Privacy Policy
Version 11.08.2026
This English version is provided for convenience. In the event of any discrepancy, the German version prevails.
Introduction and Overview
We have written this privacy policy (version 11.08.2026-313232775) in order to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller — and the processors we commission (e.g. providers) — process, will process in future, and what lawful options you have.
In short: We inform you comprehensively about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, by contrast, is intended to describe the most important things to you as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. We thereby inform you in clear and plain language that, in the course of our business activities, we only process personal data where there is a corresponding legal basis. That is certainly not possible if you give the briefest, most opaque and legally technical explanations, as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and that there may be one or two pieces of information among them that you did not previously know.
If questions nevertheless remain, we would ask you to contact the responsible body named below or in the legal notice, to follow the links provided, and to look at further information on third-party sites. Our contact details can of course also be found in the legal notice.
Scope
This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 no. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile apps for smartphones and other devices
In short: The privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels named. Should we enter into legal relationships with you outside of these channels, we will inform you separately where necessary.
Legal Bases
In the following privacy policy we provide you with transparent information on the legal principles and provisions — that is, the legal bases of the General Data Protection Regulation — that enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this General Data Protection Regulation of the EU online on EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
- Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you enter in a contact form.
- Contract (Article 6(1)(b) GDPR): We process your data in order to fulfil a contract or pre-contractual obligations with you. For example, if we conclude a purchase contract with you, we require personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): Where we are subject to a legal obligation, we process your data. For example, we are legally obliged to retain invoices for accounting purposes. These generally contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we have to process certain data in order to operate our website securely and in an economically efficient manner. This processing therefore constitutes a legitimate interest.
Further conditions such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, do not generally arise in our case. Insofar as such a legal basis should nevertheless be relevant, it will be indicated at the corresponding point.
In addition to the EU regulation, national laws also apply:
- In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), DSG for short.
- In Germany the Federal Data Protection Act, BDSG for short, applies.
Insofar as further regional or national laws apply, we will inform you about them in the following sections.
Contact Details of the Controller
Should you have questions about data protection or the processing of personal data, you will find below the contact details of the controller in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR):
eskape.digital GmbH
Sean Keogh
Mühlenkamp 12C
22303 Hamburg, Germany
Email: consulting@eskape.digital
Phone: +491736592429
Legal notice: https://www.eskape.digital/legal
Retention Period
That we only store personal data for as long as is absolutely necessary for the provision of our services and products is a general criterion for us. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases we are legally obliged to retain certain data even after the original purpose has ceased to apply, for example for accounting purposes.
Should you wish your data to be deleted or should you withdraw your consent to the data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to retain it.
We inform you further below about the specific duration of the respective data processing, insofar as we have further information about it.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you about the following rights to which you are entitled, so that data is processed fairly and transparently:
- Under Article 15 GDPR you have a right of access as to whether we process data about you. If that is the case, you have the right to receive a copy of the data and to be informed of the following:
- for what purpose we carry out the processing;
- the categories, that is, the types of data that are processed;
- who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to the processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found further below);
- the origin of the data, where we have not collected it from you;
- whether profiling takes place, that is, whether data is automatically evaluated in order to arrive at a personal profile of you.
- Under Article 16 GDPR you have a right to rectification of the data, which means that we must correct data if you find errors.
- Under Article 17 GDPR you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.
- Under Article 18 GDPR you have the right to restriction of processing, which means that we may only store the data but not use it further.
- Under Article 20 GDPR you have the right to data portability, which means that on request we will make your data available to you in a commonly used format.
- Under Article 21 GDPR you have a right to object, which, once enforced, brings about a change to the processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
- If data is used to carry out direct marketing, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used to carry out profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
- Under Article 22 GDPR you may under certain circumstances have the right not to be subject to a decision based solely on automated processing (for example profiling).
- Under Article 77 GDPR you have the right to lodge a complaint. That is, you can complain to the data protection authority at any time if you are of the opinion that the processing of personal data infringes the GDPR.
In short: You have rights — do not hesitate to contact the responsible body listed above!
If you believe that the processing of your data infringes data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria this is the Data Protection Authority, whose website you will find at https://www.dsb.gv.at/. In Germany there is a data protection officer for each federal state. For more detailed information you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Hamburg Data Protection Authority
State Commissioner for Data Protection: Thomas Fuchs
Address: Ludwig-Erhard-Str. 22, 7th floor, 20459 Hamburg
Phone: 040/428 54-40 40
Email: mailbox@datenschutz.hamburg.de
Website: https://datenschutz-hamburg.de/
Data Transfer to Third Countries
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to this processing or if some other legal permission exists. This applies in particular if the processing is required by law or is necessary for the fulfilment of a contractual relationship, and in every case only insofar as this is generally permitted. Your consent is in most cases the most important reason for us having data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently only exists if a US company that processes personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. You can find more information on this at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data possibly not being processed and stored anonymously. Furthermore, US government authorities may under certain circumstances access individual data. In addition, it may happen that collected data is linked with data from other services of the same provider, insofar as you have a corresponding user account. Where possible, we try to use server locations within the EU, insofar as this is offered.
We inform you in more detail about data transfers to third countries at the appropriate points in this privacy policy, insofar as this applies.
Security of Data Processing
In order to protect personal data, we have implemented both technical and organisational measures. Where possible for us, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as possible, within our means, for third parties to infer personal information from our data.
