Privacy Policy
Table of Contents
Introduction and Overview
We have drafted this Privacy Policy (version 17.11.2025-113080663) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (in short: data) we as controller – and the processors commissioned by us (e.g. hosting providers) – process, will process in the future, and which lawful options you have. All terms used are to be understood as gender-neutral.
In short: We inform you comprehensively about the data we process about you.
Privacy policies usually sound very technical and use legal terminology. This Privacy Policy, however, is intended to describe the most important points to you as simply and transparently as possible. Where it serves transparency, technical terms are explained in a user-friendly way, links to further information are provided, and graphics may be used. In clear and simple language, we inform you that, in the course of our business activities, we only process personal data where there is an appropriate legal basis. That is certainly not possible if one provides statements that are as brief, unclear and legal-technical as possible – as is often standard on the internet when it comes to data protection. We hope you find the following explanations interesting and informative and that there may be one or two pieces of information you did not know before.
If you still have questions, we kindly ask you to contact the controller named below or in the imprint, to follow the available links and to obtain further information from third-party websites. Our contact details can of course also be found in the imprint.
Scope of Application
This Privacy Policy applies to all personal data processed by us in our company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4(1) GDPR such as, for example, the name, email address and postal address of a person. The processing of personal data enables us to provide and bill our services and products – whether online or offline. The scope of this Privacy Policy covers:
In short: This Privacy Policy applies to all areas in which personal data in the company is processed in a structured manner via the channels mentioned. Should we enter into legal relations with you outside these channels, we will inform you separately where appropriate.
Legal Bases
In the following Privacy Policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, which allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the access point to EU law, at
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
We process your data in order to fulfil a contract or pre-contractual obligations with you. For example, if we conclude a purchase contract with you, we need personal information beforehand.
If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
In the case of legitimate interests that do not override your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website in a secure and economically efficient manner. This processing is therefore a legitimate interest.
Further legal bases such as the performance of a task carried out in the public interest or in the exercise of official authority, as well as the protection of vital interests, generally do not apply to us. If such a legal basis should nevertheless be relevant, it will be indicated at the appropriate place.
In addition to the EU Regulation, national laws also apply:
Where additional regional or national laws apply, we will inform you in the following sections.
Contact Details of the Controller
If you have any questions regarding data protection or the processing of personal data, you will find the contact details of the controller pursuant to Article 4(7) GDPR below:
Rising Performance Marketing Kft
Manuel Ried
Boldizsár utca 4, HU-1112 Budapest, Hungary
Authorized representative: Manuel Ried
Email: office@risingperformancemarketing.com
Phone: +36 30 744 8971
Imprint: https://risingperformancemarketing.com/privacy-policy/
Storage Period
As a general principle, we only store personal data for as long as is absolutely necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, however, we are legally obliged to store certain data even after the original purpose has ceased to apply, for example for accounting purposes.
If you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to retain it.
Where we have further information on the specific duration of the respective data processing, we will inform you about this in the relevant sections below.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you of the following rights to which you are entitled in order to ensure fair and transparent processing of data:
In short: You have rights – do not hesitate to contact the controller listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can lodge a complaint with the supervisory authority.
Data Transfer to Third Countries
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you have consented to this processing or if there is another legal permission. This is particularly the case when processing is required by law or necessary to fulfil a contractual relationship and, in any case, only to the extent that this is generally permitted. Your consent is, in most cases, the most important basis for us to have data processed in third countries.
The processing of personal data in third countries such as the USA, where many software providers offer services and host their servers, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, according to the Court of Justice of the European Union, an adequate level of protection for the transfer of data to the USA currently only exists if a US company that processes personal data of EU citizens in the USA is an active participant in the EU–US Data Privacy Framework. You can find more information here:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Processing of personal data by US services that are not active participants in the EU–US Data Privacy Framework may result in data being processed and stored in a non-anonymised form. Furthermore, US public authorities may have access to certain data. It may also occur that data collected is linked with data from other services of the same provider, if you have a corresponding user account. Wherever possible, we try to use server locations within the EU, where this is offered.
We will inform you more specifically about data transfers to third countries at the appropriate points in this Privacy Policy, where applicable.
Security of Data Processing
In order to protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. This makes it as difficult as reasonably possible for third parties to infer personal information from our data.
Article 25 GDPR speaks of “data protection by design and by default” and refers to the principle that, with both software (e.g. forms) and hardware (e.g. access to the server room), security must always be considered and appropriate measures implemented. Where required, we will go into more detail about specific measures below.
TLS Encryption with HTTPS
TLS, encryption and HTTPS sound very technical – and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data securely over the internet.
This means that the entire transmission of all data from your browser to our web server is secured – no one can “listen in”.
With this, we have implemented an additional security layer and comply with data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognise the use of this secure data transfer by the small lock symbol in the upper left-hand corner of the browser, to the left of the internet address (e.g. example.com), and by the use of the scheme https (instead of http) as part of our internet address.
If you want to learn more about encryption, we recommend searching for “Hypertext Transfer Protocol Secure wiki” in your preferred search engine to find good links to further information.
When you send us an inquiry through our contact form, we process the personal data you voluntarily provide. Depending on the fields you complete, this includes:
Name
Company
Email address
Country
Selected services
Budget range
Message / free text
We process this data for the following purposes:
To respond to your inquiry
To prepare offers and provide requested information
To assess service requirements and project scope
To conduct pre-contractual communication
To manage customer relationships and support
The processing of your data is based on:
Art. 6 (1) lit. b GDPR — Processing is necessary for taking steps prior to entering into a contract and for handling your request.
Art. 6 (1) lit. f GDPR — Our legitimate interest in efficiently managing inquiries and providing professional customer service.
If you explicitly agree to be contacted for marketing purposes: Art. 6 (1) lit. a GDPR (consent).
We store contact form submissions only as long as necessary to respond to your request, and in accordance with mandatory commercial and tax retention periods.
Non-contractual inquiries are deleted on a regular basis once processing is complete.
Your form submission is processed on servers operated by our hosting provider:
easyname GmbH, Canettistrasse 5/10, 1100 Vienna, Austria
easyname acts as a processor under a valid Data Processing Agreement (DPA).
The form is technically provided via Elementor Forms.
Elementor does not transfer data to third parties unless additional integrations (e.g. email marketing tools, CRMs) are explicitly connected.
We do not use such integrations.
All data transmitted through the contact form is protected by SSL encryption (HTTPS), ensuring that your information cannot be intercepted or accessed by unauthorized third parties.
You are not legally required to provide your personal data.
However, without the necessary information (such as your email address), we may not be able to respond to your inquiry.
Cookies
Cookies – Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Depends on the respective cookie. More details can be found below and/or from the software provider that sets the cookie.
📓 Processed data: Depends on the cookie used. More details can be found below and/or from the software provider that sets the cookie.
📅 Storage period: Depends on the respective cookie, can range from a few hours to several years.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What are cookies?
Our website uses HTTP cookies to store user-specific data.
In the following, we explain what cookies are and why they are used, so that you can better understand this Privacy Policy.
Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser – these are called cookies.
One thing is clear: cookies are really helpful little tools. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other application areas. HTTP cookies are small files that are stored by our website on your computer. These cookie files are placed in your browser’s cookie folder – effectively the “memory” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data, such as language or personal page settings. When you visit our site again, your browser sends these “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you your usual settings. In some browsers, each cookie has its own file; in others, like Firefox, all cookies are stored in a single file.
The following graphic illustrates a possible interaction between a web browser and a web server when requesting a web page. The browser requests a page from the server and receives, along with the page, a cookie which the browser re-sends back when requesting further pages.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our website, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie needs to be assessed individually, as each cookie stores different data. The expiration time of a cookie also varies between a few minutes and several years. Cookies are not software programs and do not contain viruses, trojans or other “malware”. Cookies cannot access information on your PC.
Here is an example of cookie data:
These minimum capacities should be supported by a browser:
What types of cookies are there?
Which cookies we use in particular depends on the services used and is explained in the following sections of this Privacy Policy. At this point we would like to briefly explain the different types of HTTP cookies.
We can distinguish 4 types of cookies:
These cookies are necessary to ensure basic functions of the website. For example, such cookies are needed when a user adds a product to the shopping cart, continues browsing and later proceeds to checkout. Thanks to these cookies, the cart is not deleted even if the user closes the browser window.
These cookies collect information about user behaviour and whether users receive error messages. They are also used to measure the loading time and behaviour of the website in different browsers.
These cookies improve user-friendliness. For example, they store entered locations, font sizes or form data.
