logo

/

Impressum

OSM Handel- und Service GmbH

Nestelbach 184/08

A-8262 Ilz

Austria

Tel: +43 (0) 664 2413041

UIDNr.: ATU83482848

Email: gebranntesholz.at@gmail.com

Privacy Policy

Last Updated: 27 August 2022

Introduction

With the following Privacy Policy, we would like to inform you about the types of personal data relating to you (hereinafter also referred to simply as “data”) that we process, the purposes for which we process such data, and the extent of such processing.

This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and on external online platforms, such as our social media profiles (hereinafter collectively referred to as the “Online Offering”).

The terms used are not gender-specific.

Last updated: 27 August 2022

Controller

OSM Handel- und Service GmbH

Nestelbach 184/08, A-8262 Ilz, Austria

Tel.: +43 (0) 664 2413041

VAT ID No.: ATU83482848

Email: gebranntesholz.at@gmail.com

Overview of Processing Activities

The following overview summarises the types of data processed, the purposes for which they are processed, and the categories of data subjects concerned.

Types of Data Processed

  • Master data
  • Payment data
  • Contact details
  • Content data
  • Contract data
  • Usage data
  • Meta and communication data
  • Event data (Facebook)

Categories of Data Subjects

  • Customers
  • Prospective customers
  • Communication partners
  • Users
  • Business and contractual partners

Purposes of Processing

  • Provision of contractual services and customer support
  • Responding to contact requests and communication
  • Security measures
  • Direct marketing
  • Audience measurement
  • Tracking
  • Office and organisational procedures
  • Conversion measurement
  • Management of and response to enquiries
  • Feedback
  • Marketing
  • Profiles containing user-related information
  • Registration procedures
  • Provision of our Online Offering and user-friendliness
  • Information technology infrastructure

Security Measures

In accordance with legal requirements and taking into account the state of the art, implementation costs, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access, entry, disclosure and transmission relating to such data, ensuring its availability and maintaining data separation. Furthermore, we have established procedures to ensure that data subjects can exercise their rights, that data is deleted, and that appropriate responses are made in the event of a threat to data security.

We also take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and data protection by default.

SSL encryption (HTTPS): To protect the data you transmit through our Online Offering, we use SSL encryption. You can identify encrypted connections of this kind by the prefix https:// in your browser’s address bar.

Transfer of Personal Data

As part of our processing of personal data, data may be transferred or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of such data may include, for example, service providers commissioned to perform IT tasks or providers of services and content integrated into a website.

In such cases, we comply with the applicable legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data to ensure its protection.

Data Processing in Third Countries

If we process data in a third country—that is, outside the European Union (EU) or the European Economic Area (EEA)—or if such processing takes place through the use of third-party services or through the disclosure or transfer of data to other persons, bodies or companies, this will be carried out only in accordance with the applicable legal requirements.

Subject to explicit consent or a transfer required by contract or law, we process data, or have it processed, only in third countries with a recognised level of data protection or on the basis of contractual obligations established through the European Commission’s Standard Contractual Clauses, recognised certifications or binding corporate rules (Articles 44–49 GDPR; European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).

Deletion of Data

The data processed by us will be deleted in accordance with legal requirements as soon as the consent permitting its processing is withdrawn or another legal basis ceases to apply—for example, when the purpose for which the data was processed no longer exists or the data is no longer required for that purpose.

If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to those purposes. This means that the data will be blocked and will not be processed for any other purposes.

This applies, for example, to data that must be retained for commercial or tax-law reasons, or where storage is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.

Our Privacy Policy may also contain additional information concerning the retention and deletion of data that applies primarily to the respective processing activities.

Use of Cookies

Cookies are small text files or other storage records that store information on end devices and retrieve information from them. For example, they may be used to store the login status of a user account, the contents of a shopping cart in an online shop, the content accessed, or the functions used within an Online Offering. Cookies may also be used for various purposes, including ensuring the functionality, security and convenience of Online Offerings and analysing visitor traffic.

Information on consent: We use cookies in accordance with the applicable legal requirements. We therefore obtain users’ prior consent unless such consent is not required by law. In particular, consent is not required where storing and retrieving information, including through cookies, is strictly necessary to provide users with a telemedia service expressly requested by them, namely our Online Offering. Users are clearly informed about the revocable nature of their consent, including details about the respective use of cookies.

