Investing Retirement Subsidised Family
  • Financial calculator
  • quirion.ai
  • Financial knowledge
  • About quirion
Login Get the app Get started
  • Investing Build wealth for your most personal wishes and finest goals.
  • Retirement Subsidised With the state-subsidised Altersvorsorgedepot, the state adds to what you pay in.
  • Family Build wealth to give your children the future they deserve.
  • Financial calculator
  • quirion.ai
  • Financial knowledge
  • About quirion
Login

Everything you can do at quirion

  • Get your retirement subsidised With the retirement provision account you invest in the capital market with state support and build wealth for later.
  • Open an individual account With broadly diversified, continuously managed ETF portfolios you build long-term wealth for your goals and wishes. Start with a lump sum or add an ETF savings plan any time.
  • Open a joint account Save together for your goals and let your wealth grow as one.
  • Open a children’s account Whether it’s university, a year abroad or a driving licence — even small contributions can create big opportunities over many years.
  • Open an instant-access account Ideal for a rainy-day fund and short-term goals: your money stays flexibly available.
  • Save with Cash-Invest An alternative to call money for funds that should stay available short-term.
  • Invest sustainably Invest by sustainable criteria without giving up the opportunities of the capital market.
  • Invest in the Megatrends portfolio Bet deliberately on future themes such as technology, health or sustainability.
  • Invest in themes Invest deliberately in the themes you find exciting and consider relevant long-term.

Privacy Policy

Preamble

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to simply as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").

The terms used are not gender-specific.

Last updated: 09 January 2025

Table of Contents

  • Preamble
  • Controller
  • Contact Data Protection Officer
  • Overview of Processing Operations
  • Relevant Legal Bases
  • Security Measures
  • Transfer of Personal Data
  • International Data Transfers
  • General Information on Data Storage and Erasure
  • Rights of Data Subjects
  • Provision of the Online Offering and Web Hosting
  • Use of Cookies
  • Special Notes on Applications (Apps)
  • Obtaining Applications via App Stores
  • Blogs and Publication Media
  • Contact and Enquiry Management
  • Chatbots and Chat Functions
  • Artificial Intelligence (AI)
  • Video Conferences, Online Meetings, Webinars and Screen Sharing
  • Audio Content
  • Cloud Services
  • Newsletters and Electronic Notifications
  • Promotional Communication via Email, Post, Fax or Telephone
  • Web Analytics, Monitoring and Optimisation
  • Online Marketing
  • Affiliate Programmes and Affiliate Links
  • Customer Reviews and Rating Procedures
  • Presences in Social Networks (Social Media)
  • Plug-ins and Embedded Functions and Content
  • Amendment and Update
  • Definitions of Terms

Controller

quirion AG
Kurfürstendamm 119
10711 Berlin

Email address:
datenschutz@quirion.de

Legal notice:
https://www.quirion.de/impressum

Contact Data Protection Officer

datenschutz@quirion.de

Overview of Processing Operations

The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects concerned.

Types of data processed

  • Master data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Image and/or video recordings.
  • Audio recordings.
  • Event data (Facebook).
  • Log data.

Categories of data subjects

  • Recipients of services and clients.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.
  • Persons depicted.
  • Third parties.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Office and organisational procedures.
  • Conversion measurement.
  • Click tracking.
  • Audience building.
  • Affiliate tracking.
  • A/B tests.
  • Organisational and administrative procedures.
  • Feedback.
  • Heatmaps.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.
  • Public relations.
  • Sales promotion.
  • Artificial intelligence (AI).

Relevant Legal Bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6(1)(1)(a) GDPR) - The data subject has given their consent to the processing of their personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legitimate interests (Art. 6(1)(1)(f) GDPR) - processing is necessary to protect the legitimate interests of the controller or a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring the protection of personal data do not override them.

National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.

Note on the applicability of the GDPR and the Swiss FADP: These data protection notices serve to provide information both under the Swiss Federal Act on Data Protection (FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used owing to their broader geographical application and comprehensibility. In particular, instead of the terms "processing" of "personal data", "overriding interest" and "particularly sensitive personal data" used in the Swiss FADP, the terms used in the GDPR, namely "processing" of "personal data" as well as "legitimate interest" and "special categories of data", are used. However, the legal meaning of the terms continues to be determined under the Swiss FADP where the Swiss FADP applies.

Security Measures

In accordance with the legal requirements, and taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, transfer, availability and separation relating to it. Furthermore, we have set up procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to threats to the data. Moreover, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by data protection-friendly default settings.

Securing online connections using TLS/SSL encryption technology (HTTPS): In order to protect the data of users transmitted via our online services from unauthorised access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signalled by the display of HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.

Transfer of Personal Data

In the course of our processing of personal data, it may happen that this data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

International Data Transfers

Data processing in third countries: Insofar as we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or the processing takes place in the context of using third-party services or the disclosure or transfer of data to other persons, bodies or companies, this only takes place in accordance with the legal requirements. Insofar as the level of data protection in the third country has been recognised by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise ensured, in particular by standard contractual clauses (Art. 46(2)(c) GDPR), express consent or in the case of contractually or legally required transfer (Art. 49(1) GDPR). In addition, we will inform you of the bases for the transfer to third countries with the individual providers from the third country, whereby the adequacy decisions take priority as the basis. Information on transfers to third countries and existing adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de. Within the framework of the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognised the level of data protection for certain companies from the USA as secure within the framework of the adequacy decision of 10 July 2023. You can find the list of certified companies as well as further information on the DPF on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). As part of the data protection notices, we inform you which of the service providers we use are certified under the Data Privacy Framework.

General Information on Data Storage and Erasure

We erase personal data that we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there are no further legal bases for the processing. This concerns cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the pursuit of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.

Our data protection notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where there are multiple indications regarding the retention period or erasure deadlines for a piece of data, the longest period is always decisive.

If a period does not expressly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships within which data is stored, the event triggering the period is the point at which the termination or other conclusion of the legal relationship takes effect.

Data that is no longer retained for the originally intended purpose but on the basis of legal requirements or other reasons is processed by us exclusively for the reasons that justify its retention.