These cookies are also called targeting cookies. They are used to deliver personalised advertising to the user. This can be very useful but also very annoying.
Usually, you are asked on your first visit which types of cookies you want to allow. And of course, this decision is itself stored in a cookie.
If you want to learn more about cookies and do not shy away from technical documentation, we recommend
https://datatracker.ietf.org/doc/html/rfc6265 – the “HTTP State Management Mechanism” Request for Comments by the IETF.
Purpose of processing via cookies
The purpose ultimately depends on the respective cookie. More details can be found below and/or from the software provider that sets the cookie.
What data is processed?
Cookies are small helpers for many different tasks. Which data is stored in cookies cannot be generalised, but we will inform you in the context of this Privacy Policy about the data processed and/or stored.
Storage period of cookies
The storage period depends on the respective cookie and will be specified further below where possible. Some cookies are deleted in less than an hour, others can remain stored on a computer for several years.
You can also influence the storage period yourself. You can delete all cookies manually at any time via your browser (see also “Right to object”). Furthermore, cookies that are based on consent will be deleted at the latest after you withdraw your consent; the lawfulness of storage up to that point remains unaffected.
Right to object – how can I delete cookies?
You decide how and whether you want to use cookies. Regardless of the service or website from which cookies originate, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies are stored in your browser, change cookie settings or delete cookies, you can find this in your browser settings:
If you generally do not want any cookies, you can configure your browser such that it always informs you when a cookie is to be set. This allows you to decide, for each individual cookie, whether you allow it or not. The procedure differs depending on the browser. It is best to search for instructions using your search engine with the terms “delete cookies Chrome” or “disable cookies Chrome” if you use Chrome.
Legal basis
Since 2009 there have been so-called “Cookie Directives”. These state that the storage of cookies requires your consent (Article 6(1)(a) GDPR). However, reactions to these directives differ widely across EU countries. In Austria, the directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the directive was not implemented as national law; instead, it was effectively implemented in Section 15(3) of the Telemedia Act (TMG), which has been replaced by the Digital Services Act (DDG) since May 2024.
For strictly necessary cookies, even where no consent is present, there are legitimate interests (Article 6(1)(f) GDPR), which are mostly economic in nature. We want to offer visitors a pleasant user experience, and certain cookies are often absolutely necessary for this.
Where non-essential cookies are used, this only happens if you have given your consent. The legal basis for this is Article 6(1)(a) GDPR.
In the following sections, you will be informed in more detail about the use of cookies, where software used by us relies on them.
Web Hosting – Introduction
Web Hosting – Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Professional hosting of the website and ensuring operations
📓 Processed data: IP address, time of website visit, browser used and additional data. More details can be found below and/or from the hosting provider used.
📅 Storage period: Depends on the provider, usually 2 weeks
⚖️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests)
What is web hosting?
When you visit websites today, certain information – including personal data – is automatically created and stored, including on this website. Such data should be processed as sparingly as possible and only where justified. By “website” we mean all pages on a domain, i.e. everything from the homepage to the very last subpage (like this one here). By “domain” we mean, for example, example.com or samplewebsite.com.
If you want to view a website on a computer, tablet or smartphone, you use a program called a web browser. You probably know some of them by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We refer to them as browsers or web browsers.
For the website to be displayed, the browser must connect to another computer where the website code is stored: the web server. Operating a web server is a complex and demanding task and is therefore generally provided by professional providers, the hosting providers. They offer web hosting and thus ensure reliable and error-free storage of website data. That’s a lot of technical terms – but please stay with us, it gets better!
When your browser connects to our web server and while data is transmitted back and forth, personal data may be processed. On the one hand, your computer stores data, and on the other hand, the web server also needs to store data for a certain period to ensure proper operation.
The following graphic illustrates the interaction between browser, the internet and the hosting provider.
Why do we process personal data?
The purposes of this data processing are:
What data is processed?
Even while you are currently visiting our website, our web server (the computer on which this website is stored) typically automatically logs data such as:
How long is the data stored?
As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not pass on this data, but we cannot exclude that authorities may access this data in case of unlawful behaviour.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without your consent!
Legal basis
The lawfulness of the processing of personal data in the context of web hosting arises from Article 6(1)(f) GDPR (protection of legitimate interests), as the use of professional hosting by a provider is necessary to present the company securely and user-friendly on the internet and to be able to pursue any attacks and claims arising from this.
We usually have a data processing agreement in place with our hosting provider pursuant to Article 28 GDPR, which ensures compliance with data protection and guarantees data security.
External Web Hosting Provider – Privacy
Below you will find the contact details of our external hosting provider, where you can find more information on data processing, in addition to the information provided above:
easyname GmbH
Canettistrasse 5/10, 1100 Vienna, Austria
You can find more details on data processing by this provider in its privacy policy.
Website Builder Systems – Introduction
Website Builder Systems – Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service
📓 Processed data: Data such as technical usage information like browser activity, clickstream activity, session heatmaps as well as contact data, IP address or your geographical location. More details can be found below and in the provider’s privacy policy.
📅 Storage period: Depends on the provider
⚖️ Legal bases: Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)
What are website builder systems?
We use a website builder system for our website. Builder systems are a special form of content management system (CMS). With a website builder, website operators can create a website very easily and without programming knowledge. In many cases, hosting providers also offer builder systems. By using such a system, personal data about you may be collected, stored and processed. In this privacy text, we provide general information on data processing by builder systems. More detailed information can be found in the provider’s privacy policy.
Why do we use website builder systems for our website?
The biggest advantage of a builder system is its ease of use. We want to provide you with a clear, simple and well-structured website that we can easily operate and maintain ourselves without external support. A builder system now offers many useful features that we can use without programming skills. This allows us to design our online presence according to our wishes and offer you an informative and pleasant experience on our website.
What data is stored by a builder system?
Which data is stored depends on the website builder used. Each provider processes and collects different data about website visitors. Usually, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and date of your website visit is collected. In addition, tracking data (e.g. browser activity, clickstream activities, session heatmaps, etc.) may also be processed. Personal data may also be collected and stored. This usually includes contact details such as email address, telephone number (if you provide it), IP address and geographical location data. You can find which data is stored in detail in the respective provider’s privacy policy.
How long and where is the data stored?
We will inform you below about the duration of data processing in connection with the website builder used, where we have further information. You will find detailed information in the provider’s privacy policy. In general, we only process personal data for as long as is absolutely necessary to provide our services and products. It may be that the provider stores data about you according to its own criteria, over which we have no control.
Right to object
You always have the right to access, rectify and delete your personal data. If you have any questions, you can also contact the provider of the website builder directly. Contact details can be found either in this Privacy Policy or on the provider’s website.
You can delete, disable or manage cookies used by providers for their functions in your browser. Depending on the browser you use, this works in different ways. Please note, however, that in this case some functions may no longer work as usual.
Legal basis
We have a legitimate interest in using a website builder system in order to optimise our online service and present it efficiently and attractively to you. The corresponding legal basis for this is Article 6(1)(f) GDPR (legitimate interests). We only use the builder system to the extent that you have given your consent.
Where data processing is not absolutely necessary for the operation of the website, data is only processed on the basis of your consent. This applies in particular to tracking activities. In this respect, the legal basis is Article 6(1)(a) GDPR (consent).
With this Privacy Policy, we have brought you closer to the most important general information on data processing. If you would like more detailed information, you will find it – where available – in the following section and/or in the provider’s privacy policy.
WordPress.com Privacy Policy
WordPress.com – Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our service
📓 Processed data: Data such as technical usage information like browser activity, clickstream activities, session heatmaps as well as contact data, IP address or your geographical location. More details can be found below in this Privacy Policy.
📅 Storage period: Depends mainly on the type of data stored and the concrete settings.
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is WordPress?
We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
The company was founded in 2003 and quickly became one of the most well-known content management systems (CMS) worldwide. A CMS is software that helps us design our website and present content in an attractive and structured way. The content can be text, audio or video.
By using WordPress, personal data about you may also be collected, stored and processed. As a rule, technical data such as operating system, browser, screen resolution or hosting provider is stored. Personal data such as IP address, geographical data or contact details may also be processed.
Why do we use WordPress on our website?
We have many strengths, but advanced programming is not one of our core competences.
Nonetheless, we want to have a powerful and attractive website that we can manage and maintain ourselves. This is exactly what a website builder system or content management system like WordPress makes possible. With WordPress, we do not have to be programming experts to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily without technical knowledge. If technical problems arise or we have special requirements for our website, we still have specialists who are at home in HTML, PHP, CSS and so on.
