Loading...
Loading...
chat.assistantName
Preamble
With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to simply as "data") we process for what purposes and to what extent within the scope of providing our application.
The terms used are not gender-specific.
Status: April 21, 2026
Table of Contents
Preamble
Controller
Overview of Processing
Legal Bases
Security Measures
Rights of Data Subjects
Business Services
Use of Online Platforms for Offering and Distribution
Payment Methods
Provision of Online Services and Web Hosting
Contact and Inquiry Management
Web Analytics, Monitoring and Optimization
Online Marketing
Social Media Presences
Plug-ins and Embedded Functions and Content
Definitions
Controller
Hamed Elahi
Dokapexon Hamed Elahi
Heinrich-Hertz-Straße 61
98693 Ilmenau
Germany
Authorized Representative: Hamed Elahi
Email address: contact@dokapexon.de
Phone: +4917632389804
Overview of Processing
The following overview summarizes the types of processed data and the purposes of their processing and refers to the affected persons.
Types of Processed Data
Inventory data.
Contact data.
Content data.
Usage data.
Meta, communication and procedural data.
Categories of Data Subjects
Communication partners.
Users.
Purposes of Processing
Communication.
Reach measurement.
Tracking.
Conversion measurement.
Target group formation.
Organizational and administrative procedures.
Feedback.
Marketing.
Profiles with user-related information.
Provision of our online offering and user-friendliness.
Information technology infrastructure.
Public relations.
Legal Bases
Legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. If more specific legal bases are relevant in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring protection of personal data do not override those interests.
National Data Protection Regulations in Germany
In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission and automated decision-making in individual cases including profiling. In addition, state data protection laws of the individual federal states may apply.
Note on Applicability of GDPR and Swiss FADP
These privacy notices serve both as information under the Swiss Federal Act on Data Protection (FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that due to the broader territorial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP “processing” of “personal data”, “overriding interest”, and “particularly sensitive personal data”, the terms “processing” of “personal data”, “legitimate interest”, and “special categories of data” used in the GDPR are applied. The legal meaning of the terms remains determined under the Swiss FADP within its scope of application.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
The measures include in particular securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, securing availability, and their separation. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also consider the protection of personal data during the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.
Securing Online Connections via TLS/SSL Encryption Technology (HTTPS)
To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This serves as an indicator for users that their data is transmitted securely and encrypted.
Rights of Data Subjects
Rights of data subjects under the GDPR:
As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
Right to object:
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing.
Right to withdraw consent:
You have the right to withdraw any consent you have given at any time.
Right of access:
You have the right to request confirmation as to whether personal data concerning you are being processed and to obtain information about this data as well as further information and a copy of the data in accordance with the legal requirements.
Right to rectification:
In accordance with the legal requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
Right to erasure and restriction of processing:
In accordance with the legal requirements, you have the right to request that data concerning you be deleted without undue delay, or alternatively to request restriction of the processing of the data.
Right to data portability:
You have the right to receive data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
Right to lodge a complaint with a supervisory authority:
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers, and other cooperation partners (collectively referred to as “contractual partners”), for the purposes of initiating, performing, and fulfilling contractual relationships as well as comparable legal relationships. This also includes pre-contractual measures taken upon request and communication related to such relationships.
Processing is carried out in particular for the performance of our contractual obligations, including primary and ancillary obligations. This includes the provision of agreed services, update and information obligations, handling of warranty claims and service disruptions, processing of withdrawals, termination of ongoing contractual relationships, reversals, refunds, and the handling of other contractual declarations and inquiries. Both one-time contracts and ongoing contractual relationships are covered.
In particular, we process master data (e.g., name, address, company name where applicable), contact data (e.g., email address, telephone number), contract and service data (e.g., subject matter of the contract, contract duration, order or transaction number), usage and performance data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of performing an assignment.
We also process personal data to safeguard our rights and to comply with legal obligations. This includes, in particular, commercial and tax retention obligations, documentation requirements, and, where applicable, obligations to provide evidence and accountability. Processing may also be carried out on the basis of our legitimate interests in proper business operations, internal administration, risk management, IT security, and the protection of our business operations and contractual partners against misuse, threats to data, trade secrets, and other legal interests. This may include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax advisors, legal advisors, or other agents, insofar as this is necessary for contract performance or to comply with legal obligations.
