Privacy Policy
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: July 31, 2025
WHO IS RESPONSIBLE AND HOW CAN YOU REACH ME?
Responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR).
TRAURAUM - Theres Kirisits Fürstenplatz 2 c/o Schirmer 14052 Berlin Germany
Email: jetzt@trauraumtheres.com Website: www.trauraumtheres.com
OVERVIEW OF PROCESSING
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the persons affected.
Types of data processed
-
Inventory data.
-
Payment data.
-
Contact data.
-
Content data.
-
Contract data.
-
Usage data.
-
Meta, communication, and procedural data.
-
Event data (Facebook).
Categories of data subjects
-
Customers.
-
Prospective customers.
-
Communication partners.
-
Users.
-
Sweepstakes and competition participants.
-
Business and contractual partners.
-
Participants.
Purposes of processing
-
Provision of contractual services and fulfillment of contractual obligations.
-
Contact inquiries and communication.
-
Security measures.
-
Direct marketing.
-
Reach measurement.
-
Tracking.
-
Office and organizational procedures.
-
Management and response to inquiries.
-
Conducting sweepstakes and competitions.
-
Feedback.
-
Marketing.
-
Profiles with user-related information.
-
Provision of our online offering and user-friendliness.
-
IT infrastructure.
RELEVANT LEGAL BASES
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
-
Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of their personal data for a specific purpose or purposes.
-
Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract.
-
Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
-
Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes in particular the Act to Adapt Data Protection Law to Regulation (EU) 2016/679 and to Implement Directive (EU) 2016/680 (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Note on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information both under the Swiss Federal Act on Data Protection (Swiss FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that, due to its broader territorial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP such as "processing" of "personal data," "overriding interest," and "particularly sensitive personal data," the terms used in the GDPR, namely "processing" of "personal data," as well as "legitimate interest" and "special categories of data," are used. However, the legal meaning of the terms will continue to be determined in accordance with the Swiss FADP within the scope of its application.
SECURITY MEASURES
In accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood of occurrence and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input, disclosure, and availability of the data, and its separation. We have also established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and privacy-friendly default settings.
IP address truncation: If IP addresses are processed by us or by the service providers and technologies used, and full processing of the IP address is not necessary, the IP address is shortened (also known as "IP masking"). In this process, the last digits, or the last part of the IP address after a period, are removed or replaced with placeholders. The truncation of the IP address is intended to prevent or significantly complicate the identification of a person based on their IP address.
TLS/SSL encryption (https): To protect the data of users transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.
TRANSFER OF PERSONAL DATA
In the course of our processing of personal data, it may happen that data is transferred to or disclosed to other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
Data transfer within the organization: We may transfer personal data to other units within our organization or grant them access to this data. If this disclosure is for administrative purposes, it is based on our legitimate business and economic interests, or occurs because it is necessary to fulfill our contractual obligations, or if the consent of the data subjects has been obtained or a legal permission exists.
INTERNATIONAL DATA TRANSFERS
Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if processing occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies, or companies, this only occurs in accordance with legal requirements. If the level of data protection in the third country has been recognized by an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise guaranteed, in particular through standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or in the case of contractually or legally required transmission (Art. 49(1) GDPR). We will also inform you of the basis for third-country transfers with individual providers from third countries, whereby adequacy decisions take precedence as the basis. Information on third-country transfers and existing adequacy decisions can be found on the EU Commission's information page:
EU-US Trans-Atlantic Data Privacy Framework: Within the framework of the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognized the level of data protection for certain companies from the USA as adequate as part of the adequacy decision of July 10, 2023. The list of certified companies, as well as further information on the DPF, can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/. We inform you within these privacy notices which service providers we use are certified under the Data Privacy Framework.
RIGHTS OF DATA SUBJECTS
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
-
Right to object: You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing.
-
Right to withdraw consent: You have the right to withdraw any consent given at any time.
-
Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about this data as well as further information and a copy of the data in accordance with legal requirements.
-
Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
-
Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to demand that data concerning you be deleted without delay, or alternatively, in accordance with legal requirements, to demand a restriction of the processing of the data.
-
Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, common, and machine-readable format, or to request its transfer to another controller.
-
Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of personal data concerning you violates the provisions of the GDPR.
