Privacy Policy
Preamble
With the following privacy policy, we would like to inform you which types of your personal data (hereinafter also referred to simply as «data») we process, for what purposes, and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as «online offering»).
The terms used are not gender-specific.
As of: September 13, 2024
Table of contents
- Preamble
- Controller
- Record of processing activities
- Relevant legal bases
- Security measures
- General information on data storage and deletion
- Data subject rights
- Business Services
- Business Processes and Procedures
- Vendors and Services Used in the Course of Business Operations
- Payment Methods
- Provision of the online service and web hosting
- Registration, Login, and User Account
- Contact and Inquiry Management
- Web Analytics, Monitoring, and Optimization
- Social Media Presence
- Plug-ins, embedded features, and content
- Changes and Updates
- Definitions of Terms
Controller
Sportagon GmbH
Neustadtstrasse 5
CH-8317 Tagelswangen
Email address: info@sportagon.ch
Phone: +41 44 315 15 65
Legal Notice: https://sau.ch/impressum/
Record of processing activities
The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of Data Processed
- Inventory data.
- Employee data.
- Payment information.
- Contact Information.
- Table of Contents.
- Contract information.
- Usage data.
- Meta data, communication data, and procedural data.
- Event details (Facebook).
- Log data.
- Credit information.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Prospective buyers.
- Communication partners.
- Users.
- Business and contractual partners.
- Third parties.
- Customers.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Audience measurement.
- Tracking.
- Office and organizational procedures.
- Conversion measurement.
- Target audience segmentation.
- Organizational and administrative procedures.
- Feedback.
- Marketing.
- Profiles containing user-specific information.
- Provision of our online services and user-friendliness.
- Assessment of creditworthiness and credit rating.
- IT infrastructure.
- Financial and Payment Management.
- Public Relations.
- Sales promotion.
- Business processes and management practices.
Relevant legal bases
Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data in accordance with the Federal Act on Data Protection (the „Swiss DPA» for short). Unlike the GDPR, for example, the Swiss Data Protection Act does not generally require that a legal basis for the processing of personal data be specified, and it stipulates that the processing of personal data must be carried out in good faith, lawfully, and proportionately (Art. 6, paras. 1 and 2 of the Swiss Data Protection Act). Furthermore, we collect personal data only for a specific purpose that is apparent to the data subject and process it only in a manner consistent with that purpose (Art. 6, para. 3 of the Swiss Data Protection Act).
Security measures
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with statutory requirements.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining data segregation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development and selection of hardware, software, and procedures, in accordance with the principle of data protection through technical design and privacy-friendly default settings.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and.
General information on data storage and deletion
We delete the personal data we process in accordance with legal requirements as soon as the underlying consents are revoked or there is no longer a legal basis for processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply when legal obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law purposes, or whose storage is necessary for the enforcement of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information regarding the retention and deletion of data that applies specifically to certain processing operations.
If there are multiple specifications regarding the retention period or deletion deadlines for a given date, the longest period shall always apply.
If a period does not expressly begin on a specific date and is at least one year in duration, it automatically begins at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the time limit is the date on which the termination or other termination of the legal relationship takes effect.
We process data that is no longer retained for its originally intended purpose—but rather due to legal requirements or other reasons—exclusively for the purposes that justify its retention.
Additional information on processing procedures, methods, and services:
- Data Retention and Deletion: The following general deadlines apply to retention and archiving under Swiss law:
- 10 years – retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers and invoices, as well as all required work instructions and other organizational documents (Art. 958f of the Swiss Code of Obligations (CO)).
- 10 years – Data that is necessary for the consideration of potential claims for damages or similar contractual claims.
Data subject rights
Data subject rights under the Swiss FADP:
As a data subject, you have the following rights in accordance with the provisions of the Swiss FADP:
- Right to Information: You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive the information necessary to enable you to exercise your rights under this law and to ensure transparent data processing.
- Right to Data Disclosure or Transfer: You have the right to request the release of your personal data that you have provided to us in a standard electronic format.