Due to the ease of use and the extensive features of WordPress, we can design our web presence according to our needs and provide you with a good user experience.
What data is processed by WordPress?
Non-personal data includes technical usage information such as browser activity, clickstream activities, session heatmaps and information about your computer, operating system, browser, screen resolution, language and keyboard settings, internet provider as well as the date of the page visit.
Personal data is also collected. This is primarily contact data (email address or phone number, if you provide it), IP address or your geographical location.
WordPress may also use cookies to collect data. These often capture data about your behaviour on our website. For example, it can record which subpages you like to view, how long you stay on individual pages, when you leave a page (bounce rate), or which preferences (e.g. language selection) you have set. Based on this data, WordPress can adapt its own marketing measures better to your interests and user behaviour. When you visit our website again, it will then be displayed the way you previously set it.
WordPress may also use technologies such as pixel tags (web beacons) to clearly identify you as a user and possibly offer interest-based advertising.
How long and where is the data stored?
How long the data is stored depends on various factors, especially on the type of data stored and the specific settings of the website. As a general rule, data is deleted by WordPress once it is no longer needed for its own purposes. There are, of course, exceptions, especially where statutory obligations require longer retention. Web server logs that contain your IP address and technical data are deleted by WordPress/Automattic after 30 days. During this period, Automattic uses the data to analyse traffic on its own websites (for example all WordPress pages) and to fix possible problems. Deleted content on WordPress websites is also kept in the trash for 30 days to allow recovery; afterwards, it may remain in backups and caches until these are deleted. Data is stored on servers of Automattic in the United States.
How can I delete my data or prevent data storage?
You always have the right and option to access your personal data and to object to its use and processing. You can also file a complaint with a state supervisory authority at any time.
In your browser, you also have the option to manage, delete or disable cookies individually. Please note that deactivated or deleted cookies may negatively affect the functions of our WordPress site. Depending on the browser you use, cookie management works slightly differently. In the section “Cookies” above, you will find links to instructions for the most common browsers.
Legal basis
If you have consented to the use of WordPress, the legal basis for the data processing is this consent. This consent constitutes the legal basis under Article 6(1)(a) GDPR (consent) for the processing of personal data that may occur when data is collected by WordPress.
We also have a legitimate interest in using WordPress in order to optimise and present our online service in an attractive way. The corresponding legal basis is Article 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use WordPress to the extent that you have given consent.
WordPress/Automattic processes data about you also in the USA. Automattic is an active participant in the EU–US Data Privacy Framework, which regulates the proper and secure transfer of personal data of EU citizens to the USA. More information can be found at:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
Automattic also uses so-called Standard Contractual Clauses (Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are template contracts provided by the European Commission that are intended to ensure that your data also meets EU data protection standards when transferred to third countries (such as the USA) and stored there. Through the EU–US Data Privacy Framework and the SCCs, Automattic undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the European Commission. You can find the decision and the relevant SCCs here:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=en
You can find more details on the privacy policy and on which data is processed and how by WordPress at:
https://automattic.com/privacy/.
We use the WordPress page builder Elementor (by Elementor Ltd., Tuval St 40, Ramat Gan, Israel) to create and display the content and layout of our website. Elementor is an extension integrated directly into our WordPress system and operates locally on our web server. This means that no data is automatically transmitted to Elementor’s servers simply by visiting our website.
When you interact with elements on our website that were created with Elementor (such as forms, animations, pop-ups, sliders, text blocks, or layout structures), the following data may be processed:
Technical data:
IP address, browser information, device type, operating system, date and time of access
Website usage data:
interaction with buttons, movement on the site, scroll depth, clicks, displayed elements
Form data (if Elementor forms are used):
The content you voluntarily submit (e.g., name, email, company, message)
Elementor stores these form submissions locally on our server, managed by our hosting provider easyname GmbH. No data is transferred to Elementor Ltd. unless specific external integrations are used (we do not use such integrations).
Elementor is used for:
Creating and managing the website layout
Displaying design and content elements
Providing interactive features such as forms, pop-ups, motion effects, galleries, etc.
Ensuring stable and optimized website performance
The use of Elementor is based on:
Art. 6 (1) lit. f GDPR — Legitimate Interest
Our legitimate interest is to provide a modern, secure and visually optimized website.
Art. 6 (1) lit. b GDPR — Contractual or Pre-contractual Measures
When Elementor is used to process inquiries (e.g., via contact forms).
Art. 6 (1) lit. a GDPR — Consent
If Elementor loads features that require your prior consent (e.g., scripts, tracking or external media).
These elements only load after you have given your permission through the cookie/consent banner.
Technical data (server logs) is stored according to our hosting provider’s standard retention periods.
Form submissions via Elementor are stored only as long as necessary to process your request and to comply with legal retention obligations, after which they are deleted.
All data processed through Elementor is handled on our own servers, located in:
easyname GmbH, Canettistrasse 5/10, 1100 Vienna, Austria
No data is automatically transferred outside the EU.
Our website uses SSL encryption (HTTPS), ensuring that any data transmitted through Elementor elements—especially form submissions—cannot be accessed by unauthorized third parties.
For more details, please refer to Elementor’s Privacy Policy:
Privacy Policy
Web Analytics – Introduction
Web Analytics – Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Evaluation of visitor information to optimise the web offering
📓 Processed data: Access statistics containing data such as locations of access, device data, duration and time of access, navigation behaviour, click behaviour and IP addresses. More details can be found from the respective web analytics tool.
📅 Storage period: Depends on the web analytics tool used
⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is web analytics?
We use software on our website to evaluate visitor behaviour – called web analytics or web analysis. Data is collected that is stored, managed and processed by the respective analytics provider (also referred to as tracking tool). The data is used to create analyses of user behaviour on our website and made available to us as website operators. Most tools also offer various testing options. For example, we can test which offers or content is best received by our visitors. For this purpose, we show you two different offers for a limited time. After the test (so-called A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics methods, user profiles can be created and data can be stored in cookies.
Why do we use web analytics?
With our website, we have a clear goal: we want to offer the best web offering in our industry. To achieve this goal, we want to provide the best and most interesting offering and ensure that you feel completely at ease on our website. Web analytics tools help us to take a closer look at the behaviour of our website visitors and then improve our web offering accordingly. For example, we can see how old our visitors are on average, where they come from, when our website is most frequently visited or which content or products are particularly popular. All this information helps us to optimise the website and adapt it to your needs, interests and wishes.
What data is processed?
Which data is stored depends on the analysis tool used. Typically, however, data is stored such as which content you view on our website, which buttons or links you click, when you access a page, which browser you use, with which device (PC, tablet, smartphone etc.) you visit the website or which operating system you use. If you have agreed that location data may also be collected, these can also be processed by the analytics provider.
Your IP address is also stored. Under the GDPR, IP addresses are considered personal data. However, your IP address is usually stored in a pseudonymised (i.e. shortened and anonymised) form. As a rule, no direct data such as your name, age, address or email address is stored for the purposes of testing, web analysis and optimisation. All such data, if collected, is stored pseudonymously. This means you cannot be identified as a person.
The following example shows schematically how Google Analytics works as an example of client-based web tracking with JavaScript code.
How long data is stored depends on the provider. Some cookies store data for only a few minutes or until you leave the website; others can store data for several years.
Duration of data processing
We will inform you below about the duration of data processing where we have more information. In general, we only process personal data for as long as is absolutely necessary to provide our services and products. If there are statutory storage obligations (e.g. for accounting purposes), this period may be exceeded.
Right to object
You also always have the right and option to withdraw your consent to the use of cookies and/or third-party providers. This can be done either via our cookie management tool or via other opt-out functions. For example, you can prevent data collection by cookies by managing, disabling or deleting cookies in your browser.
Legal basis
The use of web analytics requires your consent, which we obtain via our cookie popup. This consent constitutes the legal basis within the meaning of Article 6(1)(a) GDPR (consent) for the processing of personal data as it may occur when collected by web analytics tools.
In addition to consent, we also have a legitimate interest in analysing visitor behaviour in order to improve our offering technically and economically. Web analytics help us identify website errors, detect attacks and improve profitability. The legal basis for this is Article 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use such tools to the extent that you have given your consent.
Since web analytics tools use cookies, we also recommend reading our general section on cookies. To find out which data is stored and processed in your case, you should read the privacy information of the respective tools.
Information on specific web analytics tools can be found – where available – in the following sections.
Google Analytics Privacy Policy
Google Analytics Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Evaluation of visitor information to optimise the website.
📓 Processed data: Access statistics containing data such as access locations, device data, access duration and time, navigation behaviour and click behaviour. More details can be found further down in this privacy policy.