Information on the legal bases under data protection law: The legal basis on which we process users’ personal data with the help of cookies depends on whether we request their consent. If users give their consent, the legal basis for processing their data is that consent. Otherwise, data processed with the help of cookies is processed on the basis of our legitimate interests, for example, in the efficient operation of our Online Offering and the improvement of its usability. Where cookies are used in connection with the performance of our contractual obligations, processing is based on the necessity of using cookies to fulfil those obligations. We provide information about the purposes for which cookies are processed in this Privacy Policy or as part of our consent and processing procedures.

Retention period: With regard to the retention period, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves an Online Offering and closes their device, for example, the browser or mobile application.
  • Persistent cookies: Persistent cookies remain stored even after the device has been closed. For example, they may store the user’s login status or display preferred content immediately when the user revisits a website. Data collected with the help of cookies may also be used for audience measurement. Unless we provide users with explicit information about the type and retention period of cookies, for example, when obtaining consent, users should assume that cookies are persistent and may be stored for up to two years.

General information on withdrawal of consent and objection (opt-out): Users may withdraw their consent at any time and may also object to processing in accordance with the legal requirements set out in Article 21 GDPR. Users may also object through their browser settings, for example, by disabling the use of cookies. However, doing so may restrict the functionality of our online services. Users may also object to the use of cookies for online marketing purposes via the following websites:

Further Information on Processing Activities, Procedures and Services

Processing of cookie data on the basis of consent: We use a cookie consent management procedure through which users’ consent to the use of cookies and to the processing activities and providers specified within that procedure is obtained, managed and withdrawn.

The consent declaration is stored so that users do not need to be asked for their consent repeatedly and so that we can provide evidence of consent in accordance with our legal obligations. Consent may be stored on the server and/or in a cookie, known as an opt-in cookie, or with the help of comparable technologies, allowing the consent to be assigned to a particular user or their device.

Unless individual information concerning the providers of cookie management services states otherwise, the following applies: consent may be stored for up to two years. A pseudonymous user identifier is created and stored together with the date and time of consent, information regarding the scope of the consent—for example, the selected categories of cookies and/or service providers—as well as information about the browser, operating system and device used.

Business Services

We process data relating to our contractual and business partners, such as customers and prospective customers (collectively referred to as “Contractual Partners”), within the scope of contractual and comparable legal relationships, related measures, and communication with Contractual Partners, including at the pre-contractual stage, for example, in order to respond to enquiries.

We process this data in order to fulfil our contractual obligations. These include, in particular, the obligation to provide the agreed services, any obligations to provide updates, and remedies in the event of warranty claims or other deficiencies in performance.

We also process data to safeguard our rights and for administrative tasks and business organisation associated with these obligations. Furthermore, we process data on the basis of our legitimate interests in proper and commercially efficient business management and in security measures intended to protect our Contractual Partners and our business operations against misuse and against risks to their data, confidential information, other information and rights. This may include the involvement of telecommunications providers, transport providers and other auxiliary services, subcontractors, banks, tax and legal advisers, payment service providers or financial authorities.

Within the limits of applicable law, we disclose Contractual Partners’ data to third parties only to the extent necessary for the aforementioned purposes or to comply with legal obligations. Contractual Partners are informed about other forms of processing, such as processing for marketing purposes, in this Privacy Policy.

We inform Contractual Partners which data is required for the aforementioned purposes before or during its collection—for example, through special markings such as colours or symbols such as asterisks in online forms, or by providing this information personally.

We delete the data once statutory warranty and comparable obligations have expired, generally after four years, unless the data is stored in a customer account or must be retained for statutory archiving purposes.

The statutory retention period is ten years for tax-relevant documents, commercial books, inventories, opening balance sheets, annual financial statements, operating instructions and other organisational documents required to understand such records, and accounting documents. The statutory retention period for received commercial and business correspondence and copies of sent commercial and business correspondence is six years.

The retention period begins at the end of the calendar year in which the last entry was made in the books, the inventory, opening balance sheet, annual financial statements or management report was prepared, the commercial or business correspondence was received or sent, the accounting document was created, the record was made, or the other documents were produced.

Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply to the relationship between users and those providers.

Types of data processed: Master data (e.g. names and addresses); payment data (e.g. bank details, invoices and payment history); contact details (e.g. email addresses and telephone numbers); contract data (e.g. subject matter of the contract, contract term and customer category); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Customers; prospective customers; business and contractual partners.

Purposes of processing: Provision of contractual services and customer support; security measures; responding to contact requests and communication; office and organisational procedures; management of and response to enquiries.

Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legal obligation (Art. 6(1), first sentence, point (c) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Customer account

Contractual Partners may create an account within our Online Offering, for example, a customer or user account (hereinafter referred to as a “Customer Account”). If registration for a Customer Account is required, Contractual Partners will be informed accordingly and advised which information is required for registration.

Customer Accounts are not publicly accessible and cannot be indexed by search engines. During registration and subsequent logins and use of the Customer Account, we store customers’ IP addresses together with the relevant access times in order to provide evidence of registration and prevent possible misuse of the Customer Account.

When customers terminate their Customer Account, the data associated with that account will be deleted unless its retention is required by law. Customers are responsible for securing their data after terminating their Customer Account.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

Payment Methods

In connection with contractual and other legal relationships, on the basis of statutory obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options. For this purpose, we use banks, credit institutions and other service providers (collectively referred to as “Payment Service Providers”).

The data processed by Payment Service Providers includes master data, such as names and addresses; bank details, such as account numbers or credit card numbers; passwords, TANs and verification codes; as well as information relating to contracts, amounts and recipients. This information is required to process transactions.

However, the data entered is processed and stored exclusively by the Payment Service Providers. This means that we do not receive any bank account or credit card information, but only confirmation of the payment or notification that the payment was unsuccessful.

Under certain circumstances, Payment Service Providers may transmit data to credit reference agencies for the purpose of identity and creditworthiness checks. For further information, please refer to the terms and conditions and privacy policies of the respective Payment Service Providers.

Payment transactions are subject to the terms and conditions and privacy policies of the respective Payment Service Providers, which are available on their websites or within their transaction applications. We also refer you to these documents for further information and for the exercise of rights relating to withdrawal, access and other data subject rights.

Types of data processed: Master data (e.g. names and addresses); payment data (e.g. bank details, invoices and payment history); contract data (e.g. subject matter of the contract, contract term and customer category); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Customers; prospective customers.

Purposes of processing: Provision of contractual services and customer support.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

Further Information on Processing Activities, Procedures and Services

PayPal

Payment services and technical integration of online payment methods, such as PayPal, PayPal Plus and Braintree.

Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

Website: https://www.paypal.com/

Privacy Policy: https://www.paypal.com/webapps/mpp/ua/privacy-full

Stripe

Payment services and technical integration of online payment methods.

Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

Website: https://stripe.com

Privacy Policy: https://stripe.com/privacy

Provision of the Online Offering and Web Hosting

We process users’ data in order to provide them with our online services. For this purpose, we process users’ IP addresses, as these are necessary to transmit the content and functions of our online services to users’ browsers or end devices.

Types of data processed: Usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Provision of our Online Offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment, such as computers and servers); security measures.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Provision of the Online Offering using rented hosting space

To provide our Online Offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider, also referred to as a web hosting provider.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Collection of access data and log files

Access to our Online Offering is recorded in the form of so-called server log files. Server log files may include the address and name of the websites and files accessed, the date and time of access, the amount of data transferred, notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, the user’s IP address and requesting internet service provider.

Server log files may be used for security purposes, for example, to prevent server overload, particularly in the event of abusive attacks known as DDoS attacks. They may also be used to monitor server capacity and ensure server stability.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Deletion of data

Log file information is stored for a maximum period of 30 days and is subsequently deleted or anonymised. Data that must be retained for evidentiary purposes is excluded from deletion until the relevant incident has been conclusively resolved.

Registration, Login and User Account

Users may create a user account. During registration, users are informed of the mandatory information required. This information is processed for the purpose of providing the user account on the basis of the performance of contractual obligations. The data processed includes, in particular, login information such as the username, password and email address.

When users make use of our registration and login functions or use their user account, we store their IP address and the time of the respective user activity. This storage is based on our legitimate interests, as well as those of users, in protection against misuse and other unauthorised use.

