1. Introduction and Contact Details of the Data Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data refers to all data by which you can be personally identified.

1.2 The data controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Inna Ropchan, Ritterstr. 42, 10969 Berlin, Germany, Tel.: +491777201126, E-mail: in**@*************in.de. The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

1.3 The data controller has appointed a data protection officer who can be contacted as follows: Inna Ropchan, Ritterstr. 42, 10969 Berlin.

  1. Data Collection When Visiting Our Website

2.1 When you visit our website purely for informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data which is technically necessary for us to display the website:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

Processing is carried out in accordance with Art. 6 (1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the character string “https://” and the lock symbol in your browser line.

  1. Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files stored on your device. Some of the cookies we use are deleted after your browser session ends (so-called “session cookies”). Other cookies remain on your device and allow us to recognize your browser on your next visit (so-called “persistent cookies”). You can find the duration of storage in the cookie settings of your browser.

If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 (1)(b) GDPR for contract execution, or in accordance with Art. 6 (1)(a) GDPR in the case of given consent, or in accordance with Art. 6 (1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can set your browser to inform you about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies for specific cases or in general.

Please note that the functionality of our website may be limited if cookies are not accepted.

  1. Contacting Us

When you contact us (e.g., via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your inquiry or for establishing contact and the associated technical administration.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 (1)(f) GDPR. If your contact is aimed at concluding a contract, then the additional legal basis for processing is Art. 6 (1)(b) GDPR. Your data will be deleted after the final processing of your inquiry, provided that there are no legal retention obligations.

  1. Use of Customer Data for Direct Advertising

Subscription to Our E-Mail Newsletter

If you subscribe to our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your e-mail address. The provision of further data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter if you have expressly confirmed that you agree to receive newsletters. We will then send you a confirmation e-mail asking you to confirm by clicking a corresponding link that you wish to receive newsletters in the future.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 (1)(a) GDPR. When registering for the newsletter, we store your IP address entered by the Internet service provider (ISP) as well as the date and time of registration to be able to trace a possible misuse of your e-mail address at a later time. The data collected when registering for the newsletter will be used exclusively for the purposes of promotional communication via the newsletter.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the above-mentioned controller. After unsubscribing, your e-mail address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law and which we inform you about in this policy.

  1. Web Analytics Services

6.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”), which enables the analysis of your use of our website.

By default, when visiting the website, cookies are set by Google Analytics 4, which are small text files stored on your device that collect specific information. This includes your IP address, which is, however, truncated by Google to exclude a direct personal reference.

The information is transmitted to Google servers and processed there. Transfers to Google LLC in the USA may also occur.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activity, and provide us with other services related to website and internet usage. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. The data collected through Google Analytics 4 is stored for two months and then deleted.

All the processing described above, in particular the setting of cookies, will only take place if you have given us your express consent pursuant to Art. 6 (1)(a) GDPR.

Without your consent, Google Analytics 4 will not be used during your website visit. You can revoke your consent at any time with future effect by deactivating this service via the “Cookie Consent Tool” provided on the website.

We have entered into a data processing agreement with Google to ensure the protection of our website visitors’ data and to prohibit unauthorized disclosure to third parties.

Further legal information on Google Analytics 4 can be found at: https://business.safety.google/intl/en/privacy/, https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites

Demographics Features Google Analytics 4 uses the “demographics features” function to create statistics on age, gender, and interests based on advertising and information from third parties. This helps identify target groups for marketing activities. The collected data cannot be assigned to a specific person and is deleted after two months.

Google Signals As an extension of Google Analytics 4, this website may use Google Signals to enable cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google can analyze your usage behavior across devices, subject to your consent to the use of Google Analytics (Art. 6 (1)(a) GDPR). We do not receive any personal data from Google, only statistics. To disable cross-device analysis, deactivate “personalized ads” in your Google account settings. More info: https://support.google.com/analytics/answer/7532985

UserIDs As an extension to Google Analytics 4, the “UserIDs” function may be used on this website. If you have consented to Google Analytics 4 and created an account, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of protection.

6.2 Google Tag Manager

This website uses the “Google Tag Manager,” a service provided by the following provider:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”).