📅 Storage period: individually adjustable; by default, Google Analytics stores data for 14 months.
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is Google Analytics?
We use the Google Analytics 4 (GA4) analysis tracking tool from the American company Google Inc. on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. By combining various technologies such as cookies, device IDs and login information, you as a user can be identified across different devices. This allows your actions to be analysed across platforms.
For example, when you click on a link, this event is stored in a cookie and sent to Google Analytics. The reports we receive from Google Analytics help us to better tailor our website and service to your needs. Below, we provide more detailed information about the tracking tool, in particular what data is processed and how you can prevent this. Google Analytics is a tracking tool used to analyse traffic on our website. These measurements and analyses are based on a pseudonymous user identification number. This number does not contain any personal data such as name or address, but is used to assign events to a device. GA4 uses an event-based model that collects detailed information about user interactions such as page views, clicks, scrolling and conversion events. In addition, various machine learning functions have been built into GA4 to better understand user behaviour and certain trends. GA4 relies on modelling with the help of machine learning functions. This means that, based on the data collected, missing data can also be extrapolated in order to optimise the analysis and also to be able to make forecasts.
In order for Google Analytics to function, a tracking code is embedded in the code of our website. When you visit our website, this code records various events that you perform on our website. With GA4’s event-based data model, we as website operators can define and track specific events to obtain analyses of user interactions. This means that, in addition to general information such as clicks or page views, specific events that are important to our business can also be tracked. Such specific events can be, for example, the submission of a contact form or the purchase of a product.
As soon as you leave our website, this data is sent to the Google Analytics servers and stored there.
Google processes the data and we receive reports on your user behaviour. These reports may include the following:
In addition to the analysis reports mentioned above, Google Analytics 4 also offers the following functions, among others:
Why do we use Google Analytics on our website?
Our goal with this website is clear: we want to offer you the best possible service. The statistics and data from Google Analytics help us achieve this goal.
The statistically evaluated data gives us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimise our site so that it is easier for interested people to find on Google. On the other hand, the data helps us to better understand you as a visitor. This means we know exactly what we need to improve on our website in order to offer you the best possible service. The data also helps us to tailor our advertising and marketing measures more individually and cost-effectively. After all, it only makes sense to show our products and services to people who are interested in them.
What data is stored by Google Analytics?
Google Analytics uses a tracking code to create a random, unique ID that is linked to your browser cookie. This allows Google Analytics to recognise you as a new user and assign you a user ID. The next time you visit our site, you will be recognised as a ‘returning’ user. All collected data is stored together with this user ID. This makes it possible to evaluate pseudonymous user profiles.
In order to analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is the default. Depending on the property used, data is stored for different lengths of time.
Through identifiers such as cookies, app instance IDs, user IDs or custom event parameters, your interactions are measured across platforms, provided you have given your consent. Interactions are all types of actions you perform on our website. If you also use other Google systems (such as a Google account), data generated by Google Analytics may be linked to third-party cookies. Google does not share Google Analytics data unless we, as the website operator, approve it. Exceptions may occur if required by law.
According to Google, IP addresses are not logged or stored in Google Analytics 4. However, Google uses IP address data to derive location data and deletes it immediately afterwards. All IP addresses collected from users in the EU are therefore deleted before the data is stored in a data centre or on a server.
Since Google Analytics 4 focuses on event-based data, the tool uses significantly fewer cookies compared to previous versions (such as Google Universal Analytics). Nevertheless, there are some specific cookies that are used by GA4. These include, for example:
Name: _ga
Value: 2.1326744211.152113080663-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Basically, it serves to distinguish between website visitors.
Expiry date: after 2 years
Name: _gid
Value: 2.1687193234.152113080663-1
Purpose: The cookie is also used to distinguish between website visitors.
Expiry date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: Used to reduce the request rate. If Google Analytics is provided via Google Tag Manager, this cookie is named _dc_gtm_ <property-id>.
Expiry date: after 1 minute
Note: This list cannot claim to be exhaustive, as Google constantly changes its choice of cookies. GA4 also aims to improve data protection. The tool therefore offers a number of options for controlling data collection. For example, we can specify the storage period ourselves and also control data collection.
Here we provide an overview of the most important types of data collected by Google Analytics:
Heat maps: Google creates so-called heat maps. Heat maps show exactly which areas you click on. This gives us information about where you are ‘travelling’ on our site.
Session duration: Google defines session duration as the time you spend on our site without leaving it. If you have been inactive for 20 minutes, the session ends automatically.
Bounce rate: A bounce occurs when you view only one page on our website and then leave our website.
Account creation: When you create an account or place an order on our website, Google Analytics collects this data.
Location: IP addresses are not logged or stored in Google Analytics. However, shortly before the IP address is deleted, derivations are used for location data.
Technical information: Technical information includes your browser type, your internet service provider or your screen resolution.
Source of origin: Google Analytics and we are of course also interested in which website or advertisement brought you to our site.
Other data includes contact details, any reviews, media playback (e.g. if you play a video via our site), sharing content via social media or adding it to your favourites. This list is not exhaustive and is only intended to provide a general overview of data storage by Google Analytics.
How long and where is the data stored?
Google has servers all over the world. You can find out exactly where Google’s data centres are located here: https://datacenters.google/
Your data is distributed across various physical data carriers. This has the advantage that the data can be retrieved more quickly and is better protected against manipulation. Every Google data centre has appropriate emergency programmes for your data. If, for example, Google’s hardware fails or natural disasters cripple servers, the risk of service interruption at Google remains low.
The retention period for the data depends on the properties used. The storage period is always specified separately for each individual property. Google Analytics offers us four options for controlling the storage period:
In addition, there is also the option that data will only be deleted if you do not visit our website again within the period we have selected. In this case, the retention period will be reset each time you visit our website again within the specified period.
Once the specified period has expired, the data will be deleted once a month. This retention period applies to your data linked to cookies, user recognition and advertising IDs (e.g. cookies from the DoubleClick domain). Reporting results are based on aggregated data and are stored independently of user data. Aggregated data is a combination of individual data into a larger unit.
How can I delete my data or prevent data storage?
Under European Union data protection law, you have the right to obtain information about your data, to update it, to delete it or to restrict its use. You can prevent Google Analytics 4 from using your data by using the browser add-on to deactivate Google Analytics JavaScript (analytics.js, gtag.js). You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de. Please note that this add-on only deactivates data collection by Google Analytics.
If you want to deactivate, delete or manage cookies in general, you will find the relevant links to the respective instructions for the most popular browsers in the ‘Cookies’ section.
Legal basis
The use of Google Analytics requires your consent, which we have obtained with our cookie pop-up. According to Art. 6 (1) (a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur when collected by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of Google Analytics, we can detect website errors, identify attacks and improve economic efficiency. The legal basis for this is Art. 6 (1) lit. f GDPR (legitimate interests). However, we only use Google Analytics if you have given your consent.
Google also processes your data in the USA, among other places. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
Google also uses so-called standard contractual clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
We hope we have been able to provide you with the most important information about data processing by Google Analytics. If you would like to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.
If you would like to learn more about data processing, please refer to Google’s privacy policy at https://policies.google.com/privacy?hl=de.
Google Site Kit Privacy Policy
Google Site Kit Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Evaluation of visitor information to optimise the website.
📓 Processed data: Access statistics containing data such as access locations, device data, access duration and time, navigation behaviour, click behaviour and IP addresses. More details can be found below and in the Google Analytics privacy policy.
📅 Storage period: depends on the properties used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is Google Site Kit?
We have integrated the WordPress plugin Google Site Kit from the American company Google Inc. into our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Site Kit, we can quickly and easily view statistics from various Google products, such as Google Analytics, directly in our WordPress dashboard. The tool, or rather the tools integrated into Google Site Kit, also collect personal data from you, among other things. In this privacy policy, we explain why we use Google Site Kit, how long and where data is stored, and which other privacy policy texts are relevant to you in this context. Google Site Kit is a plugin for the WordPress content management system. With this plugin, we can view important website analysis statistics directly in our dashboard. These are statistics collected by other Google products, primarily Google Analytics. In addition to Google Analytics, Google Search Console, Page Speed Insight, Google AdSense, Google Optimize and Google Tag Manager can also be linked to Google Site Kit.
Why do we use Google Site Kit on our website?