- Right to Correction: You have the right to obtain the rectification of inaccurate personal data concerning you.
- Right to object, erasure, and destruction: You have the right to object to the processing of your data and to request that your personal data be deleted or destroyed.
Business Services
We process data from our contractual and business partners, such as customers and prospective customers (collectively referred to as „contractual partners»), within the framework of contractual and similar legal relationships, as well as related measures, and for the purpose of communicating with contractual partners (or on a pre-contractual basis), such as to respond to inquiries.
We use this data to fulfill our contractual obligations. This includes in particular the obligations to provide the agreed services, any update obligations, and remedies for warranty and other performance disruptions. In addition, we use the data to protect our rights and for the purpose of administrative tasks and corporate organization associated with these obligations. Furthermore, we process the data based on our legitimate interests in both proper and business-efficient management as well as security measures to protect our contractual partners and our business operations against abuse, threats to their data, secrets, information, and rights (e.g., involving telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed about further forms of processing, such as for marketing purposes, within the scope of this privacy policy.
We inform our contractual partners of which data is required for the aforementioned purposes either before or during the data collection process—for example, in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks, etc.), or in person.
We delete the data after the expiration of statutory warranty and comparable obligations, i.e., generally after four years, unless the data is stored in a customer account, e.g., as long as it must be retained for statutory archiving reasons (such as generally ten years for tax purposes). Data disclosed to us by the contractual partner in the course of an order will be deleted by us in accordance with the specifications and generally after the end of the order.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Affected persons: Beneficiaries and clients; prospective customers. Business and contract partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; organizational and administrative procedures. Business processes and operational procedures.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- Online store, order forms, e-commerce, and delivery: We process our customers' data to enable them to select, purchase, or order the chosen products, goods, and related services, as well as to enable their payment, delivery, or execution. Where necessary for the execution of an order, we use service providers, in particular postal, freight forwarding, and shipping companies, to carry out the delivery or execution to our customers. To process payment transactions, we use the services of banks and payment service providers. The required information is marked as such within the scope of the ordering or comparable purchasing process and includes the information required for delivery or provision and billing, as well as contact information in order to be able to consult if necessary; Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Business Processes and Procedures
Personal data of service recipients and clients—including customers, clients, or, in specific cases, legal clients, patients, or business partners, as well as other third parties—is processed within the framework of contractual and comparable legal relationships and pre-contractual measures, such as the initiation of business relationships. This data processing supports and facilitates business processes in areas such as customer management, sales, payment transactions, accounting, and project management.
The collected data serves to fulfill contractual obligations and efficiently organize operational processes. This includes the processing of business transactions, the management of customer relationships, the optimization of sales strategies, and the safeguarding of internal accounting and financial processes. Additionally, the data supports the protection of the controller's rights and promotes administrative tasks as well as the organization of the company.
Personal data may be disclosed to third parties if this is necessary to fulfill the stated purposes or legal obligations. After statutory retention periods have expired or if the purpose of the processing ceases to apply, the data will be deleted. This also includes data that must be stored for a longer period due to tax law and statutory retention requirements.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as information relating to them, such as details of authorship or time of creation); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved); log data (e.g., log files regarding logins or the retrieval of data or access times); credit rating data (e.g., credit score received, estimated probability of default, risk classification based thereon, historical payment behavior). Employee data (information on employees and other persons in an employment relationship).
- Affected persons: Service recipients and clients; prospective clients; communication partners; business and contractual partners; customers; third parties; users (e.g., website visitors, users of online services). Employees (e.g., staff members, job applicants, temporary workers, and other personnel).
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures; business processes and administrative procedures; security measures; provision of our online offering and user-friendliness; communication; marketing; sales promotion; assessment of creditworthiness and solvency; financial and payment management. Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)).
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR).