Further notes on processing operations, procedures and services:

Retention and erasure of data: The following general periods apply to retention and archiving under German law:

  • 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets as well as the work instructions and other organisational documents required to understand them, accounting vouchers and invoices (§ 147(3) in conjunction with (1) nos. 1, 4 and 4a AO, § 14b(1) UStG, § 257(1) nos. 1 and 4, (4) HGB).
  • 8 years - Accounting vouchers, such as invoices and expense receipts (§ 147(1) nos. 4 and 4a in conjunction with (3) sentence 1 AO and § 257(1) no. 4 in conjunction with (4) HGB).
  • 6 years - Other business documents: received commercial or business letters, copies of dispatched commercial or business letters, other documents insofar as they are of significance for taxation, e.g. hourly wage slips, cost accounting sheets, calculation documents, price labels, but also payroll accounting documents insofar as they are not already accounting vouchers, and till rolls (§ 147(3) in conjunction with (1) nos. 2, 3, 5 AO, § 257(1) nos. 2 and 3, (4) HGB).
  • 3 years - Data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related enquiries, based on past business experience and standard industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).

Rights of Data Subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain access to this data as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
  • Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you habitually reside, the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Provision of the Online Offering and Web Hosting

We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Log data (e.g. log files concerning logins or the retrieval of data or access times.).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers etc.).). Security measures.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also known as a "web host"); Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful access, the browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. On the one hand, server log files can be used for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and on the other hand to ensure the utilisation of the servers and their stability; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.

Use of Cookies

Cookies are small text files, or other storage markers, that store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping cart in an e-shop, the content accessed or functions used within an online offering. Cookies can also be used for various purposes, e.g. for the functionality, security and comfort of online offerings as well as for creating analyses of visitor flows.

Notes on consent: We use cookies in accordance with the legal provisions. We therefore obtain prior consent from users, unless this is not required by law. Consent is, in particular, not necessary if the storing and reading of information, including cookies, is strictly necessary in order to provide users with a telemedia service (i.e. our online offering) that they have expressly requested. Strictly necessary cookies generally include cookies with functions that serve the display and operability of the online offering, load balancing, security, the storage of users' preferences and choices, or similar purposes related to the provision of the main and ancillary functions of the online offering requested by the users. Revocable consent is clearly communicated to users and contains the information on the respective cookie use.

Notes on legal bases under data protection law: The legal basis under data protection law on which we process users' personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the business operation of our online offering and the improvement of its usability) or, if this is done in the context of fulfilling our contractual obligations, if the use of cookies is necessary in order to fulfil our contractual obligations. We provide information about the purposes for which we process cookies in the course of this privacy policy or within the framework of our consent and processing operations.

Storage period: With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are erased at the latest after a user has left an online offering and closed their end device (e.g. browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device has been closed. For example, the login status can be stored or preferred content can be displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Insofar as we do not provide users with explicit information about the type and storage period of cookies (e.g. as part of obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.

General notes on withdrawal and objection (opt-out): Users can withdraw the consent they have given at any time and also object to processing in accordance with the legal requirements in Art. 21 GDPR. Users can also declare their objection via their browser settings, e.g. by deactivating the use of cookies (although this may also restrict the functionality of our online services). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/ declared.

  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).

Further notes on processing operations, procedures and services:

  • Processing of cookie data on the basis of consent: We use a consent management solution by which users' consent to the use of cookies or to the procedures and providers named within the consent management solution is obtained. This procedure serves to obtain, log, manage and withdraw consents, in particular with regard to the use of cookies and comparable technologies used to store, read and process information on users' end devices. As part of this procedure, users' consents for the use of cookies and the associated processing of information, including the specific processing and providers named in the consent management procedure, are obtained. Users also have the option of managing and withdrawing their consents. The declarations of consent are stored in order to avoid having to request them again and to be able to provide proof of consent in accordance with the legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. Insofar as there is no specific information about the providers of consent management services, the following general notes apply: The consent is stored for a period of up to two years. In this process, a pseudonymous user identifier is created, which is stored together with the time of consent, the details of the scope of consent (e.g. relevant categories of cookies and/or service providers) as well as information about the browser, the system and the end device used; Legal bases: Consent (Art. 6(1)(1)(a) GDPR).
  • Cookiebot: Consent management; procedure for obtaining, logging, managing and withdrawing consents, in particular for the use of cookies and similar technologies for the storage, reading and processing of information on users' end devices as well as their processing; Service provider: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark; Website: https://www.cookiebot.com/de; Privacy policy: https://www.cookiebot.com/de/privacy-policy/; Data processing agreement: Provided by the service provider; Further information: Stored data (on the service provider's server): the user's IP number in anonymised form (the last three digits are set to 0), date and time of consent, browser details, the URL from which consent was sent, an anonymous, random and encrypted key value, the user's consent status.

Special Notes on Applications (Apps)

We process the data of users of our application insofar as this is necessary in order to provide users with the application and its functionalities, monitor its security and develop it further. We may also contact users in compliance with the legal requirements, insofar as the communication is necessary for the administration or use of the application. In all other respects, with regard to the processing of users' data, we refer to the data protection notices in this privacy policy.

Legal bases: The processing of data required for the provision of the functionalities of the application serves the fulfilment of contractual obligations. This also applies if the provision of the functions requires an authorisation from users (e.g. release of device functions). Insofar as the processing of data is not required for the provision of the functionalities of the application but serves the security of the application or our business interests (e.g. collection of data for the purposes of optimising the application or for security purposes), it takes place on the basis of our legitimate interests. Insofar as users are expressly asked for their consent to the processing of their data, the processing of the data covered by the consent takes place on the basis of consent.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category). Audio recordings.
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures. Provision of our online offering and user-friendliness.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).