As a service provider, it is our job to offer you the best possible experience on our website. We want you to feel comfortable on our website and find exactly what you are looking for quickly and easily. Statistical analyses help us to get to know you better and tailor our offerings to your wishes and interests. We use various Google tools for these analyses. Site Kit makes our work much easier in this regard because we can view and analyse the statistics from Google products directly in the dashboard. This means we no longer have to log in separately for each tool. Site Kit therefore always provides a good overview of the most important analysis data.
What Data Is Stored by Google Site Kit?
If you have actively agreed to tracking tools in the cookie notice (also referred to as a script or banner), Google products such as Google Analytics will set cookies and collect data about you — for example, information about your user behavior. This data is then sent to Google, where it is stored and processed. This also includes personal data such as your IP address.
For more detailed information on the individual services, we have dedicated sections within this Privacy Policy. For example, please refer to our Google Analytics Privacy Policy, where we explain in detail which data is collected, how long Google Analytics stores, manages, and processes this data, which cookies may be used, and how you can prevent data storage. We have also created specific privacy sections for other Google services such as Google Tag Manager or Google AdSense, each containing comprehensive information.
Below we show you example Google Analytics cookies that may be set in your browser if you have agreed to Google’s data processing. Please note that this is only a selection of possible cookies:
Name: _ga
Value: 2.1326744211.152113080663-2
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. It is primarily used to distinguish between website visitors.
Expiry date: after 2 years
Name: _gid
Value: 2.1687193234.152113080663-7
Purpose: This cookie is also used to distinguish between website visitors.
Expiry date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: This cookie is used to reduce the request rate.
Expiry date: after 1 minute
How long and where is the data stored?
Google stores collected data on its own Google servers, which are distributed worldwide. Most servers are located in the United States, so it is quite possible that your data will also be stored there. At https://datacenters.google/, you can see exactly where the company provides servers.
Data collected by Google Analytics is stored for a standard period of 26 months. After this period, your user data is deleted. The storage period applies to all data linked to cookies, user recognition and advertising IDs.
How can I delete my data or prevent data storage?
You always have the right to obtain information about your data, to have your data deleted, corrected or restricted. You can also deactivate, delete or manage cookies in your browser at any time.
If you want to deactivate, delete or manage cookies in general, you will find the relevant links to the respective instructions for the most popular browsers in the ‘Cookies’ section.
Legal Basis
The use of Google Site Kit requires your consent, which we obtained through our cookie popup. This consent constitutes the legal basis for the processing of personal data according to Art. 6 para. 1 lit. a GDPR (consent), as may occur when using web analytics tools.
In addition to consent, we also have a legitimate interest in analyzing the behavior of website visitors in order to improve our services both technically and economically. With the help of Google Site Kit, we can identify website errors, detect attacks, and optimize overall performance. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use Google Site Kit if you have given consent.
Google also processes your data in the United States, among other locations. Google is an active participant in the EU–US Data Privacy Framework, which regulates the lawful and secure transfer of personal data from EU citizens to the USA. You can find more information at:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
Furthermore, Google uses what are known as Standard Contractual Clauses (“SCCs”) pursuant to Art. 46 paras. 2 and 3 GDPR. Standard Contractual Clauses are template contracts provided by the European Commission to ensure that your data continues to comply with European data protection standards even when transferred to and stored in third countries (such as the USA). Through the EU–US Data Privacy Framework and the SCCs, Google commits to upholding European data protection levels when processing your relevant data, even if the data is stored, processed, and managed in the USA.
Privacy Framework and Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
To learn more about data processing by Google, we recommend that you read Google’s comprehensive privacy policy at https://policies.google.com/privacy?hl=de.
Online Marketing – Introduction
Online marketing Privacy policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Evaluation of visitor information to optimise the website.
📓 Processed data: Access statistics containing data such as access locations, device data, access duration and time, navigation behaviour, click behaviour and IP addresses. Personal data such as name or email address may also be processed. More details can be found in the respective online marketing tool used.
📅 Storage period: Depends on the online marketing tools used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is online marketing?
Online marketing refers to all measures carried out online to achieve marketing goals such as increasing brand awareness or closing a deal. Furthermore, our online marketing measures aim to draw people’s attention to our website. We therefore use online marketing to show our offering to as many interested people as possible. This usually involves online advertising, content marketing or search engine optimisation. In order to use online marketing efficiently and in a targeted manner, personal data is also stored and processed. On the one hand, the data helps us to show our content only to those people who are actually interested in it and, on the other hand, it enables us to measure the advertising success of our online marketing measures.
Why do we use online marketing tools?
We want to show our website to everyone who is interested in what we have to offer. We are aware that this is not possible without deliberate measures. That is why we do online marketing. There are various tools that make our online marketing work easier and also provide us with suggestions for improvement based on data. This allows us to target our campaigns more precisely to our target group. The purpose of these online marketing tools is ultimately to optimise our offerings.
What data is processed?
To ensure that our online marketing works and that the success of our measures can be measured, user profiles are created and data is stored in cookies (small text files), for example. With the help of this data, we can not only place advertisements in the traditional sense, but also display our content directly on our website in the way that you prefer. There are various third-party tools that offer these functions and also collect and store data from you accordingly. For example, the cookies mentioned store which pages you have visited on our website, how long you have viewed these pages, which links or buttons you click on, or which website you came to us from. Technical information may also be stored. This includes your IP address, which browser you use, which device you use to visit our website, and the time at which you accessed our website and left it again. If you have consented to us determining your location, we may also store and process this information. Your IP address is stored in pseudonymised form (i.e. abbreviated). Unique data that directly identifies you as a person, such as your name, address or email address, is also only stored in pseudonymised form as part of advertising and online marketing processes. This means that we cannot identify you as a person, but only have the pseudonymised, stored information in the user profiles.
Under certain circumstances, cookies may also be used, analysed and utilised for advertising purposes on other websites that use the same advertising tools. The data may then also be stored on the servers of the advertising tool providers.
In exceptional cases, unique data (names, email addresses, etc.) may also be stored in the user profiles. This storage occurs, for example, if you are a member of a social media channel that we use for our online marketing measures and the network links previously entered data with the user profile. For all advertising tools we use that store your data on their servers, we only ever receive aggregated information and never data that identifies you as an individual. The data merely shows how well advertising measures worked. For example, we can see which measures prompted you or other users to visit our website and purchase a service or product there. Based on the analyses, we can improve our advertising offerings in the future and tailor them even more precisely to the needs and wishes of interested parties.
Duration of data processing
We will inform you about the duration of data processing below, provided we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. Data stored in cookies is stored for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. The respective privacy policies of the individual providers usually provide detailed information about the individual cookies used by the provider.
Right to object
You also have the right and option to withdraw your consent to the use of cookies or third-party providers at any time. You can do this either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. The lawfulness of the processing until withdrawal remains unaffected.
As online marketing tools generally use cookies, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
If you have consented to the use of third-party providers, the legal basis for the corresponding data processing is this consent. According to Art. 6 (1) (a) GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur when collected by online marketing tools.
We also have a legitimate interest in measuring online marketing measures in anonymised form in order to optimise our offerings and measures with the help of the data obtained. The corresponding legal basis for this is Art. 6 (1) lit. f GDPR (legitimate interests). However, we only use the tools if you have given your consent.
Information on specific online marketing tools can be found in the following sections, where available.
Audio & Video – Introduction
Audio & Video Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Processed data: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
More details can be found below in the relevant privacy policy texts.
📅 Storage period: Data is generally stored for as long as it is necessary for the purpose of the service.
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What are audio and video elements?
We have integrated audio and video elements into our website so that you can watch videos or listen to music/podcasts directly via our website. The content is provided by service providers. All content is therefore also obtained from the providers’ respective servers.
These are integrated functional elements from platforms such as YouTube, Vimeo or Spotify. The use of these portals is usually free of charge, but paid content may also be published. With the help of these integrated elements, you can listen to or view the respective content via our website.
When you use audio or video elements on our website, your personal data may also be transmitted to the service providers, processed and stored.
Why do we use audio and video elements on our website?
Of course, we want to provide you with the best possible experience on our website. And we are aware that content is no longer conveyed solely through text and static images. Instead of simply providing you with a link to a video, we offer audio and video formats directly on our website that are entertaining or informative, and ideally both. This expands our service and makes it easier for you to access interesting content. In addition to our texts and images, we also offer video and/or audio content.
What data is stored by audio and video elements?
When you visit a page on our website that has an embedded video, for example, your server connects to the service provider’s server. In doing so, data about you is also transferred to the third-party provider and stored there. Some data is collected and stored regardless of whether you have an account with the third-party provider or not. This usually includes your IP address, browser type, operating system and other general information about your device. Most providers also collect information about your web activity. This includes, for example, session duration, bounce rate, which buttons you clicked on or which website you used to access the service. All this information is usually stored via cookies or pixel tags (also known as web beacons). Pseudonymised data is usually stored in cookies in your browser. You can always find out exactly which data is stored and processed in the privacy policy of the respective provider.