Additional information on processing procedures, methods, and services:
- Customer Management and Customer Relationship Management (CRM): Processes required in the context of customer management and customer relationship management (CRM) (e.g., customer acquisition in compliance with data protection regulations, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with due regard for data protection, data management and analysis to support customer relationships, administration of CRM systems, secure account management, customer segmentation, and target group identification); Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Contact management and maintenance: procedures required for the organization, maintenance, and safeguarding of contact information (e.g., the setup and maintenance of a central contact database, regular updates of contact information, monitoring of data integrity, implementation of data protection measures, ensuring access controls, conducting backups and restorations of contact data, training employees in the effective use of contact management software, regular review of communication history, and adjustment of contact strategies); Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Customer account: Customers can create an account within our online services (e.g., customer or user account, customer account for short). If the registration of a customer account is required, customers will be informed of this as well as of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration process as well as subsequent log-ins and uses of the customer account, we store the customers« IP addresses along with the times of access in order to be able to prove registration and prevent any misuse of the customer account. If the customer account has been terminated, the data of the customer account will be deleted after the time of termination, unless they are retained for purposes other than provision in the customer account or must be retained for legal reasons (e.g., internal storage of customer data, order processes, or invoices). It is the customers» responsibility to back up their data upon termination of the customer account; Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- General payment transactions: Procedures required for executing payment transactions, monitoring bank accounts, and controlling payment flows (e.g., preparation and verification of bank transfers, processing of direct debits, checking of bank statements, monitoring of incoming and outgoing payments, failed direct debit management, account reconciliation, cash management); Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Accounting, accounts payable, accounts receivable: procedures required for recording, processing, and controlling business transactions in accounts payable and accounts receivable accounting (e.g., preparation and review of incoming and outgoing invoices, monitoring and management of open items, execution of payment transactions, processing of dunning procedures, account reconciliation within the scope of receivables and payables, accounts payable accounting, and accounts receivable accounting); Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Financial Accounting and Taxes: Procedures required for the recording, administration, and control of financial transactions as well as the calculation, reporting, and payment of taxes (e.g., account assignment and posting of business transactions, preparation of quarterly and annual financial statements, execution of payment transactions, handling of dunning processes, account reconciliation, tax consulting, preparation and submission of tax returns, and handling of tax matters); Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Sales: Processes required in the planning, execution, and control of measures for the marketing and sale of products or services (e.g., customer acquisition, creation and follow-up of quotations, order processing, customer consulting and support, sales promotion, product training, sales controlling and analysis, management of distribution channels); Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Marketing, advertising and sales promotion: Processes required in the areas of marketing, advertising, and sales promotion (e.g., market analysis and target audience identification, development of marketing strategies, planning and execution of advertising campaigns, design and production of promotional materials, online marketing, including SEO and social media campaigns, event marketing and trade show participation, customer loyalty programs, sales promotion measures, performance measurement and optimization of marketing activities, budget management, and cost control); Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Vendors and Services Used in the Course of Business Operations
As part of our business operations, and in compliance with legal requirements, we use additional services, platforms, interfaces, or plug-ins from third parties (referred to as «services»). Their use is based on our interests in the proper, lawful, and economical management of our business operations and our internal organization.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as information relating to them, such as author details or time of creation); contract data (e.g., subject matter of the contract, term, customer category).
- Affected persons: Beneficiaries and clients; prospective customers. Business and contract partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures. Business processes and operational procedures.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- Comatose ERP system for managing products, customer data, and orders; Service provider: ProIT Informatik AG, Freidorf 151, 4132 Muttenz
Tel: +41 61 317 20 20; Email: info@proitag.ch; Website https://www.proitag.ch/index.php/produkte/erp-loesungen-von-comatic; Privacy Policy: https://www.proitag.ch/index.php?option=com_content&view=article&.id=20. - web updates kmu GmbH: Implementation and operation of the shop solution, access to shop data; Service provider: web updates kmu GmbH, Nussbergweg 2, 5400 Baden
Tel: +41 56b 496 51 94; Email: fragen@wuk.ch; Website https://wuk.ch/; Privacy Policy: https://wuk.ch/datenschutzerklaerung/.
Payment Methods
As part of contractual and other legal relationships, due to legal obligations, or otherwise based on our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, engage other service providers in addition to banks and credit institutions (collectively «payment service providers»).