Further notes on processing operations, procedures and services:

  • Commercial use: We process the data of users of our application, registered users and any test users (hereinafter uniformly referred to as "users") in order to be able to provide our contractual services to them, as well as on the basis of legitimate interests in order to be able to ensure the security of our application and develop it further. The required information is marked as such in the context of the usage, order, purchase or comparable conclusion of a contract and may include the information required for the provision of services and any billing, as well as contact information in order to be able to hold any consultations; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).
  • Storage of a universally unique identifier (UUID): For the purposes of analysing the use and functionality of the application as well as storing users' settings, the application stores a so-called universally unique identifier (UUID). This identifier is generated when this application is installed (but is not linked to the device, i.e. it is not a device identifier in this sense), remains stored between the start of the application and its updates, and is erased when users remove the application from their device.
  • Storage of a pseudonymous identifier: In order for us to be able to provide the application and ensure its functionality, we use a pseudonymous identifier. The identifier is a mathematical value (i.e. no clear data such as names is used) that is assigned to a device and/or the installation of the application installed on it. This identifier is generated when this application is installed, remains stored between the start of the application and its updates, and is erased when users remove the application from the device.
  • Device permissions for access to functions and data: The use of our application or its functionalities may require permissions from users for access to certain functions of the devices used or to the data stored on the devices or accessible with the help of the devices. By default, these permissions must be granted by users and can be withdrawn at any time in the settings of the respective devices. The exact procedure for controlling app permissions may depend on the users' device and software. If users require an explanation, they can contact us. We point out that the refusal or withdrawal of the respective permissions may affect the functionality of our application.
  • Use of microphone functions: In the context of using our application, the microphone functions and the audio recordings captured with their help are processed. The use of the microphone functions requires a permission from users, which can be withdrawn at any time. The use of the microphone functions and audio data serves in each case only to provide the respective functionality of our application, in accordance with its description to users or its typical and expected mode of operation.
  • No location history and no movement profiles: Location data is only used selectively and is not processed to create a location history or a movement profile of the devices used or their users.
  • AppsFlyer: AppsFlyer provides attribution and marketing analytics services that enable advertisers and developers to measure and analyse the effectiveness of their marketing campaigns by understanding which marketing campaigns contributed to the download/installation of their mobile applications or another conversion metric (e.g. relaunch of the application); and to measure and analyse certain events and actions within their application or websites, such as in-app purchases made by end users; AppsFlyer also helps us to detect and protect against abusive behaviour in connection with our marketing campaigns; Service provider: AppsFlyer Inc., 100 First Street, Suite 2500, San Francisco, California 94105, USA; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website:https://www.appsflyer.com/; Privacy policy:https://www.appsflyer.com/legal/privacy-policy/; Data processing agreement:https://www.appsflyer.com/legal/dpa/.Basis for third-country transfers: Standard contractual clauses (https://www.appsflyer.com/legal/dpa/).

Obtaining Applications via App Stores

Our application is obtained via special online platforms operated by other service providers (so-called "app stores"). In this context, in addition to our data protection notices, the data protection notices of the respective app stores apply. This applies in particular with regard to the procedures for reach measurement and interest-based marketing used on the platforms as well as any charges.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Recipients of services and clients. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; marketing. Provision of our online offering and user-friendliness.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Apple App Store: App and software sales platform; Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.apple.com/de/ios/app-store/; Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
  • Google Play: App and software sales platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://play.google.com/store/apps?hl=de; Privacy policy: https://policies.google.com/privacy.

Blogs and Publication Media

We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). The data of readers is processed for the purposes of the publication medium only insofar as this is necessary for its presentation and communication between authors and readers or for security reasons. In all other respects, we refer to the information on the processing of visitors to our publication medium in the context of these data protection notices.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Feedback (e.g. collecting feedback via an online form); provision of our online offering and user-friendliness; security measures. Organisational and administrative procedures.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).

Further notes on processing operations, procedures and services:

  • Comments and contributions: When users leave comments or other contributions, their IP addresses may be stored on the basis of our legitimate interests. This is done for our security in the event that someone leaves unlawful content in comments and contributions (insults, prohibited political propaganda etc.). In this case, we ourselves may be held liable for the comment or contribution and are therefore interested in the identity of the author.
    Furthermore, we reserve the right to process users' details for the purpose of spam detection on the basis of our legitimate interests.
    On the same legal basis, we reserve the right to store users' IP addresses for the duration of surveys and to use cookies in order to avoid multiple votes.
    The personal information, any contact and website information as well as the content details communicated in the context of comments and contributions are stored by us permanently until the users object; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Zendesk: Management of contact enquiries and communication; Service provider: Zendesk, Inc., 989 Market Street #300, San Francisco, CA 94102, USA; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.zendesk.de; Privacy policy: https://www.zendesk.de/company/customers-partners/privacy-policy/; Data processing agreement: https://www.zendesk.de/company/data-processing-form/. Basis for third-country transfers: Data Privacy Framework (DPF).

Contact and Enquiry Management

When you contact us (e.g. by post, contact form, email, telephone or via social media) as well as in the context of existing user and business relationships, the details of the enquiring persons are processed insofar as this is necessary to respond to the contact enquiries and any requested measures.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Communication partners; users (e.g. website visitors, users of online services).
  • Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online offering and user-friendliness.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).

Further notes on processing operations, procedures and services:

  • SugarCRM and SugarMarket: SugarCRM: customer and prospect management system including the mapping of advisory processes; complaint, claim and data protection management, legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR). SugarMarket: marketing campaign management. Legal bases: consent (Art. 6(1)(a) GDPR).
  • Contact form: When you contact us via our contact form, by email or by other means of communication, we process the personal data transmitted to us in order to respond to and handle the respective request. This generally includes information such as name, contact information and, where applicable, further information communicated to us and required for appropriate processing. We use this data exclusively for the stated purpose of making contact and communicating; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Zendesk: Management of contact enquiries and communication; Service provider: Zendesk, Inc., 989 Market Street #300, San Francisco, CA 94102, USA; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.zendesk.de; Privacy policy: https://www.zendesk.de/company/customers-partners/privacy-policy/; Data processing agreement: https://www.zendesk.de/company/data-processing-form/. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Solvemate: Chatbot and assistance software as well as connected services; Service provider: Dixa Aps, Vimmelskaftet 41A, 1 Sal, 1161 København, Denmark; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.dixa.com/solvemate-by-dixa/; Privacy policy: https://www.dixa.com/legal/privacy/. Data processing agreement: https://www.dixa.com/legal/data-processing-agreement/.

Chatbots and Chat Functions

We offer online chats and chatbot functions (together referred to as "chat services") as a means of communication. A chat is an online conversation conducted with a certain immediacy. A chatbot is software that answers users' questions or informs them via messages. When you use our chat functions, we may process your personal data.

If you use our chat services within an online platform, your identification number within the respective platform is additionally stored. We may also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to provide proof of them in accordance with the legal requirements.

We point out to users that the respective platform provider can find out that and when users communicate with our chat services, and can collect technical information about the user's device and, depending on the settings of their device, also location information (so-called metadata) for the purposes of optimising the respective services and for security purposes. Likewise, the metadata of communication via chat services (i.e. for example the information about who communicated with whom) could be used by the respective platform providers in accordance with their provisions, to which we refer for further information, for marketing purposes or to display advertising tailored to users.