Duration of data processing
You can find out exactly how long the data is stored on the servers of third-party providers either further down in the data protection text for the respective tool or in the provider’s data protection declaration. As a matter of principle, personal data is only ever processed for as long as is absolutely necessary for the provision of our services or products. This also applies to third-party providers as a rule. In most cases, you can assume that certain data will be stored on the servers of third-party providers for several years. Data can be stored for varying lengths of time, especially in cookies. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years.
Right to object
You also have the right and option to withdraw your consent to the use of cookies or third-party providers at any time. You can do this either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. The legality of the processing until withdrawal remains unaffected.
As cookies are usually also used by the integrated audio and video functions on our site, you should also read our general privacy policy on cookies. You can find out more about how your data is handled and stored in the privacy policies of the respective third-party providers.
Legal basis
If you have consented to your data being processed and stored by integrated audio and video elements, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fast and effective communication with you or other customers and business partners. However, we only use the integrated audio and video elements if you have given your consent.
YouTube Privacy Policy
YouTube Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimisation of our services
📓 Processed data: Data such as contact details, user behaviour data, information about your device and your IP address may be stored.
More details can be found further down in this privacy policy.
📅 Storage period: Data is generally stored for as long as it is necessary for the purpose of the service.
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is YouTube?
We have integrated YouTube videos into our website. This allows us to present interesting videos directly on our site. YouTube is a video portal that has been a subsidiary of Google since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that has a YouTube video embedded in it, your browser automatically connects to the YouTube or Google servers. Various data is transferred during this process (depending on your settings). Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all data processing in the European Union.
Below, we explain in more detail what data is processed, why we have embedded YouTube videos and how you can manage or delete your data.
On YouTube, users can watch, rate, comment on and upload videos free of charge. Over the last few years, YouTube has become one of the most important social media channels worldwide. To enable us to display videos on our website, YouTube provides a code snippet that we have incorporated into our site.
Why do we use YouTube videos on our website
YouTube is the video platform with the most visitors and the best content. We strive to offer you the best possible user experience on our website. And, of course, interesting videos are a must. With the help of our embedded videos, we provide you with additional helpful content alongside our texts and images. The embedded videos also make our website easier to find on the Google search engine. Even though we place advertisements via Google Ads, Google can only show these ads to people who are interested in our offers, thanks to the data it collects.
What data does YouTube store?
As soon as you visit one of our pages that has a YouTube video embedded in it, YouTube will set at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, YouTube can usually assign your interactions on our website to your profile using cookies. This includes data such as session duration, bounce rate, approximate location, technical information such as browser type, screen resolution or your internet service provider. Other data may include contact details, any ratings, sharing content via social media or adding to your favourites on YouTube.
If you are not logged into a Google account or YouTube account, Google stores data with a unique identifier linked to your device, browser or app. This ensures that your preferred language setting is retained, for example.
However, much interaction data cannot be stored because fewer cookies are set.
The following list shows cookies that were set in a browser test. On the one hand, we show cookies that are set without a logged-in YouTube account. On the other hand, we show cookies that are set with a logged-in account. The list cannot claim to be complete because user data always depends on interactions on YouTube.
Name: YSC
Value: b9-CV6ojI5Y113080663-1
Purpose: This cookie registers a unique ID to store statistics about the video viewed.
Expiry date: after the end of the session
Name: PREF
Value: f1=50000000
Purpose: This cookie also registers your unique ID. Google uses PREF to obtain statistics on how you use YouTube videos on our website.
Expiry date: after 8 months
Name: GPS
Value: 1
Purpose: This cookie registers your unique ID on mobile devices to track your GPS location.
Expiry date: after 30 minutes
Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie attempts to estimate the user’s bandwidth on our websites (with embedded YouTube videos).
Expiry date: after 8 months
Additional cookies that are set when you are logged in with your YouTube account:
Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7113080663-
Purpose: This cookie is used to create a profile of your interests. The data is used for personalised advertising.
Expiry date: after 2 years
Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user’s consent to the use of various Google services. CONSENT also serves security purposes to verify users and protect user data from unauthorised attacks.
Expiry date: after 19 years
Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile of your interests. This data helps to display personalised advertising.
Expiry date: after 2 years
Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information about your login details.
Expiry date: after 2 years
Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie works by uniquely identifying your browser and device. It is used to create a profile of your interests.
Expiry date: after 2 years
Name: SID
Value: oQfNKjAsI113080663-
Purpose: This cookie stores your Google account ID and your last login time in digitally signed and encrypted form.
Expiry date: after 2 years
Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information about how you use the website and what advertisements you may have seen before visiting our site.
Expiry date: after 3 months
How long and where is the data stored?
The data that YouTube receives and processes from you is stored on Google servers. Most of these servers are located in America. At https://datacenters.google/, you can see exactly where the Google data centres are located. Your data is distributed across the servers. This means that the data can be accessed more quickly and is better protected against manipulation.
Google stores the collected data for varying lengths of time. You can delete some data at any time, while other data is automatically deleted after a limited period of time and still other data is stored by Google for a longer period of time. Some data (such as items from ‘My Activity’, photos or documents, products) stored in your Google account will remain stored until you delete it. Even if you are not logged into a Google account, you can delete some data associated with your device, browser or app.
How can I delete my data or prevent data storage?
In principle, you can manually delete data in your Google account. With the automatic deletion function for location and activity data introduced in 2019, information is stored for either 3 or 18 months, depending on your decision, and then deleted.
Regardless of whether you have a Google account or not, you can configure your browser to delete or disable Google cookies. Depending on which browser you use, this works in different ways. Under the ‘Cookies’ section, you will find the relevant links to the respective instructions for the most popular browsers.
If you do not want cookies at all, you can set your browser to always inform you when a cookie is about to be set. This allows you to decide whether to allow each individual cookie or not.
Legal basis
If you have consented to your data being processed and stored by integrated YouTube elements, this consent serves as the legal basis for data processing (Art. 6 (1) (a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6 (1) (f) GDPR) in fast and effective communication with you or other customers and business partners. However, we only use the integrated YouTube elements if you have given your consent. YouTube also sets cookies in your browser to store data. We therefore recommend that you read our privacy policy on cookies carefully and review the privacy policy or cookie policy of the respective service provider.
YouTube also processes your data in the USA, among other places. YouTube and Google are active participants in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard contractual clauses (SCC) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the US) and stored there. Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the US. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
Since YouTube is a subsidiary of Google, there is a joint privacy policy. If you would like to learn more about how your data is handled, we recommend reading the privacy policy at https://policies.google.com/privacy?hl=de.
Web Design – Introduction
Web design Privacy policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Improving the user experience
📓 Data processed: The data processed depends heavily on the services used. In most cases, this includes the IP address, technical data, language settings, browser version, screen resolution, and browser name. You can find more details on this in the respective web design tools used.
📅 Storage period: Depends on the tools used
⚖️ Legal basis: Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (f) GDPR (legitimate interests)
What is web design?
We use various tools on our website that serve our web design purposes. Contrary to popular belief, web design is not just about making our website look pretty, but also about functionality and performance. But of course, the right look for a website is also one of the main goals of professional web design. Web design is a subfield of media design and deals with the visual, structural, and functional design of a website. The goal of web design is to improve your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience refers to all the impressions and experiences that a website visitor has on a website. One sub-item of user experience is usability. This refers to the user-friendliness of a website. The main focus here is on ensuring that content, subpages, or products are clearly structured and that you can find what you are looking for quickly and easily. In order to offer you the best possible experience on our website, we also use third-party web design tools. In this privacy policy, the category “web design” therefore includes all services that improve the design of our website. These can be, for example, fonts, various plugins, or other integrated web design functions.
Why do we use web design tools?
How you absorb information on a website depends heavily on the structure, functionality, and visual perception of the website. That’s why good, professional web design has become increasingly important to us. We are constantly working to improve our website and see this as an extended service for you as a website visitor. Furthermore, an attractive and functional website also has economic advantages for us. After all, you will only visit us and take advantage of our offers if you feel completely at ease.
What data is stored by web design tools?
When you visit our website, web design elements may be integrated into our pages that can also process data. The exact nature of this data depends heavily on the tools used. Below, you can see exactly which tools we use for our website. For more detailed information about data processing, we recommend that you also read the respective privacy policy of the tools used. In most cases, you will find out what data is processed, whether cookies are used, and how long the data is stored. Fonts such as Google Fonts, for example, also automatically transmit information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google servers.
