Loading...
Loading...
chat.assistantName
Preamble
With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to simply as "data") we process for what purposes and to what extent within the scope of providing our application.
The terms used are not gender-specific.
Status: April 28, 2026
Table of Contents
Preamble
Controller
Overview of Processing
Legal Bases
Security Measures
Rights of Data Subjects
Contact and Inquiry Management
Web Analytics, Monitoring and Optimization
Online Marketing
Social Media Presences
Plug-ins and Embedded Functions and Content
Definitions
Controller
Hamed Elahi
Dokapexon Hamed Elahi
Heinrich-Hertz-Straße 61
98693 Ilmenau
Germany
Authorized Representative: Hamed Elahi
Email address: contact@dokapexon.de
Phone: +4917632389804
Overview of Processing
The following overview summarizes the types of processed data and the purposes of their processing and refers to the affected persons.
Types of Processed Data
Inventory data.
Contact data.
Content data.
Usage data.
Meta, communication and procedural data.
Categories of Data Subjects
Communication partners.
Users.
Purposes of Processing
Communication.
Reach measurement.
Tracking.
Conversion measurement.
Target group formation.
Organizational and administrative procedures.
Feedback.
Marketing.
Profiles with user-related information.
Provision of our online offering and user-friendliness.
Information technology infrastructure.
Public relations.
Legal Bases
Legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. If more specific legal bases are relevant in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring protection of personal data do not override those interests.
National Data Protection Regulations in Germany
In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission and automated decision-making in individual cases including profiling. In addition, state data protection laws of the individual federal states may apply.
Note on Applicability of GDPR and Swiss FADP
These privacy notices serve both as information under the Swiss Federal Act on Data Protection (FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that due to the broader territorial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP “processing” of “personal data”, “overriding interest”, and “particularly sensitive personal data”, the terms “processing” of “personal data”, “legitimate interest”, and “special categories of data” used in the GDPR are applied. The legal meaning of the terms remains determined under the Swiss FADP within its scope of application.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
The measures include in particular securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, securing availability, and their separation. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also consider the protection of personal data during the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.
Securing Online Connections via TLS/SSL Encryption Technology (HTTPS)
To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This serves as an indicator for users that their data is transmitted securely and encrypted.
Rights of Data Subjects
Rights of data subjects under the GDPR:
As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
Right to object:
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing.
Right to withdraw consent:
You have the right to withdraw any consent you have given at any time.
Right of access:
You have the right to request confirmation as to whether personal data concerning you are being processed and to obtain information about this data as well as further information and a copy of the data in accordance with the legal requirements.
Right to rectification:
In accordance with the legal requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
Right to erasure and restriction of processing:
In accordance with the legal requirements, you have the right to request that data concerning you be deleted without undue delay, or alternatively to request restriction of the processing of the data.
Right to data portability:
You have the right to receive data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
Right to lodge a complaint with a supervisory authority:
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media) as well as within the scope of existing user and business relationships, the information provided by the requesting persons is processed insofar as this is necessary to answer the contact requests and any requested measures.
Types of data processed:
Contact data (e.g. postal and email addresses or telephone numbers).
Content data (e.g. textual or visual messages and posts and the information relating to them, such as authorship information or time of creation).
Data subjects:
Communication partners.
Purposes of processing and legitimate interests:
Communication; organizational and administrative procedures; feedback (e.g. collecting feedback via online form); provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
Legal basis:
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Web Analysis, Monitoring and Optimization
Web analysis (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offering or its functions or content are most frequently used, or invite reuse. It is also possible for us to track which areas require optimization.
In addition to web analysis, we may also use test procedures to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e. data summarized for a usage process, may be created for these purposes and information may be stored in a browser or device and then read out. The collected information includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data to us or to the providers of the services we use, location data may also be processed.
In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users.
In general, no clear data of users (such as email addresses or names) are stored in the context of web analysis, A/B testing and optimization, but pseudonyms. This means that we and the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases:
If we ask users for their consent to use third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Reach measurement (e.g. access statistics, detection of returning visitors); profiles with user-related information (creation of user profiles); provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
Security measures:
IP masking (pseudonymization of the IP address).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Google Analytics:
We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It is used to assign analysis information to a device in order to recognize which content users have accessed within one or more usage processes, which search terms they have used, accessed again, or interacted with our online offering.