Insofar as users agree to a chatbot activating information with regular messages, they have the option at any time to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. When the chatbot messages are unsubscribed, users' data is erased from the directory of message recipients.

We use the aforementioned information in order to operate our chat services, e.g. to address users personally, to answer their enquiries, to transmit any requested content and also to improve our chat services (e.g. to "teach" chatbots answers to frequently asked questions or to identify unanswered enquiries).

Notes on legal bases: We use the chat services on the basis of consent if we have previously obtained users' permission to process their data in the context of our chat services (this applies in cases where users are asked for consent, e.g. so that a chatbot sends them regular messages). Insofar as we use chat services to answer users' enquiries about our services or our company, this takes place for contractual and pre-contractual communication. In all other respects, we use chat services on the basis of our legitimate interests in optimising the chat services, their business efficiency and increasing the positive user experience.

Withdrawal, objection and erasure: You can withdraw any consent given at any time or object to the processing of your data in the context of our chat services.

  • Types of data processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Communication partners; users (e.g. website visitors, users of online services).
  • Purposes of processing: Contact enquiries and communication; direct marketing (e.g. by email or post).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Solvemate: Chatbot and assistance software as well as connected services; Service provider: Solvemate GmbH, Friedrichstraße 123, 10117 Berlin, Germany; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.solvemate.com/de/; Privacy policy: https://www.solvemate.com/de/legal#privacy.

Artificial Intelligence (AI)

We use artificial intelligence (AI), whereby personal data is processed. The specific purposes and our interest in the use of AI are set out below. By AI, in accordance with the term of an "AI system" pursuant to Article 3(1) of the AI Regulation, we understand a machine-based system that is designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for the inputs it receives, produces outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

Our AI systems are used in strict compliance with the legal requirements. These comprise both specific provisions for artificial intelligence and data protection requirements. In doing so, we adhere in particular to the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimisation and integrity as well as confidentiality. We ensure that the processing of personal data always takes place on a legal basis. This can be either the consent of the data subjects or a legal permission.

When using external AI systems, we carefully select their providers (hereinafter "AI providers"). In accordance with our legal obligations, we ensure that the AI providers comply with the applicable provisions. Likewise, we observe the obligations incumbent upon us when using or operating the AI services obtained. The processing of personal data by us and the AI providers takes place exclusively on the basis of consent or legal authorisation. In doing so, we place particular emphasis on transparency, fairness and the maintenance of human oversight of AI-supported decision-making processes.

To protect the processed data, we implement appropriate and robust technical and organisational measures. These ensure the integrity and confidentiality of the processed data and minimise potential risks. Through regular reviews of the AI providers and their services, we ensure ongoing compliance with current legal and ethical standards.

  • Types of data processed: Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Users (e.g. website visitors, users of online services). Third parties.
  • Purposes of processing: Artificial intelligence (AI).
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • ChatGPT: AI-based service designed to understand and generate natural language and related inputs and data, analyse information and make predictions ("AI", i.e. "artificial intelligence", is to be understood in the respective applicable legal sense of the term); Service provider: OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, D01 YC43 Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://openai.com/product; Privacy policy: https://openai.com/de/policies/eu-privacy-policy. Option to object (opt-out): https://docs.google.com/forms/d/e/1FAIpQLSevgtKyiSWIOj6CV6XWBHl1daPZSOcIWzcUYUXQ1xttjBgDpA/viewform.
  • OpenAI API: An AI API that provides developers with access to a variety of powerful language and image models, including GPT-4 and DALL-E. The OpenAI API makes it possible to integrate complex tasks such as text generation, language processing and image analysis into applications; Service provider: OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, D01 YC43 Dublin 1, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://openai.com/product; Privacy policy: https://openai.com/de/policies/eu-privacy-policy; Data processing agreement: https://openai.com/policies/data-processing-addendum; Basis for third-country transfers: Standard contractual clauses (https://openai.com/policies/data-processing-addendum). Option to object (opt-out): https://docs.google.com/forms/d/e/1FAIpQLSevgtKyiSWIOj6CV6XWBHl1daPZSOcIWzcUYUXQ1xttjBgDpA/viewform.

Video Conferences, Online Meetings, Webinars and Screen Sharing

We use platforms and applications from other providers (hereinafter referred to as "conference platforms") for the purposes of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as "conference"). When selecting the conference platforms and their services, we observe the legal requirements.

Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of the participants named below. The scope of the processing depends, on the one hand, on which data is required in the context of a specific conference (e.g. provision of access data or real names) and which optional details are provided by the participants. In addition to processing for the purpose of conducting the conference, participants' data may also be processed by the conference platforms for security purposes or service optimisation. The data processed includes personal data (first name, surname), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants' end devices, their operating system, the browser and its technical and language settings, information on the content-related communication processes, i.e. entries in chats as well as audio and video data, and also the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.

Logging and recordings: If text entries, participation results (e.g. from surveys) as well as video or audio recordings are logged, this is transparently communicated to the participants in advance and they are – where necessary – asked for their consent.

Data protection measures of the participants: Regarding the details of the processing of your data by the conference platforms, please refer to their data protection notices and, within the settings of the conference platforms, select the security and data protection settings that are optimal for you. Please also ensure, for the duration of a video conference, the protection of data and privacy in the background of your recording (e.g. by informing housemates, locking doors and using, insofar as technically possible, the function for obscuring the background). Links to the conference rooms as well as access data may not be passed on to unauthorised third parties.

Notes on legal bases: Insofar as, in addition to the conference platforms, we also process users' data and ask users for their consent to the use of the conference platforms or certain functions (e.g. agreement to a recording of conferences), the legal basis for processing is this consent. Furthermore, our processing may be necessary for the fulfilment of our contractual obligations (e.g. in participant lists, in the case of the follow-up of conversation results etc.). In all other respects, users' data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.