Duration of data processing
How long data is processed is very individual and depends on the web design elements used. If cookies are used, for example, the storage period can be as short as one minute or as long as a few years. Please inform yourself about this. We recommend that you read our general section on cookies and the privacy policies of the tools used. There you will usually find out exactly which cookies are used and what information is stored in them. Google font files, for example, are stored for one year. This is to improve the loading time of a website. As a rule, data is only stored for as long as is necessary to provide the service. Data may also be stored for longer if required by law.
Right to object
You also have the right and option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either via our cookie management tool or via other opt-out functions. You can also prevent data collection by cookies by managing, deactivating, or deleting cookies in your browser. However, some web design elements (usually fonts) contain data that cannot be deleted so easily. This is the case when data is automatically collected when a page is accessed and transmitted to a third-party provider (such as Google). In this case, please contact the support team of the relevant provider. In the case of Google, you can reach support at https://support.google.com/?hl=de.
Legal basis
If you have consented to the use of web design tools, this consent forms the legal basis for the corresponding data processing. According to Art. 6 (1) (a) GDPR (consent), this consent forms the legal basis for the processing of personal data, as may occur when it is collected by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The corresponding legal basis for this is Art. 6 (1) (f) GDPR (legitimate interests). However, we only use web design tools if you have given your consent. We would like to emphasize this again here.
Information on specific web design tools can be found in the following sections, if available.
Adobe Fonts Privacy Policy
We use Adobe Fonts, a web font hosting service, on our website. The service provider is the American company Adobe Inc. For the European region, the Irish company Adobe Systems Software Ireland Companies, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland, is responsible.
Adobe also processes your data in the USA, among other places. Adobe is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Adobe uses standard contractual clauses (Art. 46(2) and (3) GDPR). Standard contractual clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to and stored in third countries (such as the US). Through the EU-US Data Privacy Framework and the standard contractual clauses, Adobe undertakes to comply with European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the US. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
For more information on Adobe’s standard contractual clauses, please visit https://www.adobe.com/at/privacy/eudatatransfers.html.
You can find out more about the data processed when using Adobe Fonts in the privacy policy at https://www.adobe.com/at/privacy.html.
Google Fonts Privacy Policy
Google Fonts Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimization of our services
📓 Processed data: Data such as IP address and CSS and font requests
More details can be found further down in this privacy policy.
📅 Storage period: Font files are stored by Google for one year.
⚖️ Legal basis: Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (f) GDPR (legitimate interests)
What are Google Fonts?
We use Google Fonts on our website. These are the “Google fonts” from Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.
You do not need to register or enter a password to use Google fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google when using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will take a closer look at exactly how data storage works in detail.
Google Fonts (formerly Google Web Fonts) is a directory of over 800 fonts that Google makes available to its users free of charge.
Many of these fonts are published under the SIL Open Font License, while others are published under the Apache License. Both are free software licenses.
Why do we use Google Fonts on our website?
Google Fonts allows us to use fonts on our own website without having to upload them to our own server. Google Fonts is an important component in maintaining the high quality of our website. All Google fonts are automatically optimized for the web, which saves data volume and is a major advantage, especially for use on mobile devices. When you visit our site, the low file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems, and mobile devices can lead to errors. Such errors can sometimes distort text or entire web pages visually. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all popular browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can present our entire online service as beautifully and uniformly as possible.
What data does Google store?
When you visit our website, the fonts are downloaded via a Google server. This external call transmits data to Google’s servers. This also allows Google to recognize that you or your IP address has visited our website. The Google Fonts API was developed to reduce the use, storage, and collection of end-user data to what is necessary for the proper provision of fonts. API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.
Google Fonts stores CSS and font requests securely at Google and is therefore protected. The usage figures collected enable Google to determine how well the individual fonts are received. Google publishes the results on internal analysis pages, such as Google Analytics. Google also uses data from its own web crawler to determine which websites use Google fonts. This data is published in the Google Fonts BigQuery database. Entrepreneurs and developers use Google’s BigQuery web service to analyze and move large amounts of data.
However, it should be noted that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google servers. It is not clear whether this data is also stored, and Google does not communicate this clearly.
How long and where are the data stored?
For requests related to CSS assets, Google stores data for one day on its servers, which are primarily located outside the EU. This enables us to use the fonts via a Google stylesheet. A stylesheet is a formatting template that allows quick and simple changes to a website’s design or font.
The font files themselves are stored by Google for one year. Google’s goal is to generally improve the loading speed of websites. When millions of websites reference the same fonts, they are cached after the first visit and then load instantly on all other websites that the user accesses later. From time to time, Google updates font files to reduce file size, improve language coverage, and enhance overall design quality.
How can I delete my data or prevent data storage?
The data that Google stores for one day or one year cannot simply be deleted. The data is automatically transmitted to Google when the page is accessed. To have this data deleted prematurely, you must contact Google Support at https://support.google.com/?hl=de&tid=113080663. You can only prevent this data from being stored by not visiting our website.
Unlike other web fonts, Google allows us unrestricted access to all available fonts. This means we can access an unlimited selection of fonts and optimize our website’s design. You can find more information about Google Fonts and additional FAQs at https://developers.google.com/fonts/faq?tid=113080663. Google does address certain data protection topics there, but truly detailed information about data storage is not provided. It is relatively difficult to obtain precise information from Google about which data is stored.
Legal Basis
If you have consented to the use of Google Fonts, the legal basis for the corresponding data processing is your consent. According to Art. 6(1)(a) GDPR, this consent constitutes the legal basis for the processing of personal data that may occur when using Google Fonts.
Furthermore, we have a legitimate interest in using Google Fonts in order to optimize our online services. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate Interests). Nevertheless, we only use Google Fonts if you have provided your consent.
Google also processes some of your data in the United States, among other locations. Google is an active participant in the EU–US Data Privacy Framework, which regulates the proper and secure transfer of personal data from EU citizens to the United States. You can find more information at:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Google also uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission to ensure that your data complies with European data protection standards even when transferred to and stored in third countries (such as the United States). Through the EU–US Data Privacy Framework and the Standard Contractual Clauses, Google commits to upholding the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision of the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which reference the Standard Contractual Clauses, can be found at:
https://business.safety.google/intl/de/adsprocessorterms/
Information on which data Google generally collects and how this data is used can also be found at:
https://www.google.com/intl/de/policies/privacy/
Online Map Services – Introduction
Summary of the Online Map Services Privacy Policy
👥 Data Subjects: Visitors of the website
🤝 Purpose: Improving the user experience
📓 Processed Data: The data processed depends heavily on the services used. Typically, this includes IP address, location data, search queries, and/or technical data. More details can be found in the descriptions of the specific tools used.
📅 Storage Period: Depends on the tools used
⚖️ Legal Bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What Are Online Map Services?
We use online map services on our website as an extended service. Google Maps is likely the service you are most familiar with, but there are also other providers specializing in creating digital maps. Such services make it possible to display locations, route plans, or other geographic information directly on our website.
By integrating a map service, you no longer need to leave our website to view, for example, directions to a specific location. To enable the online map to function on our website, map sections are embedded using HTML code. These services can display road maps, the earth’s surface, or aerial and satellite images.
When you use the embedded map service, data is also transmitted to the respective tool and stored there. This data may include personal data.
Why Do We Use Online Map Services on Our Website?
Put simply, our goal is to offer you a pleasant experience on our website. Your experience is only truly pleasant if you can easily find your way around and quickly access all the information you need. That’s why we believe that integrating an online map system can significantly enhance our website’s service quality.
Without leaving our website, you can use the map system to view directions, locations, or even points of interest with ease. It is also extremely practical that you can instantly see where our company is located, ensuring that you can find us quickly and safely.
As you can see, there are many advantages, and we clearly consider online map services to be an important part of our customer service.
Which Data Is Stored by Online Map Services?
When you open a page on our website that includes an online map function, personal data may be transmitted to the respective service and stored there. In most cases, this involves your IP address, which can also be used to determine your approximate location. In addition to the IP address, data such as entered search terms as well as latitude and longitude coordinates are stored. For example, if you enter an address for route planning, this data will also be stored.
The data is not stored by us, but on the servers of the integrated tools. You can imagine it like this: you are on our website, but when you interact with a map service, this interaction technically takes place on that provider’s website.
To ensure that the service works properly, at least one cookie is usually set in your browser. Google Maps, for example, also uses cookies to record user behavior in order to optimize its own service and to display personalized advertising. You can find more information about cookies in our “Cookies” section.