Art. 25 GDPR speaks here of "data protection by design and by default" and means by this that with both software (e.g. forms) and hardware (e.g. access to the server room) one always thinks about security and puts corresponding measures in place. In the following we will, if necessary, go into specific measures.
TLS Encryption with https
TLS, encryption and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the internet in a tap-proof manner.
This means that the complete transmission of all data from your browser to our web server is secured — nobody can "listen in".
With this we have introduced an additional layer of security and fulfil data protection by design (Article 25(1) GDPR). Through the use of TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognise the use of this safeguarding of data transmission by the small padlock symbol at the top left of the browser, to the left of the internet address (e.g. examplesite.com), and by the use of the https scheme (instead of http) as part of our internet address.
If you would like to know more about encryption, we recommend searching Google for "Hypertext Transfer Protocol Secure wiki" to obtain good links to further information.
Communication
Communication Summary
- 👥 Data subjects: Everyone who communicates with us by telephone, email or online form
- 📓 Data processed: e.g. telephone number, name, email address, data entered in forms. You will find more details on this under the respective type of contact used
- 🤝 Purpose: Handling communication with customers, business partners, etc.
- 📅 Retention period: Duration of the business transaction and of the statutory requirements
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate by telephone, email or online form, personal data may be processed.
The data is processed for the handling and processing of your question and the associated business transaction. The data is stored for exactly that long, or for as long as the law prescribes.
Data Subjects
Everyone who seeks contact with us via the communication channels we provide is affected by the processes named.
Telephone
If you call us, the call data is stored in pseudonymised form on the respective device and at the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by email and stored in order to answer the enquiry. The data is deleted as soon as the business transaction has ended and statutory requirements permit.
If you communicate with us by email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted as soon as the business transaction has ended and statutory requirements permit.
Online Forms
If you communicate with us by means of an online form, data is stored on our web server and may be forwarded to an email address of ours. The data is deleted as soon as the business transaction has ended and statutory requirements permit.
Legal Bases
The processing of the data is based on the following legal bases:
- Art. 6(1)(a) GDPR (consent): You give us your consent to store your data and to use it further for purposes relating to the business transaction;
- Art. 6(1)(b) GDPR (contract): There is a necessity for the fulfilment of a contract with you or with a processor such as, for example, the telephone provider, or we have to process the data for pre-contractual activities such as, for example, the preparation of a quotation;
- Art. 6(1)(f) GDPR (legitimate interests): We want to conduct customer enquiries and business communication in a professional setting. For this, certain technical facilities such as email programs, Exchange servers and mobile network operators are necessary in order to be able to conduct communication efficiently.
Data Processing Agreement (DPA)
In this section we would like to explain to you what a data processing agreement is and why it is needed. Like most companies, we do not work alone but also make use of the services of other companies or individuals. Through the involvement of various companies or service providers, it may be the case that we pass on personal data for processing. These partners then act as processors, with whom we conclude a contract, the so-called data processing agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively on our instructions and must be governed by the DPA.
Who Are Processors?
As a company and website owner we are responsible for all data that we process about you. Alongside controllers there may also be so-called processors. This includes every company or person that processes personal data on our behalf. More precisely, and in the words of the GDPR definition: any natural or legal person, public authority, agency or other body which processes personal data on our behalf is regarded as a processor. Processors can therefore be service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
For a better understanding of the terminology, here is an overview of the three roles in the GDPR:
Data subject (you as customer or interested party) → Controller (we as company and client) → Processor (service providers such as web hosts or cloud providers)
Content of a Data Processing Agreement
As already mentioned above, we have concluded a DPA with our partners who act as processors. This records above all that the processor processes the data to be handled exclusively in accordance with the GDPR. The contract must be concluded in writing, although in this context conclusion of the contract electronically also counts as "in writing". Only on the basis of the contract does the processing of personal data take place. The contract must contain the following:
- binding to us as the controller
- obligations and rights of the controller
- categories of data subjects
- type of personal data
- nature and purpose of the data processing
- subject matter and duration of the data processing
- place of performance of the data processing
The contract further contains all the obligations of the processor. The most important obligations are:
- to ensure measures for data security
- to take possible technical and organisational measures in order to protect the rights of the data subject
- to maintain a record of processing activities
- to cooperate with the data protection supervisory authority upon its request
- to carry out a risk analysis in relation to the personal data received
- sub-processors may only be engaged with the written authorisation of the controller
You can see what such a DPA looks like in practice, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A model contract is presented there.
Cookies
Cookies Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: depends on the respective cookie. You will find more details on this further below or from the manufacturer of the software that sets the cookie.
- 📓 Data processed: Depends on the respective cookie used. You will find more details on this further below or from the manufacturer of the software that sets the cookie.
- 📅 Retention period: depends on the respective cookie, can vary from hours to years
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Are Cookies?
Our website uses HTTP cookies in order to store user-specific data.
In the following we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you surf the internet, you use a browser. Well-known browsers are, for example, Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, since there are also other cookies for other areas of application. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, effectively the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must additionally be specified.
Cookies store certain user data about you, such as language or personal page settings. When you call up our page again, your browser transmits the "user-related" information back to our page. Thanks to cookies, our website knows who you are and offers you the setting you are used to. In some browsers each cookie has its own file, in others such as Firefox all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. In it, the web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site; third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be assessed individually, since each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and contain no viruses, trojans or other "pests". Cookies also cannot access information on your PC.