  • Types of data processed: Master data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Communication partners; users (e.g. website visitors, users of online services); persons depicted.
  • Purposes of processing: Provision of contractual services and customer service; contact enquiries and communication; office and organisational procedures.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Microsoft Teams: Conference and communication software; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://www.microsoft.com/de-de/microsoft-365; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement, security notices: https://www.microsoft.com/de-de/trustcenter; Standard contractual clauses (ensuring the level of data protection in the case of processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.
  • Zoom: Conference and communication software; Service provider: Zoom Video Communications, Inc., 55 Almaden Blvd., Suite 600, San Jose, CA 95113, USA; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://zoom.us; Privacy policy: https://zoom.us/docs/de-de/privacy-and-legal.html; Data processing agreement: https://zoom.us/docs/de-de/privacy-and-legal.html (referred to as Global DPA); Standard contractual clauses (ensuring the level of data protection in the case of processing in third countries): https://zoom.us/docs/de-de/privacy-and-legal.html (referred to as Global DPA).

Audio Content

We use hosting and analytics offerings from service providers in order to offer our audio content for listening or download and to obtain statistical information on the retrieval of the audio content.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); provision of our online offering and user-friendliness.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); consent (Art. 6(1)(1)(a) GDPR).

Further notes on processing operations, procedures and services:

  • YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Privacy policy: https://policies.google.com/privacy; Option to object (opt-out): https://adssettings.google.com/authenticated.
  • Apple Podcasts: Podcast hosting and statistical analysis of podcast retrievals; Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Website: https://www.apple.com/de/apple-podcasts/; Privacy policy: https://www.apple.com/de/legal/privacy/.
  • Google Podcasts: Podcast hosting and statistical analysis of podcast retrievals; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://podcasts.google.com/; Privacy policy: https://policies.google.com/privacy.
  • Amazon: Marketing of advertising media and advertising space; Service provider: Amazon EU S.à r.l. (Société à responsabilité limitée), 38 avenue John F. Kennedy, L-1855 Luxembourg; legal bases: consent (Art. 6(1)(1)(a) GDPR); Website: https://www.amazon.de; Privacy policy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.

Cloud Services

We use software services that are accessible via the internet and run on the servers of their providers (so-called "cloud services", also referred to as "software as a service") for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with certain recipients or publication of content and information).

In this context, personal data may be processed and stored on the providers' servers, insofar as this data is part of communication processes with us or is otherwise processed by us, as set out in this privacy policy. This data may include, in particular, users' master data and contact data, data on transactions, contracts, other processes and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and service optimisation.

Insofar as we use the cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users' devices for the purposes of web analytics or in order to remember users' settings (e.g. in the case of media control).

  • Types of data processed: Master data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Customers; employees (e.g. staff, applicants, former employees); prospective customers; communication partners.
  • Purposes of processing: Office and organisational procedures; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers etc.).).
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Microsoft cloud services: Cloud storage, cloud infrastructure services and cloud-based application software; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://microsoft.com/de-de; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement, security notices: https://www.microsoft.com/de-de/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA; Standard contractual clauses (ensuring the level of data protection in the case of processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Newsletters and Electronic Notifications

We send newsletters, emails and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or on the basis of a legal basis. Insofar as the contents of a newsletter are named in the context of a subscription to it, these contents are decisive for the consent of the users. To subscribe to our newsletter, it is normally sufficient to provide your email address. However, in order to be able to offer you a personalised service, we may ask you to provide your name for a personal salutation in the newsletter or for further information if this is necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before we erase them, in order to be able to provide proof of consent formerly given. The processing of this data is restricted to the purpose of a potential defence against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (so-called "blocklist").

The logging of the subscription process takes place on the basis of our legitimate interests for the purpose of providing proof that it was carried out properly. Insofar as we commission a service provider with the sending of emails, this takes place on the basis of our legitimate interests in an efficient and secure sending system.

Content:

Information about us, our services, campaigns and offers.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); contact data (e.g. postal and email addresses or telephone numbers); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Communication partners. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Direct marketing (e.g. by email or post); provision of contractual services and fulfilment of contractual obligations; reach measurement (e.g. access statistics, recognition of returning visitors). Provision of our online offering and user-friendliness.
  • Retention and erasure: 3 years - Contractual claims (AT) (Data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related enquiries, based on past business experience and standard industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 1478, 1480 ABGB).). 10 years - Contractual claims (CH) (Data required to consider potential compensation claims or similar contractual claims and rights, as well as for processing related enquiries, based on past business experience and standard industry practices, is stored for the period of the statutory limitation period of ten years, unless a shorter period of 5 years is decisive, which applies in certain cases (Art. 127, 130 OR)).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR).
  • Option to object (opt-out): You can cancel the receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can otherwise use one of the contact options given above, preferably email, for this purpose.

Further notes on processing operations, procedures and services:

  • Measurement of open and click rates: The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is retrieved from our server or, if we use a dispatch service provider, from its server when the newsletter is opened. As part of this retrieval, technical information such as details of the browser and your system, as well as your IP address and the time of retrieval, is first collected. This information is used for the technical improvement of our newsletter on the basis of the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined with the help of the IP address) or the access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The information is assigned to the individual newsletter recipients and stored in their profiles until erasure. The evaluations serve to recognise the reading habits of our users and to adapt our content to them or to send different content in accordance with the interests of our users. The measurement of open and click rates as well as the storage of the measurement results in users' profiles and their further processing takes place on the basis of users' consent. A separate withdrawal of the performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be cancelled or objected to. In this case, the stored profile information is erased; Legal bases: Consent (Art. 6(1)(1)(a) GDPR).
  • Precondition for using free services: Consent to the sending of mailings can be made a precondition for using free services (e.g. access to certain content or participation in certain campaigns). Insofar as users wish to use the free service without subscribing to the newsletter, we ask you to contact us.
  • Reminder emails regarding the order process: If users do not complete an order process, we can remind users of the order process by email and send them a link to continue it. This function can be useful, for example, if the purchase process could not be continued due to a browser crash, oversight or forgetfulness. The dispatch takes place on the basis of consent, which users can withdraw at any time; Legal bases: Consent (Art. 6(1)(1)(a) GDPR).
  • Google Analytics: We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to assign analytics information to an end device in order to recognise which content the users have accessed within one or various usage processes, which search terms they have used, have accessed this again or have interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of the users who refer to our online offering and technical aspects of their end devices and browsers.
    In this process, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively for this derivation of geolocation data before it is immediately deleted. It is not logged, is not accessible and is not used for further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF); Option to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing as well as the data processed).

Promotional Communication via Email, Post, Fax or Telephone

We process personal data for the purposes of promotional communication, which can take place via various channels, such as email, telephone, post or fax, in accordance with the legal requirements.