The data processed by the payment service providers includes master data, such as name and address, bank details, such as account numbers or credit card numbers, passwords, TANs, and check digits, as well as contract-, amount-, and recipient-related information. This information is required to execute the transactions. However, the entered data is processed and stored exclusively by the payment service providers. This means that we do not receive any account- or credit card-related information, but merely information containing a confirmation or rejection of the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit reference agencies. The purpose of this transmission is identity and creditworthiness checks. For this, we refer to the terms and conditions and the data protection information of the payment service providers.
For payment transactions, the terms and conditions and privacy notices of the respective payment service providers apply, which can be accessed within the respective websites or transaction applications. We also refer to these for further information and the assertion of revocation, information, and other data subject rights.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved). Contact data (e.g., postal and email addresses or telephone numbers).
- Affected persons: Beneficiaries and clients; business and contractual partners. Prospective customers.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; business processes and operational procedures. Office and organizational procedures.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- PayPal: Payment services (technical integration of online payment methods) (e.g., PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website https://www.paypal.com/de; Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full. Basis for third country transfers: Adequacy decision (Luxembourg).
- Stripe: Payment services (technical integration of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website https://stripe.com. Privacy Policy: https://stripe.com/de/privacy.
- TWINT: Payment services (payment systems, apps, card terminals and point-of-sale systems, transaction management); Service provider: TWINT AG, Stauffacherstrasse 41, CH-8004 Zurich, Switzerland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://www.twint.ch/. Privacy Policy: https://www.twint.ch/datenschutz/.
Provision of the online service and web hosting
We process user data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
- Types of Data Processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved). Log data (e.g., log files regarding logins or the retrieval of data or access times).
- Affected persons: User (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- Provision of online service on rented storage space: To provide our online services, we use storage space, computing capacity, and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a «web host»); Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Provision of online services on own/dedicated server hardware: For the provision of our online service, we use server hardware operated by us as well as the associated storage space, computing capacity, and software; Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
- Collection of access data and log files: Access to our online services is logged in the form of so-called «server log files.» The server log files may include the address and name of the retrieved web pages and files, the date and time of retrieval, data volumes transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), and as a rule, IP addresses and the requesting provider. The server log files can be used, on the one hand, for security purposes, e.g., to prevent server overload (especially in the event of abusive attacks, so-called DDoS attacks), and on the other hand, to ensure server utilization and stability; Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR). Data deletion: Log file information is stored for a maximum of 30 days and is then deleted or anonymized. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident is finally resolved.
- Cyon Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacities); Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Service provider: cyon GmbH, Brunngässlein 12, CH – 4052 Basel, Switzerland; Website https://www.cyon.ch. Privacy Policy: https://www.cyon.ch/legal/datenschutzerklaerung.
Registration, Login, and User Account
Users can create a user account. During the registration process, users are informed of the required mandatory information, which is processed for the purpose of providing the user account on the basis of the fulfillment of contractual obligations. The data processed includes, in particular, the login information (username, password, and an email address).
As part of the use of our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests as well as those of the users in protection against misuse and other unauthorized use. These data are generally not passed on to third parties, unless it is necessary for the enforcement of our claims or there is a legal obligation to do so.
Users can be notified by email about events relevant to their user account, such as technical changes.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); log data (e.g., log files regarding logins or the retrieval of data or access times).
- Affected persons: User (e.g., website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; organizational and administrative procedures. Provision of our online offer and user-friendliness.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion». Deletion after termination.
- Legal bases Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- User profiles are not public: The user profiles are neither publicly visible nor accessible.
Contact and Inquiry Management
When contacting us (e.g., by post, contact form, email, telephone, or via social media) and within the scope of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to respond to the contact inquiries and any requested measures.
- Types of Data Processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and posts as well as information relating to them, such as author details or time of creation); usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Affected persons: Communication partners.
- Purposes of processing: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via online form). Provision of our online services and user-friendliness.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR). Performance of a contract and prior requests (Art. 6 (1) sentence 1 lit. b) GDPR).