Cookie data can look like this, for example:
Name: _ga
Value: GA1.2.1326744211.152313232775-9
Purpose: Distinguishing website visitors
Expiry date: after 2 years
A browser should be able to support these minimum sizes:
- At least 4096 bytes per cookie
- At least 50 cookies per domain
- At least 3000 cookies in total
What Types of Cookies Are There?
The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point we would like to briefly address the different types of HTTP cookies.
Four types of cookies can be distinguished:
Essential cookies
These cookies are necessary in order to ensure basic functions of the website. For example, these cookies are needed when a user places a product in the shopping basket, then continues browsing on other pages and only later goes to the checkout. Thanks to these cookies the shopping basket is not deleted, even if the user closes their browser window.
Functional cookies
These cookies collect information about user behaviour and about whether the user receives any error messages. In addition, these cookies are also used to measure loading time and the behaviour of the website in different browsers.
Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. That can be very practical, but also very annoying.
Usually, when you first visit a website, you are asked which of these types of cookies you would like to allow. And of course this decision is also stored in a cookie.
If you would like to know more about cookies and are not put off by technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments entitled "HTTP State Management Mechanism".
Purpose of the Processing via Cookies
The purpose ultimately depends on the respective cookie. You will find more details on this further below or from the manufacturer of the software that sets the cookie.
What Data Is Processed?
Cookies are little helpers for many different tasks. Which data is stored in cookies unfortunately cannot be generalised, but we will inform you in the course of the following privacy policy about the data processed or stored.
Retention Period of Cookies
The retention period depends on the respective cookie and is specified in more detail further below. Some cookies are deleted after less than an hour; others can remain stored on a computer for several years.
You also have influence over the retention period yourself. You can manually delete all cookies at any time via your browser (see also "Right to object" below). Furthermore, cookies based on consent are deleted at the latest after withdrawal of your consent, whereby the lawfulness of the storage up to that point remains unaffected.
Right to Object — How Can I Delete Cookies?
You decide for yourself how and whether you want to use cookies. Irrespective of which service or which website the cookies come from, you always have the option of deleting cookies, deactivating them or allowing them only in part. For example, you can block third-party cookies but allow all other cookies.
If you would like to determine which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Clear, enable and manage cookies in Chrome
Safari: Manage cookies and website data in Safari
Firefox: Clear cookies and site data in Firefox
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you fundamentally do not want cookies, you can set up your browser so that it always informs you when a cookie is to be set. In this way you can decide for each individual cookie whether you allow the cookie or not. The procedure varies from browser to browser. It is best to search for the instructions in Google using the search term "delete cookies Chrome" or "disable cookies Chrome" in the case of a Chrome browser.
Legal Basis
Since 2009 there have been the so-called "cookie directives". These state that the storing of cookies requires your consent (Article 6(1)(a) GDPR). Within the EU countries, however, there are still very different reactions to these directives. In Austria, the directive was implemented in § 165(3) of the Telecommunications Act (2021). In Germany the cookie directives were not implemented as national law. Instead, this directive was largely implemented in § 15(3) of the Telemedia Act (TMG), which has been replaced since May 2024 by the Digital Services Act (DDG).
For strictly necessary cookies, even where no consent is present, legitimate interests (Article 6(1)(f) GDPR) exist, which in most cases are of an economic nature. We want to give visitors to the website a pleasant user experience, and for this certain cookies are often absolutely necessary.
Insofar as non-essential cookies are used, this only happens in the case of your consent. The legal basis in this respect is Art. 6(1)(a) GDPR.
In the following sections you will be informed in more detail about the use of cookies, insofar as the software used employs cookies.
Web Hosting Introduction
Web Hosting Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: professional hosting of the website and safeguarding of its operation
- 📓 Data processed: IP address, time of the website visit, browser used and further data. You will find more details on this further below or from the respective web hosting provider used.
- 📅 Retention period: depends on the respective provider, but as a rule 2 weeks
- ⚖️ Legal bases: Art. 6(1)(f) GDPR (legitimate interests)
What Is Web Hosting?
When you visit websites nowadays, certain information — including personal data — is automatically created and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only with justification. By website, incidentally, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) through to the very last sub-page (like this one here). By domain we mean, for example, example.com or sampleexample.com.
If you want to view a website on a computer, tablet or smartphone, you use a program for this called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We refer to these in short as browsers or web browsers.
In order to display the website, the browser has to connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and demanding task, which is why this is usually taken over by professional providers. These offer web hosting and thereby ensure reliable and error-free storage of website data. A whole lot of technical terms, but please stick with it, it gets better!
When the browser on your computer (desktop, laptop, tablet or smartphone) establishes a connection, and during the data transmission to and from the web server, personal data may be processed. On the one hand your computer stores data; on the other hand the web server also has to store data for a time in order to ensure proper operation.
A picture says more than a thousand words, so the following graphic illustrates the interplay between browser, the internet and the hosting provider.
Why Do We Process Personal Data?
The purposes of the data processing are:
- Professional hosting of the website and safeguarding of its operation
- Maintaining operational and IT security
- Anonymous evaluation of access behaviour in order to improve our offering and, where applicable, for criminal prosecution or the pursuit of claims
What Data Is Processed?
Even while you are visiting our website right now, our web server — that is, the computer on which this web page is stored — as a rule automatically stores data such as
- the complete internet address (URL) of the web page called up
- browser and browser version (e.g. Chrome 87)
- the operating system used (e.g. Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g. https://www.examplesourcesite.com/whereicamefrom/)
- the host name and IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
- date and time
- in files, the so-called web server log files
How Long Is Data Stored?