The Google Tag Manager provides a technical framework that allows multiple web applications, including tracking and analytics services, to be combined, calibrated, managed, and conditioned through a unified user interface. The Google Tag Manager itself does not store or read any information on user devices. Nor does it perform any independent data analysis. However, when a page is accessed, the Google Tag Manager transmits your IP address to Google, where it may be stored. Data may also be transferred to servers belonging to Google LLC. in the USA.

This processing only occurs if you have granted us your explicit consent under Art. 6(1)(a) of the GDPR. Without such consent, Google Tag Manager will not be used during your visit to our website. You can withdraw your consent at any time with future effect. To exercise your right of withdrawal, please deactivate this service in the “cookie-consent tool” provided on the website.

We have entered into a data processing agreement with the provider, ensuring the protection of our website visitors’ data and preventing unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

Additional legal information on Google Tag Manager can be found at:
https://business.safety.google/intl/de/privacy/
and
https://policies.google.com/privacy?hl=de&gl=de

6.3 Piwik PRO

This website uses the web analytics service provided by the following provider:
Piwik PRO GmbH, Kurfürstendamm 21, 10719 Berlin, Germany

Using cookies and/or comparable technologies (tracking pixels, web beacons, algorithms for reading device and browser information), this service collects and stores pseudonymized visitor data, including information on the device used (such as IP address and browser data) for the purpose of statistically analyzing user behavior on our website and creating pseudonymized user profiles. This enables, among other things, the evaluation of movement patterns (so-called “heatmaps”), which show the duration of page visits and interactions with page content (e.g., text entries, scrolling, clicks, and mouse-overs). Pseudonymization generally rules out direct personal identification. The data is not merged with any personally identifiable data about you collected by other means.

All of the above-mentioned processing operations, especially reading or storing information on the device used, only take place if you have provided us with your explicit consent under Art. 6(1)(a) GDPR. You can withdraw this consent at any time with future effect by deactivating this service in the “cookie-consent tool” provided on the website.

We have entered into a data processing agreement with the provider, ensuring the protection of our website visitors’ data and preventing unauthorized disclosure to third parties.

7) Retargeting/Remarketing and Conversion Tracking

7.1 Meta Pixel with Extended Data Matching

Within our online offering, we use the “Meta Pixel” service in extended data matching mode, provided by:
Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Meta”)

When a user clicks on an advertisement we have placed on Facebook or Instagram, the URL of our linked page is expanded with a parameter using “Meta Pixel.” After the redirection, this URL parameter is stored in the user’s browser via a cookie that our linked page itself sets. In addition, this cookie captures specific customer data (e.g., email address) that we gather on our website in connection with Facebook or Instagram ads for transactions such as purchases, account logins, or registrations (“extended data matching”). The cookie is then read and enables the transmission of data, including specific customer data, to Meta.

We use “Meta Pixel” with extended data matching to make our advertisements (“Ads”) on Facebook and/or Instagram more effective and to ensure that they meet the interests of users or exhibit certain characteristics (e.g., interests in certain topics or products identified by the visited websites), which we transmit to Meta (“Custom Audiences”).

We also analyze the effectiveness of our advertisements by determining whether users were redirected to our website after clicking on an ad (conversion). Compared to the standard version of “Meta Pixel,” the extended data matching feature helps us better measure the effectiveness of our ad campaigns by capturing more attributable conversions.

All transmitted data is stored and processed by Meta, allowing a connection to the respective user profile. Meta may use this data for its own advertising purposes in accordance with Meta’s Data Use Policy (https://www.facebook.com/about/privacy/). The data may enable Meta and its partners to display ads on and outside of Facebook.

All of the above-described processing, particularly the setting of cookies for reading information on the device used, only takes place if you have provided us with your explicit consent under Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect by deactivating this service in the “cookie-consent tool” provided on the website.

We have entered into a data processing agreement with the provider, ensuring the protection of our website visitors’ data and preventing unauthorized disclosure to third parties.

The information generated by Meta is typically transmitted to and stored on a Meta server; in this context, data may also be transferred to Meta Platforms Inc. servers in the USA.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

7.2 Google Ads Conversion Tracking

This website uses the online advertising program “Google Ads” and, within Google Ads, the conversion tracking feature by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). We use the Google Ads service to draw attention, via advertising media (so-called Google AdWords) on external websites, to our attractive offers. We can determine how successful individual advertising measures are in relation to the data of the ad campaigns. Our aim is to show you advertising that interests you, make our website more engaging for you, and achieve a fair calculation of advertising costs.