USE OF COOKIES
Cookies are small text files or other storage records that store information on end devices and read information from end devices. For example, to store login status in a user account, the contents of a shopping cart in an e-shop, the content accessed, or functions used in an online offering. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings, as well as generating analyses of visitor flows.
Notes on consent: We use cookies in accordance with legal requirements. We therefore obtain prior consent from users, except where this is not legally required. Consent is not required, in particular, if the storage and retrieval of information, including cookies, is absolutely necessary in order to provide users with a telemedia service they have expressly requested (i.e., our online offering). Strictly necessary cookies generally include cookies with functions that serve to display and operate the online offering, load balancing, security, storing user preferences and choices, or similar purposes related to the provision of the main and secondary functions of the online offering requested by users. Revocable consent is clearly communicated to users and includes information on the respective use of cookies.
Notes on data protection legal bases: The legal basis on which we process users' personal data using cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, data processed using cookies is processed on the basis of our legitimate interests (e.g., in the efficient operation of our online offering and improvement of its usability), or, if this occurs as part of fulfilling our contractual obligations, if the use of cookies is necessary to fulfill our contractual obligations. We explain the purposes for which cookies are processed by us within this privacy policy or as part of our consent and processing procedures.
Storage period: With regard to storage duration, the following types of cookies are distinguished:
-
Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their end device (e.g., browser or mobile application).
-
Persistent cookies: Persistent cookies remain stored even after the end device is closed. For example, login status can be saved, or preferred content can be displayed directly when the user visits a website again. Likewise, data collected using cookies can be used for reach measurement. If we do not provide users with explicit information about the type and storage duration of cookies (e.g., when obtaining consent), users should assume that cookies are persistent and that the storage period can be up to two years.
General notes on withdrawal and objection (so-called "opt-out"): Users can withdraw consent they have given at any time and object to processing in accordance with legal requirements. To do so, users can, among other things, restrict the use of cookies in their browser settings (although this may also restrict the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).
Further information on processing, procedures, and services:
Processing of cookie data based on consent: We use a consent management solution in which user consent for the use of cookies or for the procedures and providers named within the consent management solution is obtained. This procedure serves to obtain, log, manage, and revoke consent, particularly with regard to the use of cookies and comparable technologies used to store, read, and process information on users' devices. As part of this procedure, users' consent for the use of cookies and the associated processing of information, including the specific processing and providers named in the consent management procedure, is obtained. Users also have the option to manage and revoke their consent. Consent declarations are stored to avoid repeated queries and to be able to provide proof of consent in accordance with legal requirements. Storage occurs server-side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. Unless specific information on consent management service providers is available, the following general information applies: The consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, information on the scope of consent (e.g., categories of cookies and/or service providers concerned), and information about the browser, system, and end device used; legal basis: consent (Art. 6(1)(a) GDPR).
PAYMENT PROCEDURES
In the context of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, use additional service providers alongside banks and credit institutions (collectively "payment service providers").
The data processed by payment service providers includes inventory data, such as name and address, bank details, such as account numbers or credit card numbers, passwords, TANs, and checksums, as well as contract-, amount-, and recipient-related information. This information is necessary to carry out transactions. However, the data entered is only processed and stored by the payment service providers. This means we do not receive any account- or credit card-related information, but only information confirming or denying payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit reporting agencies. This transmission serves the purpose of identity and creditworthiness verification. For this purpose, we refer to the terms and conditions and privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers, which are available on the respective websites or transaction applications, apply to payment transactions. We also refer to these for further information and to exercise rights of withdrawal, access, and other data subject rights.
-
Types of data processed: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contract data (e.g., contract subject matter, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Customers. Prospective customers.
-
Purposes of processing: Provision of contractual services and fulfillment of contractual obligations.
-
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further information on processing, procedures, and services:
PayPal: Payment services (technical integration of online payment methods) (e.g., PayPal, PayPal Plus, Braintree); service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); website: https://www.paypal.com/. Privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full.
PROVISION OF THE ONLINE OFFERING AND WEB HOSTING
We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
-
Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); content data (e.g., entries in online forms).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures.