As a rule, the data named above is stored for two weeks and then automatically deleted. We do not pass this data on, but cannot rule out that this data may be inspected by authorities in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass your data on without consent!
Legal Basis
The lawfulness of processing personal data in the context of web hosting arises from Art. 6(1)(f) GDPR (safeguarding legitimate interests), since the use of professional hosting with a provider is necessary in order to present the company on the internet securely and in a user-friendly manner and to be able to pursue attacks and any claims arising from them.
Between us and our hosting provider there is a contract on commissioned processing in accordance with Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.
Netlify
Our website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA.
When you visit our website, Netlify's servers automatically process technical data that is required for the delivery of the website — including your IP address, the pages called up, browser type and version, the operating system used, and the date and time of access. This processing is technically necessary in order to display the website and to ensure its security and stability.
Data submitted via our contact forms is likewise processed and stored by Netlify before being forwarded to us.
Netlify also processes data about you in the USA. Netlify is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. Netlify's Data Processing Addendum, which forms part of the Netlify terms of use, governs this processing and additionally contains the standard contractual clauses published by the European Commission (Art. 46(2) and (3) GDPR).
You can find out more about the data processed through the use of Netlify in Netlify's privacy policy at https://www.netlify.com/privacy/.
Web Analytics Introduction
Web Analytics Privacy Policy Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: Evaluation of visitor information in order to optimise the web offering.
- 📓 Data processed: Access statistics containing data such as locations of accesses, device data, access duration and time, navigation behaviour, click behaviour and IP addresses. You will find more details on this from the respective web analytics tool used.
- 📅 Retention period: depends on the web analytics tool used
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Is Web Analytics?
On our website we use software for evaluating the behaviour of website visitors, known in short as web analytics or web analysis. In doing so, data is collected which the respective analytics tool provider (also called a tracking tool) stores, manages and processes. With the help of the data, analyses of user behaviour on our website are produced and made available to us as the website operator. In addition, most tools offer various testing options. For instance, we can test which offers or content go down best with our visitors. To do so, we show you two different offers for a limited period. After the test (a so-called A/B test) we know which product or which content our website visitors find more interesting. For such test procedures, as well as for other analytics procedures, user profiles can also be created and the data stored in cookies.
Why Do We Carry Out Web Analytics?
With our website we have a clear goal in mind: we want to deliver the best web offering on the market for our industry. To achieve this goal, we want on the one hand to provide the best and most interesting offering, and on the other hand to ensure that you feel entirely comfortable on our website. With the help of web analysis tools we can examine the behaviour of our website visitors more closely and then improve our web offering accordingly for you and for us. For example, we can identify the average age of our visitors, where they come from, when our website is visited most, or which content or products are particularly popular. All this information helps us to optimise the website and thus adapt it optimally to your needs, interests and wishes.
What Data Is Processed?
Exactly which data is stored naturally depends on the analysis tools used. But as a rule it is stored, for example, which content you view on our website, which buttons or links you click, when you call up a page, which browser you use, with which device (PC, tablet, smartphone, etc.) you visit the website, or which computer system you use. If you agreed that location data may also be collected, this too can be processed by the web analysis tool provider.
Your IP address is also stored. Under the General Data Protection Regulation (GDPR), IP addresses are personal data. Your IP address is, however, as a rule stored in pseudonymised form (that is, in an unrecognisable and shortened form). For the purpose of testing, web analysis and web optimisation, no direct data such as your name, your age, your address or your email address is stored in principle. All this data, insofar as it is collected, is stored in pseudonymised form. This means that you cannot be identified as a person.
The following example shows schematically how Google Analytics works, as an example of client-based web tracking with JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website again; other cookies can store data for several years.
Duration of the Data Processing
We inform you about the duration of the data processing further below, insofar as we have further information on it. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. Where it is legally prescribed, as for example in the case of accounting, this retention period may also be exceeded.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works via the "Cookie Settings" link in the footer of every page, through which you can change your selection at any time. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.
Legal Basis
The use of web analytics requires your consent, which we have obtained with our cookie pop-up. This consent constitutes, under Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data such as may occur in the course of collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thereby improving our offering technically and economically. With the help of web analytics we identify errors on the website, can identify attacks and improve economic efficiency. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We nevertheless only use the tools insofar as you have given consent.
Since cookies are used with web analytics tools, we also recommend that you read our general privacy policy on cookies. To find out exactly which data of yours is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools can be found — where available — in the following sections.
Google Analytics Privacy Policy
Google Analytics Privacy Policy Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: Evaluation of visitor information in order to optimise the web offering.
- 📓 Data processed: Access statistics containing data such as locations of accesses, device data, access duration and time, navigation behaviour and click behaviour. You will find more details on this further below in this privacy policy.
- 📅 Retention period: individually configurable; by default Google Analytics 4 stores data for 14 months
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Is Google Analytics?
On our website we use the analysis tracking tool Google Analytics in the Google Analytics 4 (GA4) version from the American company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. Through the combination of various technologies such as cookies, device IDs and login information, you as a user can, however, be identified across different devices. This means your actions can also be analysed across platforms.
If, for example, you click a link, this event is stored in a cookie and sent to Google Analytics. With the help of the reports we receive from Google Analytics, we can better tailor our website and our service to your wishes. In the following we go into the tracking tool in more detail and inform you above all about which data is processed and how you can prevent this.