The conversion-tracking cookie is set when a user clicks on an ad placed by Google. These cookies are small text files stored on your device. They typically expire after 30 days and are not used for personal identification. If a user visits certain pages on this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Thus, cookies cannot be tracked across Google Ads customers’ websites. The information collected using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page featuring a conversion tracking tag. However, they do not receive any information that can personally identify users. As part of the use of Google Ads, personal data may also be transferred to the servers of Google LLC. in the USA.

Details on the processing triggered by Google Ads Conversion Tracking and Google’s handling of website data can be found here: https://policies.google.com/technologies/partner-sites

All of the above-mentioned processing, particularly the setting of cookies for reading information on the device used, only takes place if you have provided us with your explicit consent under Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect by deactivating this service in the “cookie-consent tool” provided on our website.

You can also permanently object to the setting of cookies by Google Ads Conversion Tracking by downloading and installing the browser plug-in available at the following link:
https://www.google.com/settings/ads/plugin?hl=de

Please note that certain features of this website may not function, or only function to a limited extent, if you have disabled the use of cookies.
Google’s privacy policy can be viewed here:
https://business.safety.google/intl/de/privacy/ and
https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

8) Website Features

8.1 Facebook Plugins

Our website uses plugins from the social network operated by the following provider:
Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins allow direct interaction with the content of the social network.

To enhance the protection of your data when you visit our website, these plugins are initially deactivated by means of the “2-click” or “Shariff” solution.

This setup ensures that when you access a page on our website that contains such plugins, no direct connection is established with the provider’s servers.

Only when you activate the plugins and thus grant your consent to the data transfer under Art. 6(1)(a) GDPR does your browser establish a direct connection to the provider’s servers. During this process, irrespective of whether you are logged into an existing user account, certain information regarding your device (including your IP address), your browser, and your browsing history may be transmitted to the provider and possibly processed further.

If you are logged into an existing user profile with the provider’s social network, information about the plugin interactions is also published there and shown to your contacts.
You can withdraw your consent at any time by clicking again to deactivate the plugin. However, withdrawal does not affect the data already transferred to the provider.

Data may also be transferred to Meta Platforms Inc., USA.

We have entered into a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

8.2 Instagram Plugins

Our website uses plugins from the social network operated by the following provider:
Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins allow direct interaction with the content of the social network.

To enhance the protection of your data when you visit our website, these plugins are initially deactivated by means of the “2-click” or “Shariff” solution.

This setup ensures that when you access a page on our website that contains such plugins, no direct connection is established with the provider’s servers.

Only when you activate the plugins and thus grant your consent to the data transfer under Art. 6(1)(a) GDPR does your browser establish a direct connection to the provider’s servers. During this process, irrespective of whether you are logged into an existing user account, certain information regarding your device (including your IP address), your browser, and your browsing history may be transmitted to the provider and possibly processed further.

If you are logged into an existing user profile with the provider’s social network, information about the plugin interactions is also published there and shown to your contacts.
You can withdraw your consent at any time by clicking again to deactivate the plugin. However, withdrawal does not affect the data already transferred to the provider.

Data may also be transferred to Meta Platforms Inc., USA.

We have entered into a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

8.3 LinkedIn Plugins

Our website uses plugins from the social network operated by the following provider:
LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland

These plugins allow direct interaction with the content of the social network.

To enhance the protection of your data when you visit our website, these plugins are initially deactivated by means of the “2-click” or “Shariff” solution.

This setup ensures that when you access a page on our website that contains such plugins, no direct connection is established with the provider’s servers.

Only when you activate the plugins and thus grant your consent to the data transfer under Art. 6(1)(a) GDPR does your browser establish a direct connection to the provider’s servers. During this process, irrespective of whether you are logged into an existing user account, certain information regarding your device (including your IP address), your browser, and your browsing history may be transmitted to the provider and possibly processed further.

If you are logged into an existing user profile with the provider’s social network, information about the plugin interactions is also published there and shown to your contacts.
You can withdraw your consent at any time by clicking again to deactivate the plugin. However, withdrawal does not affect the data already transferred to the provider.

Data may also be transferred to LinkedIn Inc., USA.