Recipients have the right to withdraw consent given at any time or to object to the promotional communication at any time.

After withdrawal or objection, we store the data required to provide proof of the previous authorisation for contacting or sending for up to three years after the end of the year of the withdrawal or objection on the basis of our legitimate interests. The processing of this data is restricted to the purpose of a possible defence against claims. On the basis of the legitimate interest in permanently observing users' withdrawal or objection, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g. by email or post); marketing. Sales promotion.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).

Web Analytics, Monitoring and Optimisation

Web analytics (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and can include behaviour, interests or demographic information about the visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online offering or its functions or content are most frequently used, or invite reuse. Likewise, it is possible for us to understand which areas require optimisation.

In addition to web analytics, we may also use testing procedures in order, for example, to test and optimise different versions of our online offering or its components.

Unless otherwise stated below, for these purposes profiles, i.e. data aggregated into a usage process, may be created and information may be stored in a browser or an end device and then read out. The information collected includes, in particular, websites visited and elements used there as well as technical information, such as the browser used, the computer system used and information on usage times. Insofar as users have agreed to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, users' IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. Generally, no clear data of users (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that we and the providers of the software used do not know the actual identity of the users, but only the details stored in their profiles for the purpose of the respective procedures.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis for data processing is the consent. Otherwise, the user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); click tracking; A/B tests; feedback (e.g. collecting feedback via an online form); heatmaps (mouse movements on the part of users, which are combined into an overall picture.); marketing. Provision of our online offering and user-friendliness.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years.).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Firebase: Google Firebase is a platform for developers of applications ("apps" for short) for mobile devices and websites. Google Firebase offers a variety of functions for testing apps, monitoring their functionality and optimising them (which are presented on the following overview page: https://firebase.google.com/products-build). The functions include, among other things, the storage of apps including personal data of the application users, such as content they have created or information concerning their interaction with the apps (so-called "cloud computing"). Google Firebase also offers interfaces that allow interaction between the users of the app and other services, e.g. authentication by means of services such as Facebook, Twitter or by means of an email-password combination; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://firebase.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Google Analytics: We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to assign analytics information to an end device in order to recognise which content the users have accessed within one or various usage processes, which search terms they have used, have accessed this again or have interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of the users who refer to our online offering and technical aspects of their end devices and browsers. In this process, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively for this derivation of geolocation data before it is immediately deleted. It is not logged, is not accessible and is not used for further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF); Option to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing as well as the data processed).
  • Google as the recipient of consent: The consent given by users in the context of a consent dialogue (also known as "cookie opt-in/consent", 'cookie banner', etc.) serves several purposes. On the one hand, it serves us to fulfil our obligation to obtain consent for the storage and reading of information on and from the user's end device (in accordance with the ePrivacy Directives). On the other hand, it covers the processing of users' personal data in accordance with the data protection requirements. In addition, this consent also applies to Google, as the company is obliged under the Digital Markets Act to obtain consent for personalised services. We therefore share the status of the consents given by users with Google. Our consent management software informs Google whether consents have been given or not. The aim is to ensure that the consents given or not given by users are taken into account when using Google Analytics and when integrating functions and external services. In this way, users' consents and their withdrawal can be adjusted dynamically and depending on the user's selection in the context of Google Analytics and other Google services within our online offering; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://support.google.com/analytics/answer/9976101?hl=de. Privacy policy: https://policies.google.com/privacy.
  • Google Tag Manager: We use Google Tag Manager, a software from Google that enables us to centrally manage so-called website tags via a user interface. Tags are small code elements on our website that serve to capture and analyse visitor activities. This technology supports us in improving our website and the content offered on it. Google Tag Manager itself does not create any user profiles, does not store any cookies with user profiles and does not carry out any independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when using Google Tag Manager, the user's IP address is transmitted to Google, which is necessary for technical reasons in order to implement the services we use. Cookies may also be set in the process. However, this data processing only takes place if services are integrated via the Tag Manager. For more detailed information on these services and their data processing, we refer to the further sections of this privacy policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement: 
    https://business.safety.google/adsprocessorterms. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Mouseflow: The data processing serves the purpose of analysing websites and their visitors (heatmaps and click tracking). For this purpose, cookies may be used and user profiles created. In the process, a log of mouse movements and clicks is created with the intention of replaying individual website visits on a random-sample basis and deriving potential improvements for the website from them. The data collected with Mouseflow is not used, without the user's separately given consent, to personally identify the user and is not combined with personal data about the bearer of the pseudonym; Service provider: Mouseflow ApS, Flaesketorvet 68, 1711 Copenhagen, Denmark; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://mouseflow.com/de/; Privacy policy: https://mouseflow.com/legal/visitor/. Option to object (opt-out): https://mouseflow.com/de/opt-out/.

Online Marketing

We process personal data for the purpose of online marketing, which can include, in particular, the marketing of advertising space or the display of promotional and other content (collectively referred to as "content") based on potential interests of users as well as the measurement of their effectiveness.

For these purposes, so-called user profiles are created and stored in a file (the so-called "cookie") or similar procedures are used, by means of which the details relevant for the display of the aforementioned content are stored about the user. This may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information, such as the browser used, the computer system used as well as information on usage times and functions used. Insofar as users have consented to the collection of their location data, this may also be processed.

In addition, users' IP addresses are stored. However, we use available IP masking procedures (i.e. pseudonymisation by shortening the IP address) to protect users. Generally, no clear data of users (such as email addresses or names) is stored in the context of the online marketing procedure, but rather pseudonyms. This means that we and the providers of the online marketing procedures do not know the actual user identity, but only the details stored in their profiles.

The information in the profiles is generally stored in the cookies or by means of similar procedures. These cookies can later generally also be read out on other websites that use the same online marketing procedure and analysed for the purpose of displaying content as well as supplemented with further data and stored on the server of the online marketing procedure provider.

In exceptional cases, it is possible to assign clear data to the profiles, primarily if the users are, for example, members of a social network whose online marketing procedure we use and the network links the user profiles with the aforementioned details. We ask you to note that users can make additional arrangements with the providers, for example by consenting in the context of registration.

In principle, we only receive access to aggregated information about the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to a conclusion of a contract with us. The conversion measurement is used solely for the success analysis of our marketing measures.

Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis for data processing is the permission. Otherwise, users' data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Notes on withdrawal and objection:

We refer to the data protection notices of the respective providers and the options to object (so-called "opt-out") specified for the providers. Insofar as no explicit opt-out option has been specified, there is, on the one hand, the possibility for you to switch off cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered in summary form directed at the respective regions:

a) Europe: https://www.youronlinechoices.eu.

b) Canada: https://www.youradchoices.ca/choices.

c) USA: https://www.aboutads.info/choices.

d) Cross-regional: https://optout.aboutads.info.

  • Types of data processed: Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Event data (Facebook) ("Event data" is information that is sent to the provider Meta, for example via Meta Pixel (whether via apps or other channels), and relates to persons or their actions. This data includes, for example, details of website visits, interactions with content and functions, app installations as well as product purchases. The processing of the event data takes place with the aim of creating target groups for content and advertising messages (Custom Audiences). It is important to note that event data does not include actual content such as comments written, no login information and no contact information such as names, email addresses or telephone numbers. "Event data" is deleted by Meta after a maximum of two years, and the target groups formed from it disappear with the deletion of our Meta user accounts.).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behaviour-based profiling, use of cookies); conversion measurement (measurement of the effectiveness of marketing measures); audience building; marketing; profiles with user-related information (creating user profiles); provision of our online offering and user-friendliness. Click tracking.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years.).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Meta Pixel and audience building (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting event data or contact information by means of interfaces in apps), it is possible for the company Meta, on the one hand, to determine the visitors to our online offering as a target group for the display of advertisements (so-called "Meta Ads"). Accordingly, we use the Meta Pixel in order to display the Meta Ads placed by us only to those users on Meta platforms and within the services of the partners cooperating with Meta (so-called "Audience Network" https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interest in certain topics or products, which becomes apparent from the websites visited) that we transmit to Meta (so-called "Custom Audiences"). With the help of the Meta Pixel, we also want to ensure that our Meta Ads correspond to the potential interest of users and do not have a harassing effect. With the help of the Meta Pixel, we can also understand the effectiveness of the Meta Ads for statistical and market research purposes by seeing whether users were forwarded to our website after clicking on a Meta Ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Data processing agreement:  https://www.facebook.com/legal/terms/dataprocessing; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Users' event data, i.e. behaviour and interest details, is processed for the purposes of targeted advertising and audience building on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum) processed. The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which relates in particular to the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites etc.) so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether the users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing as well as the data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
  • LinkedIn Insight Tag: Code that is loaded when a user visits our online offering and tracks the user's behaviour and conversions as well as storing them in a profile (possible purposes of use: measurement of campaign performance, optimisation of ad delivery, building of custom and similar audiences); Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.linkedin.com; Privacy policy:    https://www.linkedin.com/legal/privacy-policy, cookie policy: https://www.linkedin.com/legal/cookie_policy Data processing agreement: https://www.linkedin.com/legal/l/dpa Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
  • Microsoft Advertising: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites etc.) so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether the users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website:  https://about.ads.microsoft.com/en-us Privacy policy: https://privacy.microsoft.com/de-de/privacystatement; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://account.microsoft.com/privacy/ad-settings/.
  • Outbrain: Display of personalised advertisements; Service provider: Outbrain United Kingdom Limited, 175 High Holborn, London WC1V 7AA, United Kingdom; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.outbrain.com; Privacy policy: https://www.outbrain.com/privacy/. Erasure of data: The stored personal data is erased or anonymised after 13 months.
  • UTM parameter: Analysis of sources and user actions on the basis of an extension of web addresses referring to us with an additional parameter, the "UTM" parameter. For example, a UTM parameter "utm_source=platformX &utm_medium=video" can tell us that a person clicked on the link on platform X within a video. The UTM parameters provide information about the source of the link, the medium used (e.g. social media, website, newsletter), the type of campaign or the content of the campaign (e.g. posting, link, image and video). With the help of this information, we can, for example, check our visibility on the internet or the effectiveness of our campaigns; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Facebook advertisements: Placement of advertisements within the Facebook platform and evaluation of the ad results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Basis for third-country transfers: Data Privacy Framework (DPF); Option to object (opt-out): We refer to the data protection and advertising settings in the user's profile on the Facebook platforms as well as to Facebook's consent procedure and contact options for exercising rights of access and other data subject rights, as described in Facebook's privacy policy; Further information: Users' event data, i.e. behaviour and interest details, is processed for the purposes of targeted advertising and audience building on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum) processed. The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which relates in particular to the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Instagram advertisements: Placement of advertisements within the Instagram platform and evaluation of the ad results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/; Basis for third-country transfers: Data Privacy Framework (DPF); Option to object (opt-out): We refer to the data protection and advertising settings in the user's profile on the Instagram platform as well as in the context of Instagram's consent procedure and Instagram's contact options for exercising rights of access and other data subject rights in Instagram's privacy policy; Further information: Users' event data, i.e. behaviour and interest details, is processed for the purposes of targeted advertising and audience building on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum) processed. The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which relates in particular to the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).

Affiliate Programmes and Affiliate Links

In our online offering we integrate so-called affiliate links or other references (which may include, for example, search masks, widgets or discount codes) to the offers and services of third-party providers (collectively referred to as "affiliate links"). When users follow the affiliate links or subsequently take up the offers, we may receive a commission or other benefits from these third-party providers (collectively referred to as "commission").

In order to be able to track whether users have taken up the offers of an affiliate link used by us, it is necessary that the respective third-party providers find out that the users followed an affiliate link used within our online offering. The assignment of the affiliate links to the respective business transactions or to other actions (e.g. purchases) serves solely the purpose of commission accounting and is removed as soon as it is no longer required for the purpose.

For the purposes of the aforementioned assignment of the affiliate links, the affiliate links can be supplemented with certain values that are a component of the link or can be stored otherwise, e.g. in a cookie. The values may include, in particular, the originating website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer and an online identifier of the user.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis for the processing of data is the consent. Otherwise, users' data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Prospective customers. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Affiliate tracking.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • financeAds: Affiliate marketing partner programme; Service provider: financeAds GmbH & Co. KG, Karlstraße 9, 90403 Nuremberg, Germany; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.financeads.net/. Privacy policy: https://www.financeads.net/datenschutz/.
  • FinanceQuality: Affiliate marketing partner programme; Service provider: Netzeffekt GmbH, Theresienhöhe 28, 80339 Munich, Germany; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.financequality.net/. Privacy policy: https://www.financequality.net/datenschutz/.