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing, procedures, and services:
-
Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity, and software that we rent or otherwise obtain from an appropriate server provider (also known as a "web host"); legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
-
Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g., to avoid overloading the servers (particularly in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure server utilization and stability; legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further storage is necessary for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.
-
Email sending and hosting: The web hosting services we use also include the sending, receiving, and storage of emails. For these purposes, the addresses of recipients and senders, as well as further information regarding email transmission (e.g., the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for spam detection purposes. Please note that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted during transmission, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We can therefore assume no responsibility for the transmission path of emails between the sender and receipt on our server; legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
-
Wix: Hosting and software for creating, providing, and operating websites, blogs, and other online offerings; service provider: Wix.com Ltd., Nemal St. 40, 6350671 Tel Aviv, Israel; legal bases: Legitimate interests (Art. 6(1)(f) GDPR); website: https://www.wix.com/; privacy policy: https://www.wix.com/about/privacy; data processing agreement: https://www.wix.com/about/privacy-dpa-users; basis for third-country transfers: adequacy decision (Israel). Further information: In the context of the aforementioned Wix services, data may also be transmitted to Wix Inc., 500 Terry A. Francois Boulevard, San Francisco, California 94158, USA, on the basis of standard contractual clauses or an equivalent data protection guarantee within the scope of further processing on behalf of Wix.
BLOGS AND PUBLICATION MEDIA
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is only processed for the purposes of the publication medium to the extent necessary for its presentation and communication between authors and readers, or for security reasons. For further information, we refer to the information on the processing of visitors to our publication medium contained within this privacy notice.
-
Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; feedback (e.g., collecting feedback via online forms); provision of our online offering and user-friendliness.
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
CONTACT AND INQUIRY MANAGEMENT
When contacting us (e.g., by mail, contact form, email, telephone, or via social media), as well as within the framework of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to respond to the contact inquiries and any requested measures.
-
Types of data processed: Contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Communication partners.
-
Purposes of processing: Contact inquiries and communication; management and response to inquiries; feedback (e.g., collecting feedback via online forms); provision of our online offering and user-friendliness. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further information on processing, procedures, and services:
-
Contact form: When users contact us via our contact form, email, or other means of communication, we process the data provided to us in this context in order to handle the matter communicated; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
COMMUNICATION VIA MESSENGER
We use messenger services for communication purposes and therefore ask you to note the following information regarding the functionality of the messenger services, encryption, the use of communication metadata, and your options for objection.
You can also contact us via alternative means, e.g., by telephone or email. Please use the contact options provided to you or those listed within our online offering.
In the case of end-to-end encryption of content (i.e., the content of your message and attachments), we note that communication content (i.e., the content of the message and attached images) is encrypted end-to-end. This means that the content of the messages cannot be viewed, not even by the messenger providers themselves. You should always use an up-to-date version of the messenger service with encryption enabled to ensure that the content of messages is encrypted.
However, we would also like to point out to our communication partners that although the messenger providers do not view the content, they can find out that and when communication partners are communicating with us, as well as technical information about the device used by the communication partners and, depending on the settings of their device, location information (so-called metadata).
Notes on legal bases: If we ask communication partners for permission before communicating with them via messenger, the legal basis for our processing of their data is their consent. Otherwise, if we do not ask for consent and they contact us on their own initiative, for example, we use messenger services in relation to our contractual partners and as part of contract initiation as a contractual measure, and in the case of other interested parties and communication partners, on the basis of our legitimate interests in fast and efficient communication and meeting the needs of our communication partners for communication via messenger. We further note that we do not initially transmit the contact data provided to us to the messenger services without your consent.
Withdrawal, objection, and deletion: You can withdraw consent given at any time and... [this section requires a premium license to unlock on the source page].
Types of data processed: Contact data (e.g., email, phone numbers); usage data (e.g., websites visited, interest in content — this text area requires a premium license to unlock); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers — this text area requires a premium license to unlock).
-
Data subjects: Communication partners.
-
Purposes of processing: Contact inquiries and communication; direct marketing (e.g., by email or post).
-
Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
NEWSLETTER AND ELECTRONIC NOTIFICATIONS
We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") only with the consent of the recipients or a legal permission. If the content of the newsletter is specifically described as part of a newsletter registration, it is authoritative for users' consent. Otherwise, our newsletters contain information about our services and us.