We have entered into a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider relies on standard contractual clauses issued by the European Commission, which are intended to ensure compliance with the European level of data protection.

8.4 Pinterest Plugins

Our website uses plugins from the social network operated by the following provider:
Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland

These plugins allow direct interaction with the content of the social network.

To enhance the protection of your data when you visit our website, these plugins are initially deactivated by means of the “2-click” or “Shariff” solution.

This setup ensures that when you access a page on our website that contains such plugins, no direct connection is established with the provider’s servers.

Only when you activate the plugins and thus grant your consent to the data transfer under Art. 6(1)(a) GDPR does your browser establish a direct connection to the provider’s servers. During this process, irrespective of whether you are logged into an existing user account, certain information regarding your device (including your IP address), your browser, and your browsing history may be transmitted to the provider and possibly processed further.

If you are logged into an existing user profile with the provider’s social network, information about the plugin interactions is also published there and shown to your contacts.
You can withdraw your consent at any time by clicking again to deactivate the plugin. However, withdrawal does not affect the data already transferred to the provider.

Data may also be transferred to Pinterest Inc., USA.

We have entered into a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider relies on standard contractual clauses issued by the European Commission, which are intended to ensure compliance with the European level of data protection.

8.5 Google Maps

This website uses an online map service provided by the following provider:
Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps is a web service for displaying interactive (land) maps and visualizing geographic information. Using this service will show you our location and help you plan your route.

As soon as you access the subpages that include Google Maps, information about your use of our website (e.g., your IP address) is transmitted to Google’s servers, where it is stored. This may also involve transmission to servers of Google LLC. in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists at all. If you are logged in to Google, your data will be directly associated with your account. If you do not want your data to be associated with your Google profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them.

Collection, storage, and evaluation are carried out under Art. 6(1)(f) GDPR, based on Google’s legitimate interest in the display of personalized advertising, market research, and/or the design of Google websites according to users’ needs. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google in the context of using Google Maps, you also have the option of completely disabling the Google Maps web service by turning off JavaScript in your browser. In this case, Google Maps—and thus the map display on this website—cannot be used.

If legally required, we have obtained your consent under Art. 6(1)(a) GDPR to the aforementioned processing of your data. You can withdraw your consent at any time with future effect. To exercise your withdrawal, please use the objection method described above.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

Further information on Google’s privacy practices can be found here:
https://business.safety.google/intl/de/privacy/

8.6 Google Web Fonts

This site uses so-called web fonts for uniform font display from the following provider:
Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

When you call up a page, your browser loads the required web fonts into its browser cache to display text and fonts correctly and establishes a direct connection to the provider’s servers. Certain browser information, including your IP address, is transmitted to the provider.

Data may also be transferred to Google LLC in the USA.

The processing of personal data in connection with contacting the provider of the fonts only takes place if you have given us your explicit consent under Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect by deactivating this service in the “cookie-consent tool” provided on the website. If your browser does not support web fonts, a standard font is used by your computer.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

Further information on Google’s privacy policy can be found here:
https://business.safety.google/intl/de/privacy/

9) Tools and Other Services

9.1 Cookie-Consent Tool

This website uses a “cookie-consent tool” to obtain valid user consent for cookies and cookie-based applications that require consent. The “cookie-consent tool” is displayed to users on page access in the form of an interactive interface, through which they can grant consent for certain cookies and/or cookie-based applications by ticking a box. By using the tool, all cookies/services requiring consent are only loaded if the respective user grants corresponding consent by ticking the box. This ensures that such cookies are only placed on the user’s device if consent has been given.

The tool sets technically necessary cookies to store your cookie preferences. Personal user data is generally not processed in this context.

Should the processing of personal data (e.g., IP address) occur on an individual basis for purposes of storing, assigning, or logging cookie settings, it is done in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in a lawful, user-specific, and user-friendly consent management of cookies and in the lawful design of our online presence.

An additional legal basis for processing is Art. 6(1)(c) GDPR. As the responsible entity, we are legally obliged to make the use of technically non-essential cookies dependent on the respective user’s consent.

Where necessary, we have entered into a data processing agreement with the provider, ensuring the protection of our website visitors’ data and preventing unauthorized disclosure to third parties.

Further information about the operator and the configuration options of the cookie-consent tool can be found in the relevant user interface on our website.