Google Analytics is a tracking tool that serves to analyse the traffic on our website. The basis of these measurements and analyses is a pseudonymous user identification number. This number contains no personal data such as name or address, but serves to attribute events to a device. GA4 uses an event-based model that records detailed information on user interactions such as page views, clicks, scrolling and conversion events. In addition, various machine learning functions have been built into GA4 in order to better understand user behaviour and certain trends. GA4 relies on modelling with the help of machine learning functions. That is, on the basis of the data collected, missing data can also be extrapolated in order to optimise the analysis and also to be able to provide forecasts.
For Google Analytics to work at all, a tracking code is built into the code of our website. When you visit our website, this code records various events that you perform on our website. With GA4's event-based data model, we as website operators can define and track specific events in order to obtain analyses of user interactions. This means that, in addition to general information such as clicks or page views, specific events that are important for our business can also be tracked. Such specific events might be, for example, the submission of a contact form or the purchase of a product.
As soon as you leave our website, this data is sent to the Google Analytics servers and stored there.
Google processes the data and we receive reports about your user behaviour. These may include, among others, the following reports:
- Audience reports: Through audience reports we get to know our users better and know more precisely who is interested in our service.
- Advertising reports: Through advertising reports we can analyse and improve our online advertising more easily.
- Acquisition reports: Acquisition reports give us helpful information about how we can get more people excited about our service.
- Behaviour reports: Here we learn how you interact with our website. We can trace the path you take on our site and which links you click.
- Conversion reports: A conversion is a process in which you perform a desired action as a result of a marketing message. For example, when you go from being a mere website visitor to a buyer or newsletter subscriber. With the help of these reports we learn more about how our marketing measures are received by you. In this way we want to increase our conversion rate.
- Real-time reports: Here we always find out immediately what is happening on our website right now. For example, we can see how many users are reading this text at this moment.
In addition to the analysis reports named above, Google Analytics 4 also offers, among others, the following functions:
- Event-based data model: This model records very specific events that can take place on our website. For example, the playing of a video, the purchase of a product or signing up to our newsletter.
- Advanced analysis functions: With these functions we can understand your behaviour on our website or certain general trends even better. For instance, we can segment user groups, make comparative analyses of audiences or trace your route or path on our website.
- Predictive modelling: On the basis of collected data, machine learning can extrapolate missing data that predicts future events and trends. This can help us to develop better marketing strategies.
- Cross-platform analysis: The collection and analysis of data is possible from both websites and apps. This gives us the opportunity to analyse user behaviour across platforms, provided of course that you have consented to the data processing.
Why Do We Use Google Analytics on Our Website?
Our goal with this website is clear: we want to offer you the best possible service. The statistics and data from Google Analytics help us to achieve this goal.
The statistically evaluated data shows us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimise our site so that it is more easily found on Google by interested people. On the other hand, the data helps us to understand you as a visitor better. We therefore know very precisely what we have to improve on our website in order to offer you the best possible service. The data also serves us in carrying out our advertising and marketing measures in a more individual and cost-effective way. After all, it only makes sense to show our products and services to people who are interested in them.
What Data Is Stored by Google Analytics?
With the help of a tracking code, Google Analytics creates a random, unique ID that is linked to your browser cookie. In this way Google Analytics recognises you as a new user and a user ID is assigned to you. The next time you visit our site, you are recognised as a "returning" user. All collected data is stored together with this user ID. This is what makes it possible to evaluate pseudonymous user profiles.
In order to be able to analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For every newly created property, the Google Analytics 4 property is the default. Depending on the property used, data is stored for different lengths of time.
Through identifiers such as cookies, app instance IDs, user IDs or custom event parameters, your interactions are measured across platforms, provided you have consented. Interactions are all types of actions that you perform on our website. If you also use other Google systems (such as a Google account), data generated via Google Analytics can be linked with third-party cookies. Google does not pass on Google Analytics data unless we as the website operator authorise it. Exceptions may arise where it is legally required.
According to Google, no IP addresses are logged or stored in Google Analytics 4. Google does, however, use the IP address data to derive location data and deletes it immediately afterwards. All IP addresses collected from users in the EU are therefore deleted before the data is stored in a data centre or on a server.
Since the focus with Google Analytics 4 is on event-based data, the tool uses considerably fewer cookies compared with earlier versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies that are used by GA4. These include, for example:
Name: _ga
Value: 2.1326744211.152313232775-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. In principle it serves to distinguish website visitors.
Expiry date: after 2 years
Name: _gid
Value: 2.1687193234.152313232775-1
Purpose: This cookie also serves to distinguish website visitors
Expiry date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: Used to throttle the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie is given the name _dc_gtm_<property-id>.
Expiry date: after 1 minute
Note: This list cannot claim to be complete, as Google repeatedly changes its choice of cookies. A goal of GA4 is also to improve data protection. The tool therefore offers a number of options for controlling data collection. For instance, we can determine the retention period ourselves and also control data collection.
Here we show you an overview of the most important types of data collected with Google Analytics:
Heatmaps: Google creates so-called heatmaps. Via heatmaps one sees exactly those areas that you click on. In this way we obtain information about where you are "moving" on our site.
Session duration: Google refers to session duration as the time you spend on our site without leaving the page. If you have been inactive for 20 minutes, the session ends automatically.
Bounce rate: A bounce is when you view only one page on our website and then leave our website again.
Account creation: If you create an account on our website or place an order, Google Analytics collects this data.
Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, derivations for location data are used.