How Long and Where Are the Data Stored?
Each online map service processes different user data. If we have additional information available, we provide details on the duration of data processing further below in the respective sections for each tool. In general, personal data is always retained only for as long as necessary to provide the service. Google Maps, for example, stores certain data for a defined period, while other data must be deleted manually by you. Mapbox, for instance, stores IP addresses for 30 days before deleting them. As you can see, each tool stores data for different lengths of time. We therefore recommend reviewing the privacy policies of the specific tools used.
The providers also use cookies to store information about your user behavior when interacting with the map service. You can find more general information about cookies in our “Cookies” section, and the privacy policies of the respective providers also explain which cookies may be used. In most cases, these lists are provided as examples and are not exhaustive.
Right to Object
You always have the option and the right to access your personal data and to object to its use and processing. You may also withdraw any consent you have previously given us at any time. In most cases, the easiest way to do this is via the cookie consent tool. However, there are also additional opt-out tools you can use. Any cookies set by the providers can also be managed, deleted, or disabled by you with just a few clicks. Please note that this may cause some functions of the service to no longer work as usual.
How you manage cookies in your browser depends on the browser you use. In the “Cookies” section, you will also find links to instructions for the most common browsers.
Legal Basis
If you have consented to the use of an online map service, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data that may occur when using an online map service.
We also have a legitimate interest in using an online map service in order to optimize the service on our website. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate Interests). However, we only use an online map service if you have given your consent. We want to explicitly emphasize this once again.
Information about specific online map services can be found—if available—in the following sections.
OpenStreetMap Privacy Policy
OpenStreetMap Privacy Policy Summary
👥 Affected parties: Visitors of the website
🤝 Purpose: Optimization of our service offering
📓 Processed data: Data such as IP address, browser information, operating system, content of the request, limited location and usage data
More details can be found further below in this privacy policy.
📅 Storage period: The IP address is deleted after 180 days
⚖️ Legal bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)
What is OpenStreetMap?
We have integrated map sections from the online mapping tool OpenStreetMap on our website. This is an open-source mapping system that we access via an API (interface). The service is provided by OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
By using this map function, your IP address is transmitted to OpenStreetMap. In this privacy policy, you will learn why we use functions of the OpenStreetMap tool, where data is stored, and how you can prevent this data storage.
The OpenStreetMap project was launched in 2004. The aim of the project was and still is to create a free world map. Users around the world collect data about buildings, forests, rivers, and roads. Over the years, this has created a comprehensive digital world map created entirely by users. Of course, the map is not fully complete, but it contains extensive data for most regions.
Why do we use OpenStreetMap on our website?
Our website is primarily intended to be helpful to you. In our view, it is helpful whenever information can be found quickly and easily. This naturally applies to our services and products, but we also want to provide you with additional useful information.
For this reason, we use the OpenStreetMap mapping service. It allows us to show you exactly how to find our company. The map displays the best route to us, making your journey effortless.
What data is stored by OpenStreetMap?
When you visit one of our web pages that includes OpenStreetMap, user data is transmitted to the service and stored there. OpenStreetMap collects information about your interactions with the digital map, your IP address, data about your browser, device type, operating system, as well as the date and time when you used the service. Tracking software is also used to record user interactions. According to the company’s own privacy policy, the analytics tool “Piwik” is used for this purpose.
The collected data is subsequently accessible to the respective working groups of the OpenStreetMap Foundation. According to the company, personal data is not shared with other individuals or businesses unless legally required. The third-party provider Piwik does store your IP address, but only in a shortened form.
The following cookie may be set in your browser when you interact with OpenStreetMap via our website:
Value: 9.63312%7C52.41500%7C17%7CM
Purpose: Required to unlock OpenStreetMap content.
Expiration: After 10 years
If you view the map in full screen mode, you will be redirected to the OpenStreetMap website. There, the following cookies may be stored in your browser:
Value: 148253113080663-2
Purpose: Ensures the operability of the map section.
Expiration: After 1 hour
Value: 1d9bfa122e0259d5f6db4cb8ef653a1c
Purpose: Used to store session information (e.g., user behavior).
Expiration: At the end of the session
Value: 4a5.1593684142.2.1593688396.1593688396113080663-9
Purpose: Set by Piwik to store or measure user data such as click behavior.
Expiration: After 1 year
How long and where is the data stored?
The API servers, databases, and auxiliary service servers are currently located in the United Kingdom (Great Britain and Northern Ireland) and the Netherlands. Your IP address and user information, which is stored in shortened form by the web analytics tool Piwik, is deleted after 180 days.
How can I delete my data or prevent data storage?
You have the right to access your personal data at any time and to object to its use and processing. You can manage, delete, or disable any cookies that may be set by OpenStreetMap directly in your browser at any time. However, doing so may result in the service no longer functioning to its full extent. The way cookies are managed, deleted, or disabled varies depending on the browser you use. In the “Cookies” section, you will find links to the relevant instructions for the most common browsers.
Legal Basis
If you have consented to the use of OpenStreetMap, this consent constitutes the legal basis for the corresponding data processing. According to Art. 6(1)(a) GDPR (consent), this consent provides the legal basis for the processing of personal data that may occur when OpenStreetMap collects data.
We also have a legitimate interest in using OpenStreetMap to optimize our online services. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). However, we only use OpenStreetMap if you have provided your consent. We want to explicitly emphasize this once again.
If you would like to learn more about how OpenStreetMap processes data, we recommend reading the company’s privacy policy at:
https://wiki.osmfoundation.org/wiki/Privacy_Policy.
Explanation of Terms Used
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, especially when dealing with technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or specific technical expressions (such as “cookies” or “IP address”). Nevertheless, we do not want to use these terms without providing an explanation.
Below you will find an alphabetical list of important terms used throughout this privacy policy, which we may not have explained in sufficient detail earlier. If these terms originate from the GDPR and constitute defined terms, we will also include the relevant GDPR text and, where appropriate, add our own explanations.
Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Explanation:
As a company and website operator, we are responsible for all data we process from you. In addition to controllers, there may also be so-called processors. This includes any company or individual that processes personal data on our behalf. Processors can therefore include service providers such as tax advisors, as well as hosting or cloud providers, payment providers, newsletter services, or large companies such as Google or Microsoft.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Explanation:
On websites, such consent is usually obtained through a cookie consent tool. You are certainly familiar with this: when you visit a website for the first time, you are typically asked via a banner whether you agree to the processing of your data. In most cases, you can also set individual preferences and decide which types of data processing you allow and which you do not. If you do not give consent, your personal data may not be processed.
Of course, consent can also be given in writing and not only through a tool.
Personal Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Explanation:
Personal data includes all information that can identify you as a person. This typically includes data such as:
According to the European Court of Justice (ECJ), your IP address also qualifies as personal data. IT experts can use your IP address to determine at least the approximate location of your device and, consequently, identify you as the connection owner. Therefore, the storage of an IP address also requires a legal basis under the GDPR.
There are also so-called “special categories” of personal data, which are particularly sensitive. These include:
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Explanation:
Profiling involves gathering various pieces of information about a person in order to learn more about them. In the online sector, profiling is often used for advertising purposes or creditworthiness checks. Web or advertising analytics tools, for example, collect data about your behaviour and interests on a website. From this data, a specific user profile is created, which allows advertising to be targeted to a relevant audience.
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Explanation:
In our case, we are responsible for the processing of your personal data and therefore the “controller”. If we transfer collected data to other service providers for processing, these providers become “processors”. For this purpose, a “data processing agreement (DPA)” must be signed.
Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Note:
When we refer to processing in our Privacy Policy, we mean any type of data processing. As outlined in the original GDPR definition above, this includes not only the collection but also the storage and handling of data.
Closing Remarks
Congratulations! If you are reading these lines, you have truly “fought” your way through our entire Privacy Policy – or at least scrolled down to this point. As you can see from the extent of this Privacy Policy, we take the protection of your personal data very seriously and not lightly at all.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. We do not only want to tell you which data is being processed, but also why we use various software tools. Privacy policies often sound very technical and legalistic. However, since most of you are neither web developers nor lawyers, we wanted to take a different linguistic approach and explain the matter in simple and clear terms. Of course, this is not always possible due to the nature of the topic. Therefore, we explain the most important terms again at the end of this Privacy Policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the responsible body. We wish you a pleasant time and hope to welcome you back on our website soon.
All texts are protected by copyright.
Source: Privacy Policy created with the Data Protection Generator by AdSimple.