The time of use and its duration are also stored, as well as the sources of users who refer to our online offering and technical aspects of their devices and browsers.
Pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU data traffic, IP address data are used exclusively for this derivation of geolocation data before being immediately deleted. They are not logged, are not accessible and are not used for any further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before traffic is forwarded to Analytics servers for processing.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Consent (Art. 6(1) sentence 1 lit. a GDPR)
Website: https://marketingplatform.google.com/intl/de/about/analytics/
Security measures: IP masking (pseudonymization of the IP address)
Privacy policy: https://policies.google.com/privacy
Data processing agreement: https://business.safety.google/adsprocessorterms/
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms)
Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de
Ad personalization settings: https://myadcenter.google.com/personalizationoff
Further information: https://business.safety.google/adsservices/
Online Marketing
We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “content”) based on users’ potential interests and measuring their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (the so-called “cookie”) or similar procedures are used by means of which the information relevant for displaying the aforementioned content is stored about the user. This may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical information such as the browser used, the computer system used and information on usage times and functions used. If users have consented to the collection of their location data, these may also be processed.
In addition, users’ IP addresses are stored. However, we use available IP masking procedures (i.e. pseudonymization by shortening the IP address) for user protection.
In general, no clear data of users (such as email addresses or names) are stored as part of the online marketing process, but pseudonyms. This means that we and the providers of the online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
The statements in the profiles are usually stored in cookies or by means of similar procedures. These cookies can later generally be read on other websites that use the same online marketing procedure and analyzed for the purpose of displaying content, as well as supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases, clear data may be assigned to the profiles, primarily if users are, for example, members of a social network whose online marketing procedure we use and the network links user profiles with the aforementioned information. We ask users to note that they can make additional agreements with the providers, for example by consenting during registration.
We generally only receive aggregated information about the success of our advertisements. However, within the framework of so-called conversion measurement, we can check which of our online marketing procedures led to a so-called conversion, i.e. for example to a contract conclusion with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless otherwise stated, please assume that cookies used are stored for a period of two years.
Notes on legal bases:
If we ask users for their consent to the use of third-party providers, the legal basis for data processing is permission (consent). Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Notes on withdrawal and objection:
We refer to the privacy notices of the respective providers and the objection options (so-called “opt-out”) specified for the providers. If no explicit opt-out option is specified, you can disable cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for specific regions:
a) Europe: https://www.youronlinechoices.eu
b) Canada: https://youradchoices.ca/
c) USA: https://optout.aboutads.info/
d) Cross-region: https://optout.aboutads.info
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Reach measurement (e.g. access statistics, detection of returning visitors); tracking (e.g. interest-/behavior-based profiling, use of cookies); audience creation; marketing; profiles with user-related information (creation of user profiles); conversion measurement (measurement of the effectiveness of marketing measures).
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years. (Cookies and similar storage technologies may be stored on users’ devices for up to two years, unless otherwise specified.)
Security measures:
IP masking (pseudonymization of the IP address).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Additional Information on Processing Activities, Procedures, and Services Google Ads and Conversion Measurement
We use online marketing procedures such as Google Ads for the placement of content and advertisements within the service provider’s advertising network (e.g., in search results, videos, or websites) so that they are displayed to users who are likely interested in the advertisements.
We also measure conversions, i.e., whether users interacted with the advertisements and used the promoted offers (so-called “conversions”). We only receive anonymized information and no personal information about individual users.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR)
Website: https://marketingplatform.google.com
Privacy Policy: https://policies.google.com/privacy
Third-country transfer basis: Data Privacy Framework (DPF)
Further information: https://business.safety.google/adsservices/
Controller-to-controller data processing terms and Standard Contractual Clauses: https://business.safety.google/adscontrollerterms
Presences on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to provide information about us.
We point out that user data may be processed outside the European Union. This may result in risks for users, for example because enforcement of user rights could be more difficult.