Technical information: Technical information includes, among other things, your browser type, your internet provider or your screen resolution.
Source: Google Analytics — and we — are of course also interested in which website or which advertisement brought you to our site.
Further data includes contact details, any ratings, the playing of media (e.g. when you play a video via our site), the sharing of content via social media or adding to your favourites. The list makes no claim to completeness and serves only as general orientation regarding data storage by Google Analytics.
How Long and Where Is the Data Stored?
Google has its servers distributed all over the world. Here you can read exactly where the Google data centres are located: https://datacenters.google/
Your data is distributed across various physical storage media. This has the advantage that the data can be retrieved more quickly and is better protected against manipulation. In every Google data centre there are corresponding emergency programmes for your data. If, for example, Google's hardware fails or natural disasters knock out servers, the risk of a service interruption at Google nevertheless remains low.
The retention period of the data depends on the properties used. The retention period is always determined separately for each individual property. Google Analytics offers us four options for controlling the retention period:
- 2 months: this is the shortest retention period.
- 14 months: by default, data with GA4 remains stored for 14 months.
- 26 months: data can also be stored for 26 months.
- Data is only deleted when we delete it manually
In addition, there is also the option that data is only deleted if you no longer visit our website within the period we have selected. In this case the retention period is reset each time you visit our website again within the specified period.
Once the specified period has elapsed, the data is deleted once a month. This retention period applies to your data that is linked to cookies, user recognition and advertising IDs (e.g. cookies of the DoubleClick domain). Report results are based on aggregated data and are stored independently of user data. Aggregated data is a merging of individual data into a larger unit.
How Can I Delete My Data or Prevent Data Storage?
Under the data protection law of the European Union, you have the right to obtain information about your data, to update it, to delete it or to restrict it. Using the browser add-on for deactivating Google Analytics JavaScript (analytics.js, gtag.js), you prevent Google Analytics 4 from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=en. Please note that this add-on only deactivates data collection by Google Analytics.
If you fundamentally want to deactivate, delete or manage cookies, you will find the corresponding links to the relevant instructions for the best-known browsers under the "Cookies" section.
Legal Basis
The use of Google Analytics requires your consent, which we have obtained with our cookie pop-up. This consent constitutes, under Art. 6(1)(a) GDPR (consent), the legal basis for the processing of personal data such as may occur in the course of collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors and thereby improving our offering technically and economically. With the help of Google Analytics we identify errors on the website, can identify attacks and improve economic efficiency. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We nevertheless only use Google Analytics insofar as you have given consent.
Google also processes data about you in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
You can find the Google Ads Data Processing Terms, which refer to the standard contractual clauses, at https://business.safety.google/adsprocessorterms/.
We hope we have been able to give you the most important information about data processing by Google Analytics. If you would like to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/us/ and https://support.google.com/analytics/answer/6004245?hl=en.
If you would like to learn more about the data processing, use the Google privacy policy at https://policies.google.com/privacy?hl=en.
Data Processing Agreement (DPA) Google Analytics
Within the meaning of Article 28 of the General Data Protection Regulation (GDPR), we have concluded a data processing agreement (DPA) with Google. You can read what a DPA is exactly and, above all, what a DPA must contain in our general section "Data Processing Agreement (DPA)".
This contract is legally prescribed because Google processes personal data on our behalf. It clarifies that Google may only process data received from us on our instructions and must comply with the GDPR. You can find the link to the data processing terms at https://business.safety.google/adsprocessorterms/
Audio & Video Introduction
Audio & Video Privacy Policy Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: Optimisation of our service performance
- 📓 Data processed: Data such as contact details, data on user behaviour, information about your device and your IP address may be stored. You will find more details on this further below in the corresponding data protection texts.
- 📅 Retention period: data generally remains stored for as long as it is necessary for the purpose of the service
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Are Audio and Video Elements?
We have embedded audio and video elements on our website so that you can watch videos or listen to music/podcasts directly via our website. The content is made available by service providers. All content is therefore also obtained from the corresponding servers of the providers.
These are embedded functional elements from platforms such as YouTube, Vimeo or Spotify. Use of these portals is generally free of charge, but paid content can also be published. With the help of these embedded elements you can listen to or watch the respective content via our website.
If you use audio or video elements on our website, personal data about you may also be transmitted to, processed and stored by the service providers.
Why Do We Use Audio & Video Elements on Our Website?
Of course we want to deliver the best offering to you on our website. And we are aware that content is no longer conveyed merely in text and static images. Instead of simply giving you a link to a video, we offer you audio and video formats directly on our website that are entertaining or informative and ideally both. That extends our service and makes it easier for you to access interesting content. Thus, in addition to our texts and images, we also offer video and/or audio content.
What Data Is Stored by Audio & Video Elements?
When you call up a page on our website that has, for example, an embedded video, your server connects to the server of the service provider. In doing so, data about you is also transferred to the third-party provider and stored there. Some data is collected and stored entirely irrespective of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system, and further general information about your device. Furthermore, most providers also obtain information about your web activity. This includes, for example, session duration, bounce rate, which button you clicked, or via which website you are using the service. All this information is usually stored via cookies or pixel tags (also called web beacons). Pseudonymised data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
Duration of the Data Processing
Exactly how long the data is stored on the servers of the third-party providers can be found either further below in the data protection text of the respective tool or in the provider's privacy policy. In principle, personal data is only ever processed for as long as is absolutely necessary for the provision of our services or products. This generally also applies to third-party providers. In most cases you can assume that certain data will be stored on the servers of third-party providers for several years. Data can be stored for varying lengths of time, especially in cookies. Some cookies are deleted as soon as you leave the website; others can be stored in your browser for a number of years.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works via the "Cookie Settings" link in the footer of every page, through which you can change your selection at any time. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. The lawfulness of the processing up to the point of withdrawal remains unaffected.