To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for personal address in the newsletter, or other information, if this is necessary for the purposes of the newsletter.
Double opt-in procedure: Registration for our newsletter generally takes place using a so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to ensure that no one can register using someone else's email address. Newsletter registrations are logged to prove the registration process in accordance with legal requirements. This includes storing the registration and confirmation times, as well as the IP address. Changes to your data stored with the mailing service provider are also logged.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove previously given consent. Processing of this data is limited to the purpose of possible defense against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist.
Logging of the registration process is based on our legitimate interests for the purpose of proving its proper execution. If we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.
Content: Information about us, our services, promotions, and offers.
-
Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email, phone numbers); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); usage data (e.g., websites visited, interest in content, access times).
-
Data subjects: Communication partners.
-
Purposes of processing: Direct marketing (e.g., by email or post).
-
Legal bases: Consent (Art. 6(1)(a) GDPR).
-
Right to object (opt-out): You can cancel receipt of our newsletter at any time, i.e., withdraw your consent or object to further receipt. You will find a link to cancel the newsletter at the end of each newsletter, or you can use one of the contact options listed above, preferably email.
Further information on processing, procedures, and services:
Measurement of open and click rates: The newsletters contain a so-called "web beacon," i.e., a pixel-sized file that is retrieved from our server, or, if we use a mailing service provider, from their server, when the newsletter is opened. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, is initially collected.
This information is used to technically improve our newsletter based on technical data or on target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. This information is assigned to individual newsletter recipients and stored in their profiles until they are deleted. These evaluations help us identify our users' reading habits and adapt our content to them, or send different content according to our users' interests.
The measurement of open and click rates and the storage of measurement results in user profiles — this text area requires a premium license to unlock; legal bases: Consent (Art. 6(1)(a) GDPR).
SWEEPSTAKES AND COMPETITIONS
We process personal data of participants in sweepstakes and competitions only in compliance with the relevant data protection regulations, insofar as processing is contractually necessary for the provision, execution, and processing of the sweepstakes, participants have consented to the processing, or the processing serves our legitimate interests (e.g., in the security of the sweepstakes or the protection of our interests from misuse through possible collection of IP addresses when submitting entries).
If entries from participants are published as part of the sweepstakes (e.g., as part of a vote or presentation of entries or winners, or reporting on the sweepstakes), we point out that participants' names may also be published in this context. Participants can object to this at any time.
If the sweepstakes takes place within an online platform or social network (e.g., Facebook or Instagram, hereinafter referred to as "online platform"), the terms of use and privacy policies of the respective platforms also apply. In these cases, we point out that we are responsible for the information provided by participants as part of the sweepstakes, and inquiries regarding the sweepstakes should be directed to us.
Participants' data will be deleted once the sweepstakes or competition has ended and the data is no longer required to inform winners, or because further inquiries about the sweepstakes are no longer expected. As a general rule, participants' data will be deleted no later than 6 months after the end of the sweepstakes. Winners' data may be retained longer, e.g., to answer questions about prizes or to fulfill the prize obligations; in this case, the retention period depends on the type of prize and can be up to three years for goods or services, e.g., to handle warranty claims. Furthermore, participants' data may be stored longer, e.g., in the form of reporting on the sweepstakes in online and offline media.
If data was collected as part of the sweepstakes for other purposes, its processing and retention period are governed by the privacy notices for this use (e.g., in the case of newsletter registration as part of a sweepstakes).
-
Types of data processed: Inventory data (e.g., names, addresses); content data (e.g., entries in online forms); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Sweepstakes and competition participants.
-
Purposes of processing: Conducting sweepstakes and competitions.
-
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
SURVEYS AND QUESTIONNAIRES
We conduct surveys and questionnaires to collect information for the respectively communicated survey purpose. The surveys and questionnaires we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is only processed to the extent necessary for the provision and technical execution of the surveys (e.g., processing the IP address to display the survey in the user's browser, or enabling the survey to be resumed using a cookie).
-
Types of data processed: Contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Communication partners. Participants.
-
Purposes of processing: Feedback (e.g., collecting feedback via online forms).