As a general rule, this data is not disclosed to third parties unless this is necessary for the enforcement of our claims or we are legally obliged to do so.

Users may be informed by email about matters relevant to their user account, such as technical changes.

Types of data processed: Master data (e.g. names and addresses); contact details (e.g. email addresses and telephone numbers); content data (e.g. information entered in online forms); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Provision of contractual services and customer support; security measures; management of and response to enquiries; provision of our Online Offering and user-friendliness.

Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Deletion of data following account termination

When users terminate their user account, the data relating to that account will be deleted, subject to any statutory permission or obligation or the users’ consent.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

No obligation to retain data

Users are responsible for securing their data before the end of the contractual relationship following account termination. We are entitled to permanently delete all user data stored during the term of the contract.

Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).

Single Sign-On

“Single Sign-On”, “Single Sign-On login” or “Single Sign-On authentication” refers to procedures that allow users to log in to our Online Offering using a user account held with a Single Sign-On provider, such as a social network.

To use Single Sign-On authentication, users must be registered with the respective Single Sign-On provider and enter the required login details in the relevant online form, or already be logged in with that provider and confirm the Single Sign-On login by clicking the relevant button.

Authentication takes place directly with the respective Single Sign-On provider. As part of this authentication process, we receive a user ID confirming that the user is logged in with the respective provider under that ID, as well as an identifier that cannot be used by us for any other purpose, known as a “User Handle”.

Whether additional data is transmitted to us depends entirely on the Single Sign-On procedure used, the data-sharing choices made during authentication, and the data users have made available in the privacy or other settings of their account with the Single Sign-On provider.

The data transmitted may vary depending on the provider and the user’s choices, but generally includes the email address and username. We can neither view nor store the password entered with the Single Sign-On provider during this procedure.

Users should note that the information stored by us may be automatically synchronised with their user account held with the Single Sign-On provider. However, this is not always possible and may not actually occur. For example, if users change their email address, they may need to update it manually in their user account with us.

Where agreed with users, we may use Single Sign-On as part of or prior to the performance of a contract. Where users have been asked for their consent, the data is processed on the basis of that consent. Otherwise, Single Sign-On is used on the basis of our legitimate interests and those of users in an efficient and secure login system.

If users decide that they no longer wish to use the connection to their account with the Single Sign-On provider for Single Sign-On purposes, they must remove this connection in their account settings with that provider. If users wish to have their data deleted by us, they must terminate their registration with us.

Types of data processed: Master data (e.g. names and addresses); contact details (e.g. email addresses and telephone numbers); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses); Facebook Event Data. “Event Data” refers to data that may be transmitted by us to Facebook, for example through the Facebook Pixel, apps or other methods, and that relates to individuals or their actions. Such data may include information about website visits, interactions with content and functions, app installations and product purchases. Event Data is processed for the purpose of creating target groups for content and advertising information, known as Custom Audiences. Event Data does not include the actual content, such as comments written by users, login information or contact details such as names, email addresses or telephone numbers. Facebook deletes Event Data after a maximum of two years. Target groups created from this data are deleted when our Facebook account is deleted.

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Provision of contractual services and customer support; security measures; login procedures.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Facebook Single Sign-On

Authentication service provided by the Facebook platform.

Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Website: Facebook

Privacy Policy: Meta Privacy Policy

Data Processing Agreement: Meta Data Processing Terms

Standard Contractual Clauses concerning the level of data protection for processing in third countries: Meta EU Data Transfer Addendum

Google Single Sign-On

Authentication service.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Website: Google

Privacy Policy: Google Privacy Policy

Opt-out and advertising settings: Google Ads Settings

Blogs and Publication Media

We use blogs or comparable means of online communication and publication (hereinafter referred to as “Publication Media”). Readers’ data is processed for the purposes of the Publication Media only to the extent necessary for presenting the content, facilitating communication between authors and readers, or ensuring security. For all other matters, please refer to the information in this Privacy Policy concerning the processing of visitors’ data in connection with our Publication Media.