Since cookies are usually also used by the embedded audio and video functions on our site, you should also read our general privacy policy on cookies. In the privacy policies of the respective third-party providers you will find more detail about the handling and storage of your data.
Legal Basis
If you have consented to data about you being processed and stored by embedded audio and video elements, this consent counts as the legal basis for the data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or with other customers and business partners. We nevertheless only use the embedded audio and video elements insofar as you have given consent.
YouTube Privacy Policy
YouTube Privacy Policy Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: Optimisation of our service performance
- 📓 Data processed: Data such as contact details, data on user behaviour, information about your device and your IP address may be stored. You will find more details on this further below in this privacy policy.
- 📅 Retention period: data generally remains stored for as long as it is necessary for the purpose of the service
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Is YouTube?
We have built YouTube videos into our website. In this way we can present interesting videos to you directly on our site. YouTube is a video portal that has been a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you call up a page on our website that has a YouTube video embedded, your browser automatically connects to the servers of YouTube or Google. In doing so, various data is transferred (depending on the settings). Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all data processing in the European area.
In the following we want to explain to you in more detail which data is processed, why we have embedded YouTube videos, and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on and upload videos free of charge. Over the last few years YouTube has become one of the most important social media channels worldwide. So that we can display videos on our web page, YouTube provides a snippet of code that we have built into our site.
Why Do We Use YouTube Videos on Our Website?
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our web page. And of course interesting videos must not be missing. With the help of our embedded videos we make further helpful content available to you alongside our texts and images. In addition, our web page is more easily found on the Google search engine thanks to the embedded videos.
What Data Is Stored by YouTube?
We embed YouTube videos in extended data protection mode (youtube-nocookie.com). This means: when you open a page with an embedded video, no cookies are initially stored on your device. Connection data is, however, already transmitted to YouTube when the page loads, including your IP address, which is technically required in order to deliver the video player to your browser. As soon as you actively start a video, YouTube can store cookies on your device. If you are logged into your YouTube account, YouTube can usually attribute your interactions on our web page to your profile with the help of cookies. This includes data such as session duration, bounce rate, approximate location, technical information such as browser type, screen resolution or your internet provider. Further data can include contact details, any ratings, the sharing of content via social media, or adding to your favourites on YouTube.
If you are not logged into a Google account or a YouTube account, Google stores data with a unique identifier linked to your device, browser or app. In this way, for example, your preferred language setting is retained. But much interaction data cannot be stored, as fewer cookies are set.
In the following list we show cookies that were set in a browser during a test. On the one hand we show cookies that are set without a logged-in YouTube account. On the other hand we show cookies that are set with a logged-in account. The list cannot claim to be complete, because user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y313232775-1
Purpose: This cookie registers a unique ID in order to store statistics of the video watched.
Expiry date: after end of session
Name: PREF
Value: f1=50000000
Purpose: This cookie likewise registers your unique ID. Via PREF, Google receives statistics on how you use YouTube videos on our web page.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie registers your unique ID on mobile devices in order to track the GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user's bandwidth on our web pages (with embedded YouTube video).
Expiry date: after 8 months
Further cookies that are set when you are logged in with your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7313232775-
Purpose: This cookie is used to create a profile of your interests. The data is used for personalised advertisements.
Expiry date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user's consent to the use of various Google services. CONSENT also serves security purposes, in order to verify users and protect user data from unauthorised attacks.
Expiry date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile of your interests. This data helps to be able to display personalised advertising.
Expiry date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: Information about your login data is stored in this cookie.
Expiry date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and your device. It is used to create a profile of your interests.
Expiry date: after 2 years
Name: SID
Value: oQfNKjAsI313232775-
Purpose: This cookie stores your Google account ID and your last login time in digitally signed and encrypted form.
Expiry date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information on how you use the web page and which advertising you may have seen before visiting our site.
Expiry date: after 3 months
How Long and Where Is the Data Stored?
The data that YouTube receives and processes from you is stored on the Google servers. Most of these servers are located in America. At https://datacenters.google/ you can see exactly where the Google data centres are located. Your data is distributed across the servers. This means the data can be retrieved more quickly and is better protected against manipulation.
Google stores the collected data for varying lengths of time. Some data you can delete at any time, other data is automatically deleted after a limited time, and yet other data is stored by Google over a longer period. Some data (such as items from "My Activity", photos or documents, products) that is stored in your Google account remains stored until you delete it. Even if you are not logged into a Google account, you can delete some data that is linked to your device, browser or app.
How Can I Delete My Data or Prevent Data Storage?
In principle you can delete data in your Google account manually. With the automatic deletion function for location and activity data introduced in 2019, information is stored — depending on your decision — either for 3 or 18 months and then deleted.
Regardless of whether you have a Google account or not, you can configure your browser so that cookies from Google are deleted or deactivated. Depending on which browser you use, this works in different ways. Under the "Cookies" section you will find the corresponding links to the relevant instructions for the best-known browsers.
If you fundamentally do not want cookies, you can set up your browser so that it always informs you when a cookie is to be set. In this way you can decide for each individual cookie whether you allow it or not.