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing, procedures, and services:
-
Google Forms: Creation and evaluation of online forms, surveys, feedback forms, etc.; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: Legitimate interests (Art. 6(1)(f) GDPR); website: https://www.google.com/forms/about/; privacy policy: https://policies.google.com/privacy; data processing agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfers: Data Privacy Framework (DPF).
WEB ANALYTICS, MONITORING, AND OPTIMIZATION
Web analytics (also referred to as "reach measurement") serves to evaluate visitor flows on our online offering and may include behavioral, interest-based, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify at what time our online offering, or its functions or content, is most frequently used or invites reuse. We can also determine which areas require optimization.
In addition to web analytics, we may also use testing procedures, e.g., to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e., data combined for a usage process, may be created for these purposes, and information may be stored in and retrieved from a browser or end device. The data collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used, and information about usage times. If users have consented to the collection of their location data with respect to us or to the providers of the services we use, location data may also be processed.
Users' IP addresses are also stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. In general, no identifiable user data (such as email addresses or names) is stored as part of web analytics, A/B testing, and optimization, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
-
Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Reach measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); provision of our online offering and user-friendliness.
-
Security measures: IP masking (pseudonymization of the IP address).
-
Legal bases: Consent (Art. 6(1)(a) GDPR).
Further information on processing, procedures, and services:
Google Analytics: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to assign analysis information to an end device in order to identify which content users have accessed within one or more usage processes, which search terms they used, whether they accessed content again, or how they interacted with our online offering. The time and duration of use, as well as the sources of users referring to our online offering and technical aspects of their end devices and browsers, are also stored. Pseudonymous user profiles are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible, and is not used for further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: Consent (Art. 6(1)(a) GDPR); website:
https://marketingplatform.google.com/about/analytics/; security measures: IP masking (pseudonymization of the IP address); privacy policy: https://policies.google.com/privacy; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for third-country transfers: Data Privacy Framework (DPF); right to object (opt-out): opt-out plugin: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed).
ONLINE MARKETING
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on users' potential interests, as well as measuring its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (a so-called "cookie"), or similar procedures are used by which information relevant to the display of the aforementioned content is stored about the user. This information may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information, such as the browser used, the computer system used, and information about usage times and functions used. If users have consented to the collection of their location data, this may also be processed.
Users' IP addresses are also stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect users. In general, no identifiable user data (such as email addresses or names) is stored as part of the online marketing process, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is generally stored in cookies or by means of similar procedures. These cookies can later generally also be read on other websites that use the same online marketing procedure, and analyzed for the purpose of displaying content, as well as supplemented with additional data and stored on the server of the online marketing procedure provider.
In exceptional cases, identifiable data may be assigned to the profiles. This is the case, for example, if the users are members of a social network whose online marketing procedures we use, and the network links the user profiles with the aforementioned information. Please note that users may enter into additional agreements with providers, for example through consent given during registration.
We generally only have access to aggregated information about the success of our advertisements. However, as part of so-called conversion measurement, we can check which of our online marketing procedures led to a so-called conversion, i.e., for example, to a contract being concluded with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless otherwise stated, please assume that cookies used are stored for a period of two years.
-
Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Reach measurement (e.g., access statistics, recognition of returning visitors); tracking (e.g., interest-/behavior-based profiling, use of cookies); marketing; profiles with user-related information (creating user profiles).
-
Security measures: IP masking (pseudonymization of the IP address).
-
Right to object (opt-out): We refer to the privacy notices of the respective providers and the objection options (so-called "opt-out") listed for the providers. If no explicit opt-out option is provided, you can disable cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, offered collectively for the respective regions: a) Europe: https://www.youronlinechoices.eu b) Canada: https://www.youradchoices.ca/choices c) USA: https://www.aboutads.info/choices d) Cross-region: https://optout.aboutads.info
CUSTOMER REVIEWS AND RATING PROCEDURES
We participate in review and rating procedures to evaluate, optimize, and promote our services. If users rate us or otherwise provide feedback via the participating review platforms or procedures, the general terms and conditions of use and privacy notices of the providers also apply. As a rule, rating also requires registration with the respective providers.
To ensure that reviewers have actually used our services, with the customer's consent we transmit the necessary data regarding the customer and the service used to the respective review platform (including name, email address, and order or item number). This data is used solely to verify the authenticity of the user.