Personal data will only be disclosed to third parties where this is necessary for the performance of the contract, for pre-contractual measures, to safeguard legitimate interests, or to fulfill legal obligations. Any further processing, in particular for marketing purposes, will be addressed separately in this Privacy Policy.
We inform contractual partners of the data required in each individual case at the time of data collection, for example through appropriate labeling in online forms or during personal contact.
Personal data will be deleted as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations apply. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in connection with a specific assignment will be deleted after completion of the assignment and expiry of any retention periods, unless further legal or contractual obligations to retain such data exist.
The legal basis for processing is Article 6(1)(b) GDPR for the performance of pre-contractual measures and contractual relationships, Article 6(1)(c) GDPR for compliance with legal obligations, and, where applicable, Article 6(1)(f) GDPR based on our legitimate interests as described above.
Online Shop, Order Forms, E-Commerce, and Fulfillment:
We process customer data in order to enable them to select, purchase, or order products, goods, and related services, as well as their payment and delivery or execution. Where necessary for order fulfillment, we engage service providers, in particular postal, freight, and shipping companies, to carry out delivery or performance. For payment processing, we use banks and payment service providers.
Required information is identified as such within the ordering process and includes the data necessary for delivery, provision, and billing, as well as contact information for any follow-up communication.
Legal basis: Article 6(1)(b) GDPR.
Use of Online Platforms for Offering and Distribution
We offer our services on online platforms operated by third-party providers. In this context, the privacy policies of the respective platform providers apply in addition to this Privacy Policy. This applies in particular with regard to payment processing and procedures used on such platforms for reach measurement and interest-based marketing.
Legal bases: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
Payment Processing via Google Play Store:
When payments are made via the Google Play Store (Google LLC), payment data is processed directly by the respective provider. The application does not receive any direct payment information (such as credit card details), but only confirmation of payment.
The processed data includes:
Order ID
Purchase date
Type of purchased product
Payment status (successful or failed)
Payment processing is carried out exclusively by the respective app store providers. Google LLC is responsible for the processing of payment data. The privacy policies and terms of use of the respective providers apply.
Further information can be found in Google’s Privacy Policy.
Legal basis: Article 6(1)(b) GDPR.
Retention: Payment-related information transmitted to us (e.g., order ID, purchase date) is stored in accordance with statutory retention periods and subsequently deleted.
Data subject rights: You have the right to request access to your stored data and exercise other rights described in this Privacy Policy. For payment-related inquiries, you may also contact the respective provider.
Payment Methods
Within the context of contractual and other legal relationships, based on legal obligations or our legitimate interests, we offer efficient and secure payment options and use banks and other payment service providers (collectively referred to as “payment service providers”).
Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, ensuring that transmitted data is protected from unauthorized access.
The data processed by payment service providers includes master data (e.g., name, address), bank data (e.g., account numbers, credit card numbers), authentication data (e.g., passwords, TANs), and transaction-related data. This data is necessary for processing transactions.
We do not receive account or credit card information, but only confirmation or rejection of payment. Payment service providers may transfer data to credit agencies for identity and creditworthiness checks.
The terms and privacy policies of the respective payment service providers apply.
Legal bases: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
Google Pay:
Payment service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://pay.google.com/
Privacy Policy: https://policies.google.com/privacy
Legal basis: Article 6(1)(b) GDPR.
Provision of Online Services and Web Hosting
We process users’ data in order to provide our online services. For this purpose, we process the user’s IP address, which is necessary to deliver content and functionality to the user’s browser or device.
Processed data includes usage data, metadata, communication data, and log data.
Processing purposes include:
Provision of our online services
Ensuring functionality and user-friendliness
IT infrastructure operation
Security measures
Legal basis: Article 6(1)(f) GDPR.
Hosting:
For the provision of our online services, we use storage space, computing capacity, and software rented or otherwise obtained from a hosting provider.
Collection of Access Data and Log Files:
Access to our online services is logged in server log files. These may include:
Accessed pages and files
Date and time of access
Data volume transferred
Browser type and version
Operating system
Referrer URL
IP address
Requesting provider
Log files are used for security purposes (e.g., preventing server overload or DDoS attacks) and to ensure system stability.
Log file data is stored for a maximum of 30 days and then deleted or anonymized. Data required for evidentiary purposes is excluded from deletion until the respective incident has been fully resolved.
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media) as well as within the scope of existing user and business relationships, the information provided by the requesting persons is processed insofar as this is necessary to answer the contact requests and any requested measures.