Types of data processed: Master data (e.g. names and addresses); contact details (e.g. email addresses and telephone numbers); content data (e.g. information entered in online forms); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Provision of contractual services and customer support; feedback (e.g. collecting feedback via online forms); provision of our Online Offering and user-friendliness.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Contact and Enquiry Management

When individuals contact us—for example, through a contact form, by email, telephone or social media—and in the context of existing user and business relationships, we process the information they provide to the extent necessary to respond to their enquiries and carry out any requested measures.

We respond to enquiries and manage contact and enquiry data within contractual or pre-contractual relationships in order to fulfil our contractual obligations or respond to contractual and pre-contractual enquiries. In all other cases, processing is based on our legitimate interests in responding to enquiries and maintaining user and business relationships.

Types of data processed: Contact details (e.g. email addresses and telephone numbers); content data (e.g. information entered in online forms); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Communication partners.

Purposes of processing: Contact enquiries and communication; management of and response to enquiries; feedback (e.g. collecting feedback via online forms); provision of our Online Offering and user-friendliness; provision of contractual services and customer support.

Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Contact form

When users contact us through our contact form, by email or through other communication channels, we process the data provided in connection with the enquiry in order to deal with the matter communicated to us.

For this purpose, we process personal data within the framework of pre-contractual and contractual business relationships to the extent necessary for their performance. Otherwise, processing is based on our legitimate interests and those of our communication partners in having enquiries answered, as well as on our statutory retention obligations.

Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Newsletters and Electronic Notifications

We send newsletters, emails and other electronic notifications (hereinafter referred to as “Newsletters”) only with the recipients’ consent or where legally permitted. If the content of a Newsletter is specifically described during the registration process, that description determines the scope of the user’s consent. Otherwise, our Newsletters contain information about us and our services.

As a general rule, users only need to provide their email address to subscribe to our Newsletters. However, we may also ask them to provide their name so that we can address them personally in the Newsletter, or to provide further information where this is necessary for the purposes of the Newsletter.

Double opt-in procedure: Registration for our Newsletter generally follows a double opt-in procedure. This means that after registering, users receive an email asking them to confirm their subscription. This confirmation is necessary to prevent anyone from subscribing using another person’s email address.

Newsletter registrations are logged so that we can demonstrate that the registration process complies with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes made to data stored by the email service provider are also logged.

Deletion and restriction of processing: Based on our legitimate interests, we may retain unsubscribed email addresses for up to three years before deleting them in order to demonstrate that valid consent had previously been given. The processing of this data is restricted to the possible defence against legal claims.

Users may request the deletion of their data at any time, provided that the former existence of consent is confirmed at the same time. Where we are required to permanently observe objections, we reserve the right to retain the email address solely for this purpose in a suppression list, also known as a “Blocklist”.

The registration process is logged on the basis of our legitimate interests in demonstrating that it was carried out correctly. Where we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure mailing system.

Types of data processed: Master data (e.g. names and addresses); contact details (e.g. email addresses and telephone numbers); meta and communication data (e.g. device information and IP addresses).

Data subjects: Communication partners.

Purposes of processing: Direct marketing (e.g. by email or post).

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Right to object (opt-out): You may unsubscribe from our Newsletter at any time, withdraw your consent or object to receiving further Newsletters. An unsubscribe link is provided at the end of every Newsletter. Alternatively, you may use one of the contact options stated above, preferably email.

Web Analytics, Monitoring and Optimisation

Web analytics, also referred to as “audience measurement”, is used to evaluate visitor traffic to our Online Offering. It may include pseudonymous information about visitors’ behaviour, interests or demographic characteristics, such as age or gender.

Audience analysis enables us, for example, to identify when our Online Offering, its functions or content are used most frequently or encourage repeat visits. It also allows us to determine which areas require optimisation.

In addition to web analytics, we may use testing procedures to compare and optimise different versions of our Online Offering or its individual components.

Unless otherwise stated below, profiles may be created for these purposes by combining data relating to a particular usage session. Information may also be stored in and retrieved from a browser or end device.

The information collected includes, in particular, websites visited and elements used on those websites, as well as technical information such as the browser and computer system used and access times. Where users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.

Users’ IP addresses are also processed. However, we use IP masking, meaning pseudonymisation by shortening the IP address, in order to protect users.