Furthermore, user data within social networks are generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and the resulting interests of users. These profiles may in turn be used, for example, to display advertisements within and outside the networks that presumably correspond to the interests of users. For this purpose, cookies are generally stored on users’ computers in which the usage behavior and interests of users are stored. In addition, data may be stored in the usage profiles independently of the devices used by users (in particular if they are members of the respective platforms and are logged in there).
For a detailed presentation of the respective processing operations and the objection options (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the providers have access to the user data and can directly take appropriate measures and provide information. If you still need help, you can contact us.
Types of data processed:
Contact data (e.g. postal and email addresses or telephone numbers);
Content data (e.g. textual or visual messages and posts and the information relating to them, such as authorship information or time of creation);
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions);
Inventory data (e.g. full name, residential address, contact information, customer number, etc.);
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Communication; feedback (e.g. collecting feedback via online form); public relations; provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
Storage and deletion:
Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
Legal basis:
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Social network, enables sharing photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages;
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.instagram.com;
Privacy policy: https://privacycenter.instagram.com/policy/;
Basis for third-country transfers: Data Privacy Framework (DPF).
Facebook Pages
Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page (“fan page”). This includes, in particular, information about user behavior (e.g. viewed or interacted content, actions performed) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook’s data policy: https://www.facebook.com/privacy/policy/.
Facebook also uses this data to provide us with statistical evaluations via the “Page Insights” service, which provide information about how people interact with our page and its content. The basis for this is an agreement with Facebook (“Information on Page Insights”: https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Users can therefore direct requests for information or deletion directly to Facebook. The rights of users (in particular access, deletion, objection, complaint to a supervisory authority) remain unaffected. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). For further processing, including a possible transfer to Meta Platforms Inc. in the USA, Meta Platforms Ireland Limited is solely responsible.
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.facebook.com;
Privacy policy: https://www.facebook.com/privacy/policy/;
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not further processing) of data of visitors used to create “Page Insights” (statistics) of our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles such as job function, country, industry, seniority level, company size and employment status.
Privacy information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
We have concluded a special agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which regulates, in particular, security measures and LinkedIn’s commitment to fulfill data subject rights (e.g. users can direct access or deletion requests directly to LinkedIn). The rights of users (in particular the right of access, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, an EU-based company. Further processing of the data is exclusively the responsibility of LinkedIn Ireland Unlimited Company, in particular with regard to the transfer of data to the parent company LinkedIn Corporation in the USA.
Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.linkedin.com;
Privacy policy: https://www.linkedin.com/legal/privacy-policy;
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa);
Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Social network, enables sharing photos, commenting, favoriting and curating posts, sending messages, subscribing to profiles;
Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.pinterest.com;
Privacy policy: https://policy.pinterest.com/de/privacy-policy.
Snapchat
Social network, enables sharing photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages;
Service provider: Snap Inc., 3000 31st Street, Santa Monica, California 90405 USA;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.snapchat.com/;
Privacy policy: https://www.snap.com/de-DE/privacy/privacy-policy;
Basis for third-country transfers: Standard Contractual Clauses (https://www.snap.com/en-US/terms/standard-contractual-clauses).
Threads
Social network;
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://www.threads.com/;
Privacy policy: https://help.instagram.com/515230437301944.
X (formerly Twitter)
Social network;
Service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://x.com;
Privacy policy: https://x.com/de/privacy.
YouTube
Social network and video platform;
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Privacy policy: https://policies.google.com/privacy;
Basis for third-country transfers: Data Privacy Framework (DPF);
Opt-out option: https://myadcenter.google.com/personalizationoff.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process users’ IP addresses, as they could not send the content to users’ browsers without the IP address. The IP address is therefore required for displaying this content or functions. We strive to use only content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Through these “pixel tags”, information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may also be stored in cookies on users’ devices and may include technical information about the browser and operating system, referring websites, visit time and other information about the use of our online offering, but may also be linked with such information from other sources.
Notes on legal bases:
If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. interest in efficient, economical and user-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
Types of data processed:
Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
Data subjects:
Users (e.g. website visitors, users of online services).
Purposes of processing and legitimate interests:
Provision of our online services and user-friendliness.
Storage and deletion:
Deletion in accordance with the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
Legal basis:
Consent (Art. 6(1) sentence 1 lit. a GDPR).
Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR).