9.2 – Papierkram

To manage our accounting, we use the cloud-based accounting software service from the following provider:
odacer Finanzsoftware GmbH, Konrad-Adenauer-Ring 13, 65187 Wiesbaden, Germany

This provider processes incoming and outgoing invoices and may also process bank transaction data for our business to capture invoices automatically, match them to transactions, and generate financial accounting reports through a semi-automated process.

If personal data is processed in this context, the processing is based on our legitimate interest in an efficient organization and documentation of our business operations.

9.3 CleanTalk

For security purposes, this website uses the service of the following provider:
CleanTalk Inc., 711 S Carson Street, Suite 4, Carson City, NV, 89701, USA

This provider protects the website and the associated IT infrastructure from unauthorized third-party access, cyberattacks, viruses, and malware. The provider collects users’ IP addresses and, if necessary, other data about their behavior on our website (particularly the URLs accessed and header information) to detect and prevent illegitimate website access and threats. The collected IP address is compared against a list of known attackers. If the IP address is identified as a security risk, the provider can automatically block it from accessing the site. The collected information is transmitted to and stored on the provider’s server.

The described data processing occurs under Art. 6(1)(f) GDPR on the basis of our legitimate interests in protecting the website from harmful cyberattacks and preserving structural and data integrity and security.

We have concluded a data processing agreement with the provider to ensure the protection of our website visitors’ data and prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

9.4 Solid Security

For security purposes, this website uses the service of the following provider:
Liquid Web LLC, 2703 Ena Dr, Lansing, MI 48917, USA

This provider protects the website and the associated IT infrastructure from unauthorized third-party access, cyberattacks, viruses, and malware. The provider collects users’ IP addresses and, if necessary, other data about their behavior on our website (particularly the URLs accessed and header information) to detect and prevent illegitimate website access and threats. The collected IP address is compared against a list of known attackers. If the IP address is identified as a security risk, the provider can automatically block it from accessing the site. The collected information is transmitted to and stored on the provider’s server.

The described data processing occurs under Art. 6(1)(f) GDPR on the basis of our legitimate interests in protecting the website from harmful cyberattacks and preserving structural and data integrity and security.

We have concluded a data processing agreement with the provider to ensure the protection of our website visitors’ data and prevent unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU–US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

10) Data Subject Rights

10.1 Under applicable data protection law, you have the following rights regarding the processing of your personal data (rights to information and intervention) vis-à-vis the controller, subject to the relevant legal requirements:

  • Right of access pursuant to Art. 15 GDPR
  • Right to rectification pursuant to Art. 16 GDPR
  • Right to erasure pursuant to Art. 17 GDPR
  • Right to restriction of processing pursuant to Art. 18 GDPR
  • Right to notification pursuant to Art. 19 GDPR
  • Right to data portability pursuant to Art. 20 GDPR
  • Right to withdraw consent granted pursuant to Art. 7(3) GDPR
  • Right to lodge a complaint pursuant to Art. 77 GDPR

10.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE REASONS FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES TO ESTABLISH, EXERCISE, OR DEFEND LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING. YOU MAY EXERCISE THE RIGHT TO OBJECT AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.

11) Duration of Storage of Personal Data

The duration for which personal data is stored is determined by the respective legal basis, the purpose of processing, and—if applicable—by the relevant statutory retention period (e.g., commercial and tax law retention periods).

When personal data is processed on the basis of an explicit consent pursuant to Art. 6(1)(a) GDPR, the data in question is stored until you withdraw your consent.

If there are statutory retention periods for data that is processed within the framework of contractual or quasi-contractual obligations on the basis of Art. 6(1)(b) GDPR, such data is routinely deleted upon expiry of these retention periods, provided it is no longer required for contract performance or initiation and provided there is no legitimate interest on our part in further storage.

When personal data is processed on the basis of Art. 6(1)(f) GDPR, it is stored until you exercise your right to object under Art. 21(1) GDPR, unless we can prove compelling legitimate reasons for the processing that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.

When personal data is processed for direct marketing purposes based on Art. 6(1)(f) GDPR, it is stored until you exercise your right to object under Art. 21(2) GDPR.

Unless otherwise specified in the other information contained in this notice about specific processing situations, stored personal data is otherwise deleted once it is no longer needed for the purposes for which it was collected or otherwise processed.