As a general rule, no directly identifying user data, such as names or email addresses, is stored in connection with web analytics, A/B testing or optimisation. Instead, pseudonyms are used. This means that neither we nor the providers of the software used know the users’ actual identities; we only have access to the information stored in their profiles for the purposes of the respective procedures.

Types of data processed: Usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Audience measurement (e.g. access statistics and identification of returning visitors); profiles containing user-related information (creation of user profiles).

Security measures: IP masking (pseudonymisation of the IP address).

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Further Information on Processing Activities, Procedures and Services

Google Analytics 4

We use Google Analytics to analyse user behaviour on the basis of a pseudonymous user identification number. This identification number does not contain directly identifying data such as names or email addresses.

It is used to associate analytical information with an end device in order to identify which content users access during one or more sessions, which search terms they use, whether they access content again and how they interact with our Online Offering.

The time and duration of use, the sources that refer users to our Online Offering, and technical information concerning their end devices and browsers are also recorded. Pseudonymous user profiles may be created using information collected from different devices, and cookies may be used for this purpose.

Analytics provides general geographic location data by deriving the following metadata from IP-based searches: city, including the city’s derived latitude and longitude; continent; country; region; subcontinent; and the corresponding ID-based information.

To protect user data within the EU, Google receives and processes all user data through domains and servers located within the EU. Users’ IP addresses are not logged and are shortened by default. For users in the EU, this shortening takes place on servers located within the EU. In addition, any sensitive data collected from users in the EU is deleted before it is collected through EU domains and servers.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Website: Google Marketing Platform – Analytics

Privacy Policy: Google Privacy Policy

Data Processing Terms: Google Ads Data Processing Terms

Standard Contractual Clauses: Google Ads Data Processing Terms

Right to object (opt-out): Google Analytics Opt-out Browser Add-on

Advertising settings: Google Ads Settings

Further information: Google Business Data Responsibility

Online Marketing

We process personal data for online marketing purposes. This may include, in particular, the marketing of advertising space and the display of advertising and other content (collectively referred to as “Content”) based on users’ potential interests, as well as measuring the effectiveness of such Content.

For these purposes, user profiles are created and stored in a file known as a “cookie”, or similar technologies are used to store information about users that is relevant to the display of the aforementioned Content.

This information may include, for example, Content viewed, websites visited, online networks used, communication partners and technical information such as the browser and computer system used, access times and functions used. Where users have consented to the collection of their location data, this information may also be processed.

Users’ IP addresses are also processed. However, we use available IP masking procedures, meaning pseudonymisation through the shortening of IP addresses, in order to protect users.

As a general rule, no directly identifying user data, such as email addresses or names, is stored as part of online marketing procedures. Instead, pseudonyms are used. This means that neither we nor the providers of the online marketing procedures know the users’ actual identities; we only have access to the information stored in their profiles.

The information contained in profiles is generally stored in cookies or by means of similar technologies. These cookies may subsequently also be read on other websites that use the same online marketing procedure. The information may be analysed for the purpose of displaying Content, supplemented with additional data and stored on the servers of the online marketing service provider.

In exceptional cases, directly identifying data may be linked to profiles. This may occur, for example, where users are members of a social network whose online marketing procedures we use and the network links users’ profiles with the aforementioned information. Please note that users may enter into additional agreements with the providers, for example by giving their consent during registration.

As a general rule, we only receive aggregated information about the performance of our advertisements. However, as part of so-called conversion measurement, we may determine which of our online marketing procedures resulted in a conversion, such as the conclusion of a contract with us. Conversion measurement is used exclusively to analyse the effectiveness of our marketing activities.

Unless otherwise stated, users should assume that the cookies used are stored for a period of two years.

Types of data processed: Usage data (e.g. websites visited, interest in Content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Audience measurement (e.g. access statistics and identification of returning visitors); tracking (e.g. interest- or behaviour-based profiling and the use of cookies); marketing; profiles containing user-related information (creation of user profiles); conversion measurement (measurement of the effectiveness of marketing activities).

Security measures: IP masking (pseudonymisation of the IP address).