Types of data processed:
Contact data (e.g. postal and email addresses or telephone numbers).
Content data (e.g. textual or visual messages and posts and the information relating to them, such as authorship information or time of creation).
Data subjects:
Communication partners.
Purposes of processing and legitimate interests:
Communication; organizational and administrative procedures; feedback (e.g. collecting feedback via online form); provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
Legal basis:
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Web Analysis, Monitoring and Optimization
Web analysis (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offering or its functions or content are most frequently used, or invite reuse. It is also possible for us to track which areas require optimization.
In addition to web analysis, we may also use test procedures to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e. data summarized for a usage process, may be created for these purposes and information may be stored in a browser or device and then read out. The collected information includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data to us or to the providers of the services we use, location data may also be processed.
In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users.
In general, no clear data of users (such as email addresses or names) are stored in the context of web analysis, A/B testing and optimization, but pseudonyms. This means that we and the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases:
If we ask users for their consent to use third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Reach measurement (e.g. access statistics, detection of returning visitors); profiles with user-related information (creation of user profiles); provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
Security measures:
IP masking (pseudonymization of the IP address).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Google Analytics:
We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It is used to assign analysis information to a device in order to recognize which content users have accessed within one or more usage processes, which search terms they have used, accessed again, or interacted with our online offering.
The time of use and its duration are also stored, as well as the sources of users who refer to our online offering and technical aspects of their devices and browsers.
Pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU data traffic, IP address data are used exclusively for this derivation of geolocation data before being immediately deleted. They are not logged, are not accessible and are not used for any further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before traffic is forwarded to Analytics servers for processing.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Consent (Art. 6(1) sentence 1 lit. a GDPR)
Website: https://marketingplatform.google.com/intl/de/about/analytics/
Security measures: IP masking (pseudonymization of the IP address)
Privacy policy: https://policies.google.com/privacy
Data processing agreement: https://business.safety.google/adsprocessorterms/
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms)
Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de
Ad personalization settings: https://myadcenter.google.com/personalizationoff
Further information: https://business.safety.google/adsservices/
Online Marketing
We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “content”) based on users’ potential interests and measuring their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (the so-called “cookie”) or similar procedures are used by means of which the information relevant for displaying the aforementioned content is stored about the user. This may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical information such as the browser used, the computer system used and information on usage times and functions used. If users have consented to the collection of their location data, these may also be processed.
In addition, users’ IP addresses are stored. However, we use available IP masking procedures (i.e. pseudonymization by shortening the IP address) for user protection.
In general, no clear data of users (such as email addresses or names) are stored as part of the online marketing process, but pseudonyms. This means that we and the providers of the online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
The statements in the profiles are usually stored in cookies or by means of similar procedures. These cookies can later generally be read on other websites that use the same online marketing procedure and analyzed for the purpose of displaying content, as well as supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases, clear data may be assigned to the profiles, primarily if users are, for example, members of a social network whose online marketing procedure we use and the network links user profiles with the aforementioned information. We ask users to note that they can make additional agreements with the providers, for example by consenting during registration.
We generally only receive aggregated information about the success of our advertisements. However, within the framework of so-called conversion measurement, we can check which of our online marketing procedures led to a so-called conversion, i.e. for example to a contract conclusion with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless otherwise stated, please assume that cookies used are stored for a period of two years.
Notes on legal bases:
If we ask users for their consent to the use of third-party providers, the legal basis for data processing is permission (consent). Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Notes on withdrawal and objection:
We refer to the privacy notices of the respective providers and the objection options (so-called “opt-out”) specified for the providers. If no explicit opt-out option is specified, you can disable cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for specific regions:
a) Europe: https://www.youronlinechoices.eu
b) Canada: https://youradchoices.ca/
c) USA: https://optout.aboutads.info/
d) Cross-region: https://optout.aboutads.info
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Reach measurement (e.g. access statistics, detection of returning visitors); tracking (e.g. interest-/behavior-based profiling, use of cookies); audience creation; marketing; profiles with user-related information (creation of user profiles); conversion measurement (measurement of the effectiveness of marketing measures).
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years. (Cookies and similar storage technologies may be stored on users’ devices for up to two years, unless otherwise specified.)
Security measures:
IP masking (pseudonymization of the IP address).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Additional Information on Processing Activities, Procedures, and Services Google Ads and Conversion Measurement
We use online marketing procedures such as Google Ads for the placement of content and advertisements within the service provider’s advertising network (e.g., in search results, videos, or websites) so that they are displayed to users who are likely interested in the advertisements.