-
Types of data processed: Contract data (e.g., contract subject matter, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Customers; users (e.g., website visitors, users of online services).
-
Purposes of processing: Feedback (e.g., collecting feedback via online forms); marketing.
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
PRESENCE ON SOCIAL NETWORKS (SOCIAL MEDIA)
We maintain online presences within social networks and, in this context, process users' data in order to communicate with users active there or to provide information about us.
We note that users' data may be processed outside the European Union in this context. This may pose risks for users, as it may, for example, make it more difficult to enforce users' rights.
Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on usage behavior and resulting user interests. These usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to users' interests. For these purposes, cookies are generally stored on users' computers, in which usage behavior and users' interests are stored. Furthermore, data may also be stored in the usage profiles independently of the devices used by the users (particularly if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Even in the case of requests for information and the exercise of data subject rights, we point out that these can be exercised most effectively with the providers. Only the providers have access to users' data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you can contact us.
-
Types of data processed: Contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Contact inquiries and communication; feedback (e.g., collecting feedback via online forms); marketing.
-
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing, procedures, and services:
Instagram: Social network; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Legitimate interests (Art. 6(1)(f) GDPR); website: https://www.instagram.com/; privacy policy: https://instagram.com/about/legal/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
LinkedIn: Social network; service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; legal bases: Legitimate interests (Art. 6(1)(f) GDPR); website: https://www.linkedin.com/; privacy policy: https://www.linkedin.com/legal/privacy-policy; basis for third-country transfers: Data Privacy Framework (DPF); right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out; further information: We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of visitor data used to create "Page Insights" (statistics) for our LinkedIn profiles.
This data includes information about the types of content users view or interact with, or the actions they take, as well as information about the devices used by users (e.g., IP addresses, operating system, browser type, language settings, cookie data) and information from users' profiles, such as job function, country, industry, hierarchy level, company size, and employment status. Privacy information regarding LinkedIn's processing of user data can be found in LinkedIn's privacy notices: https://www.linkedin.com/legal/privacy-policy
We have entered into a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum," https://legal.linkedin.com/pages-joint-controller-addendum), which regulates, among other things, the security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill data subject rights (i.e., users can, for example, direct requests for information or deletion directly to LinkedIn). Users' rights (in particular the right to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection of data by and transmission to Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of Ireland Unlimited Company, particularly with regard to the transmission of data to the parent company LinkedIn Corporation in the USA.
Facebook: Social network; when you visit our Facebook page, Facebook collects, among other things, your IP address and other information stored on your computer in the form of cookies. This information is used to provide us, as the operator of the Facebook page, with statistical information about the use of the Facebook page. Facebook provides more detailed information about this at the following link: https://www.facebook.com/help/pages/insights. Using the statistical information transmitted, we are unable to draw conclusions about individual users. We only use this information to respond to our users' interests and to continuously improve our online presence and ensure its quality. We collect your data via our fan page only to enable possible communication and interaction with us. This collection generally includes your name, message content, comment content, and profile information you have made "publicly" available. The processing of your personal data for the purposes stated above is based on our legitimate business and communication interest in offering an information and communication channel pursuant to Art. 6(1)(f) GDPR. Should you, as a user, have given consent to data processing to the respective provider of the social network, the legal basis for processing extends to Art. 6(1)(a), Art. 7 GDPR. Due to the fact that the actual data processing is carried out by the provider of the social network, our access to your data is limited. Only the provider of the social network is authorized to have full access to your data. As a result, only the provider can directly take appropriate measures to fulfill your user rights (requests for information, deletion, objection, etc.). Exercising the relevant rights is therefore most effective directly with the respective provider. We are jointly responsible with Facebook for the personal content of the fan page. Data subject rights can be exercised with Facebook Ireland as well as with us. Primary responsibility for processing Insights data lies with Facebook under the GDPR, and Facebook fulfills all obligations under the GDPR with regard to the processing of Insights data; Facebook Ireland provides the essential elements of the Page Insights addendum to data subjects. We do not make decisions regarding the processing of Insights data or any further information arising from Art. 13 GDPR, including the legal basis, the identity of the controller, and the storage period of cookies on user devices. Further information can be found directly at Facebook (supplementary agreement with Facebook): https://www.facebook.com/legal/terms/page_controller_addendum
PLUGINS AND EMBEDDED FUNCTIONS AND CONTENT
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos, or maps (hereinafter collectively referred to as "content").