Additional information on processing procedures, methods, and services:
- Contact form: When contacting us via our contact form, by e-mail or other communication channels, we process the personal data transmitted to us in order to answer and process the respective request. This usually includes details such as name, contact information and, if applicable, other information provided to us that is necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as reach measurement) serves to evaluate visitor flows to our online offering and can include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify at what times our online offering, its functions, or its content are used most frequently, or invite reuse. It also enables us to understand which areas require optimization.
In addition to web analytics, we can also use testing procedures to test and optimize different versions of our online service or its components.
Unless otherwise specified below, profiles—meaning data compiled regarding a usage process—may be created for these purposes, and information may be stored in a browser or on an end device and subsequently read out. The collected information includes, in particular, visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and details regarding usage times. If users have consented to the collection of their location data to us or to the providers of the services we use, the processing of location data is also possible.
In addition, the users' IP addresses are stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating the IP address) to protect the users. Generally, no clear user data (such as e-mail addresses or names) is stored in the context of web analytics, A/B testing, and optimization; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.
Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of Data Processed: Usage data (e.g., page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved); content data (e.g., textual or visual messages and posts as well as information relating to them, such as author details or time of creation). Event data (Facebook) («Event data» is information that is sent to the provider Meta via the Meta Pixel (whether via apps or other channels), for example, and relates to individuals or their actions. This data includes details of website visits, interactions with content and functions, app installations, and product purchases. Event data is processed for the purpose of creating target groups for content and advertising messages (Custom Audiences). It is important to note that event data does not include actual content such as written comments, login information, and contact information such as names, email addresses, or phone numbers. «Event data» is deleted by Meta after a maximum of two years, and the target groups formed from it disappear when our Meta user accounts are deleted.).
- Affected persons: User (e.g., website visitors, users of online services).
- Purposes of processing: Audience measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles); provision of our online service and user-friendliness; tracking (e.g., interest-based/behavioral profiling, use of cookies); conversion measurement (measurement of the effectiveness of marketing measures); target group creation. Marketing.
- Storage and deletion: Deletion in accordance with the information in the «General Information on Data Storage and Deletion» section. Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal bases Consent (Art. 6 (1) sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- Google Analytics: We use Google Analytics to measure and analyze the use of our online services based on a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to assign analysis information to a terminal device in order to recognize which content users have accessed within one or different usage processes, which search terms they have used, have accessed them again, or have interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of users who refer to our online offering and technical aspects of their terminal devices and browsers.
In the process, pseudonymous user profiles are created with information from the use of various devices, and cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subregion (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible, and is not used for any further purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for third country transfers: Equivalence Decision (Ireland); Right to Opt Out: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (Types of processing and the data processed). - Google as the recipient of the consent: The consent provided by users as part of a consent dialog (also known as «cookie opt-in/consent,» ‚cookie banner,‘ etc.) serves several purposes. First, it enables us to fulfill our obligation to obtain consent for the storage and retrieval of information on and from users’ devices (in accordance with the ePrivacy Directive). Second, it covers the processing of users’ personal data in accordance with data protection requirements. Furthermore, this consent also applies to Google, as the company is required under the Digital Markets Act to obtain consent for personalized services. Therefore, we share the status of the consents granted by users with Google. Our consent management software informs Google whether or not consent has been granted. The goal is to ensure that users’ granted or withheld consent is taken into account when using Google Analytics and when integrating features and external services. This allows us to dynamically adjust user consents and their revocations within Google Analytics and other Google services on our website based on user selections; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://support.google.com/analytics/answer/9976101?hl=de; Privacy Policy: https://policies.google.com/privacy. Basis for third country transfers: Adequacy decision (Ireland).