We also measure conversions, i.e., whether users interacted with the advertisements and used the promoted offers (so-called “conversions”). We only receive anonymized information and no personal information about individual users.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR)
Website: https://marketingplatform.google.com
Privacy Policy: https://policies.google.com/privacy
Third-country transfer basis: Data Privacy Framework (DPF)
Further information: https://business.safety.google/adsservices/
Controller-to-controller data processing terms and Standard Contractual Clauses: https://business.safety.google/adscontrollerterms
Presences on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to provide information about us.
We point out that user data may be processed outside the European Union. This may result in risks for users, for example because enforcement of user rights could be more difficult.
Furthermore, user data within social networks are generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and the resulting interests of users. These profiles may in turn be used, for example, to display advertisements within and outside the networks that presumably correspond to the interests of users. For this purpose, cookies are generally stored on users’ computers in which the usage behavior and interests of users are stored. In addition, data may be stored in the usage profiles independently of the devices used by users (in particular if they are members of the respective platforms and are logged in there).
For a detailed presentation of the respective processing operations and the objection options (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the providers have access to the user data and can directly take appropriate measures and provide information. If you still need help, you can contact us.
Types of data processed:
Contact data (e.g. postal and email addresses or telephone numbers);
Content data (e.g. textual or visual messages and posts and the information relating to them, such as authorship information or time of creation);
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions);
Inventory data (e.g. full name, residential address, contact information, customer number, etc.);
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Communication; feedback (e.g. collecting feedback via online form); public relations; provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
Storage and deletion:
Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
Legal basis:
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Social network, enables sharing photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages;
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.instagram.com;
Privacy policy: https://privacycenter.instagram.com/policy/;
Basis for third-country transfers: Data Privacy Framework (DPF).
Facebook Pages
Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page (“fan page”). This includes, in particular, information about user behavior (e.g. viewed or interacted content, actions performed) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook’s data policy: https://www.facebook.com/privacy/policy/.
Facebook also uses this data to provide us with statistical evaluations via the “Page Insights” service, which provide information about how people interact with our page and its content. The basis for this is an agreement with Facebook (“Information on Page Insights”: https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Users can therefore direct requests for information or deletion directly to Facebook. The rights of users (in particular access, deletion, objection, complaint to a supervisory authority) remain unaffected. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). For further processing, including a possible transfer to Meta Platforms Inc. in the USA, Meta Platforms Ireland Limited is solely responsible.
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.facebook.com;
Privacy policy: https://www.facebook.com/privacy/policy/;
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not further processing) of data of visitors used to create “Page Insights” (statistics) of our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles such as job function, country, industry, seniority level, company size and employment status.
Privacy information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
We have concluded a special agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which regulates, in particular, security measures and LinkedIn’s commitment to fulfill data subject rights (e.g. users can direct access or deletion requests directly to LinkedIn). The rights of users (in particular the right of access, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, an EU-based company. Further processing of the data is exclusively the responsibility of LinkedIn Ireland Unlimited Company, in particular with regard to the transfer of data to the parent company LinkedIn Corporation in the USA.
Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.linkedin.com;
Privacy policy: https://www.linkedin.com/legal/privacy-policy;
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa);
Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Social network, enables sharing photos, commenting, favoriting and curating posts, sending messages, subscribing to profiles;
Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.pinterest.com;
Privacy policy: https://policy.pinterest.com/de/privacy-policy.
Snapchat
Social network, enables sharing photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages;
Service provider: Snap Inc., 3000 31st Street, Santa Monica, California 90405 USA;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.snapchat.com/;
Privacy policy: https://www.snap.com/de-DE/privacy/privacy-policy;
Basis for third-country transfers: Standard Contractual Clauses (https://www.snap.com/en-US/terms/standard-contractual-clauses).
Threads
Social network;
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.threads.com/;
Privacy policy: https://help.instagram.com/515230437301944.
X (formerly Twitter)
Social network;
Service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://x.com;
Privacy policy: https://x.com/de/privacy.
YouTube
Social network and video platform;
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Privacy policy: https://policies.google.com/privacy;
Basis for third-country transfers: Data Privacy Framework (DPF);
Opt-out option: https://myadcenter.google.com/personalizationoff.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process users’ IP addresses, as they could not send the content to users’ browsers without the IP address. The IP address is therefore required for displaying this content or functions. We strive to use only content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Through these “pixel tags”, information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may also be stored in cookies on users’ devices and may include technical information about the browser and operating system, referring websites, visit time and other information about the use of our online offering, but may also be linked with such information from other sources.