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Right to object (opt-out): Please refer to the privacy policies of the respective providers and the opt-out options specified by them. If no explicit opt-out option is provided, users may disable cookies in their browser settings. However, this may restrict certain functions of our Online Offering. We also recommend the following regional opt-out services:

  • Europe: Your Online Choices
  • Canada: YourAdChoices Canada
  • USA: WebChoices
  • Cross-regional: DAA Opt-Out

Further Information on Processing Activities, Procedures and Services

Google Ads and conversion measurement

We use the “Google Ads” online marketing service to place advertisements within Google’s advertising network, for example in search results, videos and on websites. These advertisements are displayed to users who are presumed to have an interest in them. We also measure the conversion of these advertisements.

We only receive the anonymous total number of users who clicked on our advertisement and were subsequently redirected to a page containing a so-called conversion tracking tag. We do not receive any information that would allow us to identify individual users.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Website: Google Marketing Platform

Privacy Policy: Google Privacy Policy

Further information on processing activities and data processed: Google Ads Privacy Information

Controller-to-controller data protection terms and Standard Contractual Clauses for transfers to third countries: Google Ads Controller Data Protection Terms

Google AdSense with personalised advertisements

We use Google AdSense with personalised advertisements to display advertising within our Online Offering and receive remuneration for displaying or otherwise using such advertising.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Website: Google Marketing Platform

Privacy Policy: Google Privacy Policy

Further information on processing activities and data processed: Google Ads Privacy Information

Data processing terms for Google advertising products, controller-to-controller data protection terms and Standard Contractual Clauses for transfers to third countries: Google Ads Controller Data Protection Terms

Google AdSense with non-personalised advertisements

We use Google AdSense with non-personalised advertisements to display advertising within our Online Offering and receive remuneration for displaying or otherwise using such advertising.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).

Website: Google Marketing Platform

Privacy Policy: Google Privacy Policy

Further information on processing activities and data processed: Google Ads Privacy Information

Google Ads controller-to-controller data protection terms and Standard Contractual Clauses for transfers to third countries: Google Ads Controller Data Protection Terms

Social Media Presence

We maintain online profiles on social networks and process users’ data in this context in order to communicate with users active on those platforms or to provide information about us.

Please note that users’ data may be processed outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, users’ data is generally processed within social networks for market research and advertising purposes. For example, user profiles may be created based on users’ behaviour and the interests derived from it. These profiles may then be used to display advertisements within and outside the respective networks that are presumed to correspond to users’ interests.

For these purposes, cookies are generally stored on users’ devices, recording their usage behaviour and interests. Information may also be stored in user profiles independently of the devices used, particularly where users are members of the respective platforms and are logged in.

For detailed information about the respective forms of processing and available objection and opt-out options, please refer to the privacy policies and information provided by the operators of the respective networks.

With regard to requests for information and the exercise of data subject rights, we would also like to point out that these rights can be exercised most effectively directly with the respective providers. Only the providers have access to users’ data and can take appropriate action and provide information directly. However, if you require assistance, you may contact us.

Types of data processed: Contact details (e.g. email addresses and telephone numbers); content data (e.g. information entered in online forms); usage data (e.g. websites visited, interest in content and access times); meta and communication data (e.g. device information and IP addresses).

Data subjects: Users (e.g. website visitors and users of online services).

Purposes of processing: Contact enquiries and communication; feedback (e.g. collecting feedback via online forms); marketing.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Further Information on Processing Activities, Procedures and Services

Instagram

Social network.

Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Website: Instagram

Privacy Policy: Instagram Privacy Policy

Facebook Pages

Profiles within the Facebook social network.

We are jointly responsible with Meta Platforms Ireland Limited for the collection, but not the subsequent processing, of data relating to visitors to our Facebook Page, also known as a “Fan Page”.

This data includes information about the types of content users view or interact with and the actions they take, as well as information about the devices they use, such as IP addresses, operating system, browser type, language settings and cookie data.

Facebook also collects and uses information to provide Page operators with analytics services known as “Page Insights”. These services allow Page operators to obtain information about how individuals interact with their Pages and associated content.

We have entered into a specific agreement with Facebook concerning Page Insights. This agreement specifies, in particular, the security measures Facebook must observe. Facebook has also agreed to fulfil data subject rights, meaning that users may, for example, submit requests for access to or deletion of their data directly to Facebook.