Integration always requires that the third-party providers of this content process the users' IP address, as they could not send the content to their browser without the IP address. The IP address is therefore necessary for the display of this content or functions. We strive to use only content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, visit time, and other information about the use of our online offering, as well as being combined with such information from other sources.
-
Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); event data (Facebook) ("event data" is data that may be transmitted by us to Facebook, e.g., via the Facebook pixel (via apps or other means), and relates to persons or their actions; this data includes, for example, information about website visits, interactions with content, functions, app installations, product purchases, etc.; event data is processed for the purpose of forming target groups for content and advertising information (custom audiences); event data does not include the actual content (such as comments written), no login information, and no contact information (i.e., no names, email addresses, or phone numbers). Event data is deleted by Facebook after a maximum of two years; the target groups formed from it are deleted when our Facebook account is deleted).
-
Data subjects: Users (e.g., website visitors, users of online services).
-
Purposes of processing: Provision of our online offering and user-friendliness; marketing; profiles with user-related information (creating user profiles).
-
Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing, procedures, and services:
Facebook plugins and content: Facebook social plugins and content – this may include, for example, content such as images, videos, or text, and buttons that allow users to share content from this online offering within Facebook. The list and appearance of Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/. We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt, as part of a transmission (but not the further processing), of "event data" that Facebook collects using the Facebook social plugins (and content embedding functions) implemented on our online offering, or receives as part of a transmission for the following purposes: a) displaying content and advertising information that corresponds to users' presumed interests; b) delivering commercial and transaction-related messages (e.g., contacting users via Facebook Messenger); c) improving ad delivery and personalizing functions and content (e.g., improving the detection of which content or advertising information presumably corresponds to users' interests). We have entered into a special agreement with Facebook ("Controller Addendum," https://www.facebook.com/legal/controller_addendum), which regulates, among other things, the security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfill data subject rights (i.e., users can, for example, direct requests for information or deletion directly to Facebook). Note: If Facebook provides us with metrics, analyses, and reports (which are aggregated, i.e., contain no information about individual users and are anonymous to us), this processing does not take place within the framework of joint responsibility, but rather on the basis of a data processing agreement ("Data Processing Terms," https://www.facebook.com/legal/terms/dataprocessing), the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms), and, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum," https://www.facebook.com/legal/EU_data_transfer_addendum). Users' rights (in particular the right to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Consent (Art. 6(1)(a) GDPR); website: https://www.facebook.com/; privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
Font Awesome (hosted on our own server): Display of fonts and icons; service provider: The Font Awesome icons are hosted on our own server; no data is transmitted to the Font Awesome provider; legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Instagram plugins and content: Instagram plugins and content – this may include, for example, content such as images, videos, or text, and buttons that allow users to share content from this online offering within Instagram. We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt, as part of a transmission (but not the further processing), of "event data" that Facebook collects using Instagram functions (e.g., content embedding functions) implemented on our online offering, or receives as part of a transmission for the following purposes: a) displaying content and advertising information that corresponds to users' presumed interests; b) delivering commercial and transaction-related messages (e.g., contacting users via Facebook Messenger); c) improving ad delivery and personalizing functions and content (e.g., improving the detection of which content or advertising information presumably corresponds to users' interests). We have entered into a special agreement with Facebook ("Controller Addendum," https://www.facebook.com/legal/controller_addendum), which regulates, among other things, the security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfill data subject rights (i.e., users can, for example, direct requests for information or deletion directly to Facebook). Note: If Facebook provides us with metrics, analyses, and reports (which are aggregated, i.e., contain no information about individual users and are anonymous to us), this processing does not take place within the framework of joint responsibility, but rather on the basis of a data processing agreement ("Data Processing Terms," https://www.facebook.com/legal/terms/dataprocessing), the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms), and, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum," https://www.facebook.com/legal/EU_data_transfer_addendum). Users' rights (in particular the right to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Legitimate interests (Art. 6(1)(f) GDPR); website: https://www.instagram.com/. Privacy policy: https://instagram.com/about/legal/privacy/.