Notes on legal bases:
If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Google Fonts (retrieval from Google servers)
Retrieval of fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation and consideration of possible licensing restrictions. The font provider is informed of the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) are transmitted, which are necessary for providing the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the USA.
When visiting our online offering, users’ browsers send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the Internet, (2) the requested URL on the Google server and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of website visitors, as well as the referrer URL (i.e. the webpage on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers and are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent must adapt the font for the respective browser type. The user agent is primarily logged and used for debugging and to generate aggregated usage statistics with which the popularity of font families is measured. These aggregated usage statistics are published on the Google Fonts “Analytics” page. Finally, the referrer URL is logged so that the data can be used for production maintenance and an aggregated report on top integrations based on the number of font requests can be generated. According to Google, none of the information collected by Google Fonts is used to create profiles of end users or to serve targeted advertising.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://fonts.google.com/;
Privacy policy: https://policies.google.com/privacy;
Basis for third-country transfers: Data Privacy Framework (DPF).
Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
Definitions
In this section, you will find an overview of the terminology used in this privacy policy. Where the terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.
Inventory data:
Inventory data includes essential information required for identifying and managing contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic information such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Inventory data form the basis for any formal interaction between persons and services, institutions or systems by enabling clear assignment and communication.
Content data:
Content data includes information generated in the course of creating, editing and publishing content of all kinds. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data are not limited to the actual content itself but also include metadata that provide information about the content itself, such as tags, descriptions, author information and publication dates.
Contact data:
Contact data are essential information that enable communication with individuals or organizations. They include, among other things, telephone numbers, postal addresses and email addresses, as well as communication means such as social media handles and instant messaging identifiers.
Conversion measurement:
Conversion measurement (also referred to as “visit action evaluation”) is a procedure used to determine the effectiveness of marketing measures. As a rule, a cookie is stored on users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, we can track whether advertisements placed by us on other websites were successful.
Meta, communication and procedural data:
Meta, communication and procedural data are categories that contain information about the way data are processed, transmitted and managed. Meta data, also known as data about data, include information that describes the context, origin and structure of other data. They may include information on file size, creation date, document author and modification histories.
Communication data record the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths.
Procedural data describe the processes and workflows within systems or organizations, including workflow documentation, transaction logs and activity logs, as well as audit logs used to track and review processes.
Usage data:
Usage data refers to information that records how users interact with digital products, services or platforms. This data includes a wide range of information showing how users use applications, which functions they prefer, how long they stay on certain pages and which paths they take through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information and location data. They are particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content and improving products or services. In addition, usage data play a crucial role in identifying trends, preferences and potential problem areas within digital offerings.
Personal data:
“Personal data” are any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Profiles with user-related information:
The processing of “profiles with user-related information”, or simply “profiles”, includes any type of automated processing of personal data consisting of the use of such personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information regarding demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behavior on a website or location). Cookies and web beacons are often used for profiling purposes.
Reach measurement:
Reach measurement (also referred to as web analytics) serves to evaluate visitor flows of an online offering and may include behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online offerings can, for example, recognize at what time users visit their websites and which content they are interested in. This enables them to better adapt website content to the needs of their visitors. Pseudonymous cookies and web beacons are often used for reach analysis in order to recognize returning visitors and obtain more precise analyses of the use of an online offering.
Tracking:
“Tracking” refers to the ability to track users’ behavior across multiple online offerings. As a rule, behavior and interest information regarding the online offerings used are stored in cookies or on servers of the tracking technology providers (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to match their interests.
Controller:
A “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
Processing:
“Processing” is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, evaluating, storing, transmitting or deleting.
Audience creation:
Audience creation (English “Custom Audiences”) refers to the creation of target groups for advertising purposes, e.g. for displaying advertisements. For example, based on a user’s interest in certain products or topics on the Internet, it can be concluded that the user is interested in advertisements for similar products or the online shop in which they viewed the products.
“Lookalike audiences” (or similar target groups) refer to displaying suitable content to users whose profiles or interests are presumed to correspond to the users for whom the profiles were created. Cookies and web beacons are generally used for the creation of custom audiences and lookalike audiences.