The agreement with Facebook does not restrict users’ rights, particularly their rights to access, deletion and objection, or their right to lodge a complaint with the competent supervisory authority.

Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Website: Facebook

Privacy Policy: Meta Privacy Policy

Page Insights Controller Addendum: Information about Page Insights

Further information about Page Insights data: Information about Page Insights Data

Standard Contractual Clauses concerning the level of data protection for processing in third countries: Meta EU Data Transfer Addendum

Joint responsibility is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company established within the European Union.

The subsequent processing of the data is the sole responsibility of Meta Platforms Ireland Limited. This particularly includes the transfer of data to its parent company, Meta Platforms, Inc., in the United States, based on the Standard Contractual Clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.

TikTok

Social network and video platform.

Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).

Website: TikTok

Privacy Policy: TikTok Privacy Policy

Amendments and Updates to the Privacy Policy

We ask you to review the content of our Privacy Policy regularly. We will amend this Privacy Policy whenever changes to the data processing activities we carry out make this necessary.

We will inform you if any changes require action on your part, such as renewed consent, or any other form of individual notification.

Where we provide addresses and contact details of companies and organisations in this Privacy Policy, please note that these may change over time. We therefore recommend verifying the relevant details before contacting them.

Rights of Data Subjects

As a data subject, you have various rights under the GDPR, particularly those arising from Articles 15 to 21 GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you where such processing is based on Article 6(1), point (e) or (f) GDPR. This also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of such data for such marketing purposes. This also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed and to receive access to such data, together with further information and a copy of the data, in accordance with the applicable legal requirements.
  • Right to rectification: In accordance with the applicable legal requirements, you have the right to request that incomplete personal data concerning you be completed or that inaccurate personal data concerning you be corrected.
  • Right to erasure and restriction of processing: In accordance with the applicable legal requirements, you have the right to request the immediate deletion of personal data concerning you or, alternatively, to request that the processing of such data be restricted.
  • Right to data portability: You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format. You may also request that this data be transmitted to another controller, in accordance with the applicable legal requirements.
  • Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the place of the alleged infringement, if you believe that the processing of personal data concerning you infringes the GDPR.

Definitions

This section provides an overview of the terminology used in this Privacy Policy. Many of these terms are derived from the law and are defined, in particular, in Article 4 GDPR. The statutory definitions are binding. The following explanations are primarily intended to make the terms easier to understand. The terms are listed in alphabetical order.

  • Conversion measurement: Conversion measurement, also referred to as “conversion tracking”, is a method used to determine the effectiveness of marketing activities. Generally, a cookie is stored on users’ devices on the websites where the marketing activities take place and is subsequently retrieved on the target website. This allows us, for example, to determine whether advertisements placed by us on other websites were successful.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person, hereinafter referred to as the “data subject”. An identifiable natural person is one who can be identified directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier such as a cookie, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
  • Profiles containing user-related information: The processing of “profiles containing user-related information”, or “profiles” for short, includes any form of automated processing of personal data that involves using such data to analyse, evaluate or predict certain personal aspects relating to a natural person. Depending on the type of profiling, this may include information concerning demographics, behaviour and interests, such as interactions with websites and their content, interest in particular content or products, clicking behaviour on a website or location. Cookies and web beacons are frequently used for profiling purposes.
  • Audience measurement: Audience measurement, also referred to as “web analytics”, is used to evaluate visitor traffic to an Online Offering. It may include visitors’ behaviour or interest in certain information, such as website content. Audience analysis enables website operators, for example, to identify when visitors access their websites and which content interests them. This allows them to adapt website content more effectively to visitors’ needs. Pseudonymous cookies and web beacons are frequently used for audience analysis to identify returning visitors and obtain more accurate information about the use of an Online Offering.
  • Tracking: “Tracking” refers to the ability to monitor users’ behaviour across multiple Online Offerings. Information relating to users’ behaviour and interests is generally stored in cookies or on the servers of tracking technology providers, a practice also known as profiling. This information may subsequently be used, for example, to display advertisements that are likely to correspond to users’ interests.
  • Controller: A “controller” is the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data.
  • Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually every form of handling data, including collecting, analysing, storing, transmitting and deleting it.

Created using the free privacy policy generator provided by Datenschutz-Generator.de by Dr Thomas Schwenke.