­site (usa­ge data) to the ext­ent neces­sa­ry to enable the user to use the ser­vice or to bill them. The legal basis for this is Art. 6(1)(b) GDPR.

The cus­to­mer data coll­ec­ted will be dele­ted after the com­ple­ti­on of the order or ter­mi­na­ti­on of the busi­ness rela­ti­onship and the expiry of any appli­ca­ble legal reten­ti­on peri­ods. Legal reten­ti­on peri­ods remain unaf­fec­ted.

10. Own services

Handling applicant data

We offer you the oppor­tu­ni­ty to app­ly to us (e.g. by e‑mail, pos­tal mail or via the online appli­ca­ti­on form). In the fol­lo­wing we inform you about the scope, pur­po­se and use of the per­so­nal data coll­ec­ted as part of the appli­ca­ti­on pro­cess. We assu­re you that the coll­ec­tion, pro­ces­sing and use of your data is car­ri­ed out in accordance with appli­ca­ble data pro­tec­tion law and all other legal regu­la­ti­ons, and that your data will be trea­ted strict­ly con­fi­den­ti­al­ly.

Scope and purpose of data collection

When you sub­mit an appli­ca­ti­on to us, we pro­cess the per­so­nal data rela­ted to it (e.g., cont­act and com­mu­ni­ca­ti­on data, appli­ca­ti­on docu­ments, notes during job inter­views, etc.), inso­far as this is neces­sa­ry for deci­ding on the con­clu­si­on of an employ­ment rela­ti­onship. The legal basis for this is § 26 BDSG under Ger­man law (initia­ti­on of an employ­ment rela­ti­onship), Art. 6(1)(b) GDPR (gene­ral con­tract initia­ti­on), and – if you have given your con­sent – Art. 6(1)(a) GDPR. Your con­sent is revo­ca­ble at any time. Your per­so­nal data will only be dis­c­lo­sed to per­sons invol­ved in pro­ces­sing your appli­ca­ti­on within our com­pa­ny.

If the appli­ca­ti­on is suc­cessful, the data sub­mit­ted by you will be stored in our data pro­ces­sing sys­tems based on § 26 BDSG and Art. 6(1)(b) GDPR for the pur­po­se of imple­men­ting the employ­ment rela­ti­onship.

Data retention period

If we are unable to offer you a job, refu­se to accept an offer of employ­ment, or with­draw your appli­ca­ti­on, we reser­ve the right to store the data you have pro­vi­ded with us for up to 6 months from the end of the appli­ca­ti­on pro­cess (rejec­tion or with­dra­wal of the appli­ca­ti­on), based on our legi­ti­ma­te inte­rests (Art. 6(1)(f) GDPR). After that, the data will be dele­ted and the phy­si­cal appli­ca­ti­on docu­ments des­troy­ed. The sto­rage ser­ves, in par­ti­cu­lar, as evi­dence in the event of a legal dis­pu­te. If it is appa­rent that the data will be requi­red after the 6‑month peri­od has expi­red (e.g., due to an immi­nent or pen­ding legal dis­pu­te), a dele­ti­on will only take place when the pur­po­se for fur­ther sto­rage no lon­ger appli­es.

Lon­ger sto­rage may also take place if you have given your con­sent (Artic­le 6(1)(a) GDPR) or if sta­tu­to­ry reten­ti­on obli­ga­ti­ons pre­clude dele­ti­on.

Inclusion in the applicant pool

If we do not offer you a job, the­re is the pos­si­bi­li­ty of inclu­ding you in our appli­cant pool. In the event of accep­tance, all docu­ments and infor­ma­ti­on from the appli­ca­ti­on will be added to the appli­cant pool in order to cont­act you in the event of sui­ta­ble vacan­ci­es.

Admis­si­on to the appli­cant pool takes place sole­ly on the basis of your express con­sent (Art. 6(1)(a) GDPR). The con­sent is vol­un­t­a­ry and is not rela­ted to the ongo­ing appli­ca­ti­on pro­cess. The data sub­ject can with­draw their con­sent at any time. In this case, the data from the appli­cant pool will be dele­ted irre­vo­ca­bly, unless the­re are any legal reasons for retai­ning it.

The data from the appli­cant pool will be dele­ted irre­vo­ca­bly no later than two years after con­sent is gran­ted.