Further Information on Processing Operations, Procedures and Services
Google Fonts (retrieval from Google servers)
Retrieval of fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation and consideration of possible licensing restrictions. The font provider is informed of the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) are transmitted, which are necessary for providing the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the USA.
When visiting our online offering, users’ browsers send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the Internet, (2) the requested URL on the Google server and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of website visitors, as well as the referrer URL (i.e. the webpage on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers and are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent must adapt the font for the respective browser type. The user agent is primarily logged and used for debugging and to generate aggregated usage statistics with which the popularity of font families is measured. These aggregated usage statistics are published on the Google Fonts “Analytics” page. Finally, the referrer URL is logged so that the data can be used for production maintenance and an aggregated report on top integrations based on the number of font requests can be generated. According to Google, none of the information collected by Google Fonts is used to create profiles of end users or to serve targeted advertising.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
Legal basis: Legitimate interests (Art. 6(1) sentence 1 lit. f GDPR);
Website: https://fonts.google.com/;
Privacy policy: https://policies.google.com/privacy;
Basis for third-country transfers: Data Privacy Framework (DPF).
Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
Definitions
In this section, you will find an overview of the terminology used in this privacy policy. Where the terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.
Inventory data:
Inventory data includes essential information required for identifying and managing contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic information such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Inventory data form the basis for any formal interaction between persons and services, institutions or systems by enabling clear assignment and communication.
Content data:
Content data includes information generated in the course of creating, editing and publishing content of all kinds. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data are not limited to the actual content itself but also include metadata that provide information about the content itself, such as tags, descriptions, author information and publication dates.
Contact data:
Contact data are essential information that enable communication with individuals or organizations. They include, among other things, telephone numbers, postal addresses and email addresses, as well as communication means such as social media handles and instant messaging identifiers.
Conversion measurement:
Conversion measurement (also referred to as “visit action evaluation”) is a procedure used to determine the effectiveness of marketing measures. As a rule, a cookie is stored on users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, we can track whether advertisements placed by us on other websites were successful.
Meta, communication and procedural data:
Meta, communication and procedural data are categories that contain information about the way data are processed, transmitted and managed. Meta data, also known as data about data, include information that describes the context, origin and structure of other data. They may include information on file size, creation date, document author and modification histories.
Communication data record the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths.
Procedural data describe the processes and workflows within systems or organizations, including workflow documentation, transaction logs and activity logs, as well as audit logs used to track and review processes.
Usage data:
Usage data refers to information that records how users interact with digital products, services or platforms. This data includes a wide range of information showing how users use applications, which functions they prefer, how long they stay on certain pages and which paths they take through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information and location data. They are particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content and improving products or services. In addition, usage data play a crucial role in identifying trends, preferences and potential problem areas within digital offerings.
Personal data:
“Personal data” are any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Profiles with user-related information:
The processing of “profiles with user-related information”, or simply “profiles”, includes any type of automated processing of personal data consisting of the use of such personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information regarding demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behavior on a website or location). Cookies and web beacons are often used for profiling purposes.
Reach measurement:
Reach measurement (also referred to as web analytics) serves to evaluate visitor flows of an online offering and may include behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online offerings can, for example, recognize at what time users visit their websites and which content they are interested in. This enables them to better adapt website content to the needs of their visitors. Pseudonymous cookies and web beacons are often used for reach analysis in order to recognize returning visitors and obtain more precise analyses of the use of an online offering.
Tracking:
“Tracking” refers to the ability to track users’ behavior across multiple online offerings. As a rule, behavior and interest information regarding the online offerings used are stored in cookies or on servers of the tracking technology providers (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to match their interests.
Controller:
A “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
Processing:
“Processing” is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, evaluating, storing, transmitting or deleting.
Audience creation:
Audience creation (English “Custom Audiences”) refers to the creation of target groups for advertising purposes, e.g. for displaying advertisements. For example, based on a user’s interest in certain products or topics on the Internet, it can be concluded that the user is interested in advertisements for similar products or the online shop in which they viewed the products.
“Lookalike audiences” (or similar target groups) refer to displaying suitable content to users whose profiles or interests are presumed to correspond to the users for whom the profiles were created. Cookies and web beacons are generally used for the creation of custom audiences and lookalike audiences.