Legal Basis
If you have consented to data about you being processed and stored by embedded YouTube elements, this consent counts as the legal basis for the data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and good communication with you or with other customers and business partners. We nevertheless only use the embedded YouTube elements insofar as you have given consent. YouTube also sets cookies in your browser in order to store data. For this reason we recommend that you read our data protection text on cookies carefully and look at the privacy policy or the cookie policy of the respective service provider.
YouTube also processes data about you in the USA, among other places. YouTube, or rather Google, is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
You can find the Google Ads Data Processing Terms, which refer to the standard contractual clauses, at https://business.safety.google/adsprocessorterms/.
As YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to learn more about how your data is handled, we recommend the privacy policy at https://policies.google.com/privacy?hl=en.
Web Design Introduction
Web Design Privacy Policy Summary
- 👥 Data subjects: Visitors to the website
- 🤝 Purpose: Improvement of the user experience
- 📓 Data processed: Which data is processed depends heavily on the services used. Usually this involves, for example, IP address, technical data, language settings, browser version, screen resolution and name of the browser. You will find more details on this from the respective web design tools used.
- 📅 Retention period: depends on the tools used
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Is Web Design?
On our website we use various tools that serve our web design. Web design is not, as is often assumed, only about our website looking pretty, but also about functionality and performance. But of course the right look of a website is also one of the major goals of professional web design. Web design is a sub-area of media design and is concerned with the visual as well as the structural and functional design of a website. The goal is to improve your experience on our website with the help of web design. In web design jargon one speaks in this connection of user experience (UX) and usability. User experience refers to all the impressions and experiences that the website visitor has on a website. A sub-item of user experience is usability. This is about the user-friendliness of a website. The emphasis here is above all on content, sub-pages or products being clearly structured and on your finding what you are looking for easily and quickly. In order to offer you the best possible experience on our website, we also use so-called web design tools from third-party providers. In this privacy policy, the category "web design" therefore covers all services that improve our website in terms of design. These can be, for example, fonts, various plugins or other embedded web design functions.
Why Do We Use Web Design Tools?
How you take in information on a website depends very heavily on the structure, the functionality and the visual perception of the website. For that reason, good and professional web design has become ever more important for us too. We work constantly on improving our website and also see this as an extended service for you as a website visitor. Furthermore, an attractive and functioning website also has economic advantages for us. After all, you will only visit us and make use of our offerings if you feel entirely comfortable.
What Data Is Stored by Web Design Tools?
When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly which data is involved naturally depends heavily on the tools used. Further below you can see exactly which tools we use for our website. For more detailed information about the data processing, we also recommend that you read the respective privacy policy of the tools used. There you will usually find out which data is processed, whether cookies are used, and how long the data is retained. When loading the fonts we use, your IP address is transmitted to the provider's server, since this is technically required in order to deliver the font files to your browser.
Duration of the Data Processing
How long data is processed is very individual and depends on the web design elements used. If cookies are used, for example, the retention period can be as little as a minute but also a few years. Please inform yourself in this regard. For this we recommend, on the one hand, our general text section on cookies, as well as the privacy policies of the tools used. There you will as a rule find out exactly which cookies are used and what information is stored in them. In principle, data is only ever retained for as long as is necessary for the provision of the service. Where there are legal requirements, data may also be stored for longer.
Right to Object
You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works via the "Cookie Settings" link in the footer of every page, through which you can change your selection at any time. You can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. Among web design elements (mostly with fonts), however, there is also data that cannot be deleted quite so easily. This is the case when data is collected automatically directly upon a page being called up and transmitted to a third-party provider (such as Google). In that case please contact the support of the corresponding provider. In the case of Google you can reach support at https://support.google.com/?hl=en.
Legal Basis
The legal basis for the use of the web design tools we employ is Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in presenting our website consistently, professionally and functionally in the fonts we have licensed.
The fonts we use are loaded automatically when a page is called up and are technically required for the intended presentation of the website. We do not obtain prior consent for this. No cookies are set by the web design tools we use.
Information on specific web design tools can be found — where available — in the following sections.
Adobe Fonts Privacy Policy
On our website we use Adobe Fonts, a web font hosting service. The service provider is the American company Adobe Inc. For the European area, the Irish company Adobe Systems Software Ireland Companies, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland, is responsible.
Adobe also processes data about you in the USA, among other places. Adobe is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Adobe uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the standard contractual clauses, Adobe undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
You can find more information on the standard contractual clauses at Adobe at https://www.adobe.com/privacy/eudatatransfers.html.
You can find out more about the data processed through the use of Adobe Fonts in the privacy policy at https://www.adobe.com/privacy.html.
Closing Words
Congratulations! If you are reading these lines, you have really "fought" your way through our entire privacy policy, or at least scrolled this far. As you can see from the length of our privacy policy, we take the protection of your personal data anything but lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we want not only to tell you which data is processed, but also to convey the reasons behind the use of various software programs. As a rule, privacy policies sound very technical and legalistic. Since most of you, however, are neither web developers nor lawyers, we wanted to take a different path linguistically as well and explain the matter in simple and clear language. Of course, this is not always possible given the subject matter. For that reason the most important terms are explained in more detail at the end of the privacy policy.
If you have questions about data protection on our website, please do not hesitate to contact us or the responsible body. We wish you a pleasant time and hope to be able to welcome you back to our website soon.
All texts are protected by copyright.
Source: Privacy Policy created with the Privacy Policy Generator for Germany by AdSimple