- Google Tag Manager: We use Google Tag Manager, a software by Google that enables us to centrally manage website tags via a user interface. Tags are small code elements on our website used to track and analyze visitor activity. This technology helps us improve our website and the content offered on it. Google Tag Manager itself does not create user profiles, store cookies containing user profiles, or perform independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services we use on our website. Nevertheless, when using Google Tag Manager, users' IP addresses are transmitted to Google, which is technically necessary to implement the services we use. Cookies may also be set in the process. However, this data processing only takes place if services are integrated via Tag Manager. For more detailed information regarding these services and their data processing, please refer to the subsequent sections of this privacy policy.; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement:
https://business.safety.google/adsprocessorterms. Basis for third country transfers: Adequacy decision (Ireland). - Meta Pixel and Custom Audiences: With the help of the Meta Pixel (or comparable functions for transmitting event data or contact information via interfaces in apps), Meta is able, on the one hand, to determine the visitors to our online offering as a target group for the display of advertisements (so-called «Meta Ads»). Accordingly, we use the Meta Pixel in order to display the Meta Ads placed by us only to such users on Meta's platforms and within the services of partners cooperating with Meta (so-called «Audience Network»)» https://www.facebook.com/audiencenetwork/ ) to display [ads] to users who have also shown an interest in our online service or who exhibit certain characteristics (e.g., interest in specific topics or products apparent from the visited web pages) that we transmit to Meta (so-called «Custom Audiences»). With the help of the Meta pixel, we also want to ensure that our Meta ads correspond to the potential interest of the users and are not annoying. With the help of the Meta pixel, we can also track the effectiveness of Meta ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta ad (so-called «conversion measurement»); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for third country transfers: Equivalence Decision (Ireland); Further information: User event data, i.e., behavioral and interest information, is processed for the purposes of targeted advertising and audience creation on the basis of the joint controllership agreement («Controller Addendum», https://www.facebook.com/legal/controller_addendum) processed. The joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which particularly includes the transmission of data to the parent company Meta Platforms, Inc. in the USA (based on the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
Social Media Presence
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
Please note that user data may be processed outside the European Union. This may result in risks for users, for example because the enforcement of user rights could be made more difficult.
Furthermore, user data within social networks is typically processed for market research and advertising purposes. For example, user profiles can be created based on user behavior and the resulting interests of the users. The latter may in turn be used to display advertisements inside and outside the networks that presumably correspond to the interests of the users. Therefore, cookies are generally stored on the users' computers, in which the user behavior and interests are saved. In addition, data can also be stored in the user profiles independently of the devices used by the users (in particular if they are members of the respective platforms and logged in there).
For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
We also point out that in the case of requests for information and the assertion of data subject rights, these can be asserted most effectively with the providers. Only the latter have access to the respective user data and can directly take appropriate measures and provide information. Should you still need help, you can contact us.
- Types of Data Processed: Contact data (e.g., postal and email addresses or phone numbers); content data (e.g., text or image messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Affected persons: User (e.g., website visitors, users of online services).
- Purposes of processing: Communication; Feedback (e.g., collecting feedback via online form). Public relations.
- Storage and deletion: Deletion in accordance with the information in the section «General Information on Data Storage and Deletion».
- Legal bases Legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).
Additional information on processing procedures, methods, and services:
- Instagram: Social network, enables the sharing of photos and videos, commenting on and favoriting posts, messaging, and subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for third country transfers: Adequacy decision (Ireland).
- Facebook pages: Profiles within the social network Facebook – We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data of visitors to our Facebook page (so-called «fan page»). This data includes information about the types of content users view or interact with, or the actions taken by them (see „Things you and others do and provide» in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by the users (e.g., IP addresses, operating system, browser type, language settings, cookie data; see under „Device Information» in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under „How do we use this information?», Facebook also collects and uses information to provide analytical services, known as «Page Insights», to page operators so that they can gain insights into how people interact with their pages and the content associated with them. We have entered into a special agreement with Facebook («Page Insights Information», https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfill the rights of data subjects (i.e. users can, for example, direct requests for information or deletion directly to Facebook). The rights of users (in particular to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the «Page Insights Information» (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint responsibility is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which particularly concerns the transmission of data to the parent company Meta Platforms, Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/. Basis for third country transfers: Adequacy decision (Ireland).
- LinkedIn: Social Network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of visitors whose data is collected for the purpose of creating „Page Insights» (statistics) of our LinkedIn profiles.
This data includes information about the types of content that users view or interact with, or the actions taken by them, as well as information about the devices used by the users (e.g., IP addresses, operating system, browser type, language settings, cookie data) and information from the users' profile, such as job title, country, industry, seniority, company size, and employment status. Information on data protection regarding the processing of user data by LinkedIn can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy
We have entered into a special agreement with LinkedIn Ireland («Page Insights Joint Controller Addendum‚ (the 'Addendum»))., https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill the rights of data subjects (i.e. users can, for example, direct requests for information or deletion directly to LinkedIn). The rights of users (in particular to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint controllership is limited to the collection of data by and transmission to Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of Ireland Unlimited Company, which particularly concerns the transmission of data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third country transfers: Adequacy decision (Ireland). Right to Opt Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - TikTok: Social network that enables the sharing of photos and videos, commenting on and favoriting posts, sending messages, and subscribing to accounts; Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://www.tiktok.com; Privacy Policy: https://www.tiktok.com/de/privacy-policy. Basis for third country transfers: Standard Contractual Clauses (https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms).
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Privacy Policy: https://policies.google.com/privacy; Basis for third country transfers: Adequacy decision (Ireland). Right to Opt Out: https://myadcenter.google.com/personalizationoff.
- Mailchimp: Email marketing, automation of marketing processes, collection, storage and management of contact data, measurement of campaign performance, tracking and analysis of recipient interaction with content, content personalization; Service provider: Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://mailchimp.com; Privacy Policy: https://mailchimp.com/legal/; Data Processing Agreement: https://mailchimp.com/legal/; Basis for third country transfers: Standard contractual clauses (provided by the service provider). Further information: Special safety measures: https://mailchimp.com/de/help/mailchimp-european-data-transfers/.
Plug-ins, embedded features, and content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as „third-party providers»). These may include, for example, graphics, videos, or city maps (hereinafter uniformly referred to as „content»).
The integration always requires that the third-party providers of this content process the users„ IP address, as they could not send the content to their browser without the IP address. The IP address is therefore necessary for the display of this content or functions. We strive to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as »web beacons„) for statistical or marketing purposes. Information such as visitor traffic on the pages of this website can be evaluated using the »pixel tags". Furthermore, the pseudonymous information can be stored in cookies on the user's device and can contain, among other things, technical information about the browser and operating system, referring websites, the time of visit, and other details regarding the use of our online service, and may also be combined with such information from other sources.
Information on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of Data Processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved).
- Affected persons: User (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness. Provision of contractual services and fulfillment of contractual obligations.
- Storage and deletion: Deletion in accordance with the information in the «General Information on Data Storage and Deletion» section. Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Legal bases Consent (Art. 6 (1) sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR).
Additional information on processing procedures, methods, and services:
- reCAPTCHA: We integrate the «reCAPTCHA» function to be able to recognize whether entries (e.g. in online forms) are made by humans and not by automatically operating machines (so-called «bots»). The processed data may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, length of stay on websites, previously visited websites, interactions with reCAPTCHA on other websites, under certain circumstances cookies, as well as results from manual recognition processes (e.g. answering questions asked or selecting objects in images). Data processing is carried out on the basis of our legitimate interest in protecting our online offering against abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website https://www.google.com/recaptcha/; Privacy Policy: https://policies.google.com/privacy; Basis for third country transfers: Adequacy decision (Ireland). Right to Opt Out: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://myadcenter.google.com/personalizationoff.
- YouTube videos: Video content; YouTube videos are embedded via a special domain (recognizable by the component «youtube-nocookie») in the so-called «Enhanced Privacy Mode», which means that no cookies regarding user activities are collected to personalize video playback. Nevertheless, information on user interaction with the video (e.g., remembering the last playback position) may be saved; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy. Basis for third country transfers: Adequacy decision (Ireland).
Changes and Updates
We kindly ask you to check the content of our privacy policy on a regular basis. We will update the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require any action on your part (e.g., consent) or any other individual notification.
Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, please note that these addresses may change over time and we ask that you verify the information before contacting them.