Customer Reviews and Rating Procedures

We participate in review and rating procedures in order to evaluate, optimise and promote our services. When users rate us via the participating rating platforms or procedures or otherwise give feedback, the general terms and conditions or terms of use and the data protection notices of the providers additionally apply. As a rule, the rating also requires registration with the respective providers.

In order to ensure that the rating persons have actually used our services, we transmit the data required for this with regard to the customer and the service used to the respective rating platform (including name, email address and order number or article number) with the customer's consent. This data is used solely to verify the authenticity of the user.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Recipients of services and clients. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Google Customer Reviews: Service for obtaining and/or displaying customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: In the context of obtaining customer reviews, an identification number and time for the business transaction to be rated, in the case of review requests sent directly to customers the customer's email address as well as their details on the country of residence and the review details themselves are processed; further details on the types of processing as well as the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: Information on the services, data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
  • Trusted Shops (Trustedbadge): Rating platform - Within the joint controllership existing between us and Trusted Shops, for data protection questions and to assert your rights please contact Trusted Shops by preference using the contact options given in the data protection information. Irrespective of this, however, you can always contact the controller of your choice. Your request will then, if necessary, be passed on to the other controller for a response. The trustbadge is provided by a US-American CDN provider (Content Delivery Network). An adequate level of data protection is ensured by standard data protection clauses and further contractual measures. When the trustbadge is called up, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of retrieval, the amount of data transferred and the requesting provider (access data) and documents the retrieval. The IP address is anonymised immediately after collection, so that the stored data cannot be assigned to your person. The anonymised data is used in particular for statistical purposes and for error analysis. If you have given your consent, after order completion the trustbadge accesses order information stored on your end device (order total, order number, and where applicable the product purchased) as well as your email address, and your email address is hashed using a cryptographic one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Art. 6(1)(1)(a) GDPR. This serves to check whether you are already registered for Trusted Shops services. If this is the case, the further processing takes place in accordance with the contractual agreement made between you and Trusted Shops. Insofar as you are not yet registered for the services or do not give your consent to automatic recognition via the trustbadge, you will subsequently be given the opportunity to register manually for the use of the services or to conclude the protection in the context of your possibly already existing usage contract. For this purpose, after completion of your order, the trustbadge accesses the following information stored on the end device used by you: order total, order number and email address. This is necessary so that we can offer you buyer protection. A transmission of the data to Trusted Shops only takes place when you actively decide to conclude buyer protection by clicking on the correspondingly labelled button in the so-called trustcard. Insofar as you decide to use the services, the further processing is governed by the contractual agreement with Trusted Shops in accordance with Art. 6(1)(b) GDPR, in order to be able to complete your registration for buyer protection and secure the order as well as, where applicable, to be able to send you review invitations by email afterwards. Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6(1)(f) GDPR for the purpose of ensuring trouble-free operation. In the process, processing may take place in third countries (USA and Israel). An adequate level of data protection is ensured in the case of the USA by standard data protection clauses and further contractual measures, and in the case of Israel by an adequacy decision. ; Service provider: Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany; Legal bases: consent (Art. 6(1)(1)(a) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.trustedshops.de. Privacy policy: https://www.trustedshops.de/impressum/#datenschutz.

Customer Reviews and Rating Procedures

We participate in review and rating procedures in order to evaluate, optimise and promote our services. When users rate us via the participating rating platforms or procedures or otherwise give feedback, the general terms and conditions or terms of use and the data protection notices of the providers additionally apply. As a rule, the rating also requires registration with the respective providers.

In order to ensure that the rating persons have actually used our services, we transmit the data required for this with regard to the customer and the service used to the respective rating platform (including name, email address and order number or article number) with the customer's consent. This data is used solely to verify the authenticity of the user.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Recipients of services and clients. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Google Customer Reviews: Service for obtaining and/or displaying customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: In the context of obtaining customer reviews, an identification number and time for the business transaction to be rated, in the case of review requests sent directly to customers the customer's email address as well as their details on the country of residence and the review details themselves are processed; further details on the types of processing as well as the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: Information on the services, data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.

Presences in Social Networks (Social Media)

We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about us.

We point out that user data may be processed outside the area of the European Union in the process. This may give rise to risks for users, because, for example, it could make it more difficult to enforce users' rights.

Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on the usage behaviour and the resulting interests of users. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of users. For this purpose, cookies are generally stored on users' computers, in which the usage behaviour and the interests of users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by users (in particular if they are members of the respective platforms and are logged in there).

For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the data protection declarations and information of the operators of the respective networks.

Also in the case of requests for access and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the latter each have access to the user data and can directly take appropriate measures and provide information. Should you nevertheless require help, you can contact us.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Communication; feedback (e.g. collecting feedback via an online form). Public relations.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Instagram: Social network, enables the sharing of photos and videos, commenting on and favouriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the social network Facebook - Together with Meta Platforms Ireland Limited, we are responsible for the collection (but not the further processing) of data of visitors to our Facebook page (so-called "fan page"). This data includes information on the types of content that users view or with which they interact, or the actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device information" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information in order to provide analytics services, so-called "Page Insights", for page operators so that they obtain insights into how people interact with their pages and with the content connected to them. We have concluded a special agreement with Facebook ("Information about Page Insights", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfil the data subject rights (i.e. users can, for example, direct requests for access or erasure directly to Facebook). The rights of users (in particular to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further notes can be found in the "Information about Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which relates in particular to the transmission of the data to the parent company Meta Platforms, Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
  • LinkedIn: Social network - Together with LinkedIn Ireland Unlimited Company, we are responsible for the collection (but not the further processing) of data of visitors that is created for the purposes of producing the "Page Insights" (statistics) of our LinkedIn profiles. 
    This data includes information on the types of content that users view or with which they interact, or the actions they take, as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data) and details from the user's profile, such as job function, country, industry, seniority level, company size and employment status. Data protection information on the processing of users' data by LinkedIn can be found in LinkedIn's data protection notices: https://www.linkedin.com/legal/privacy-policy 
    We have concluded a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum (the ‚Addendum‘)", https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfil the data subject rights (i.e. users can, for example, direct requests for access or erasure directly to LinkedIn). The rights of users (in particular to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint controllership is limited to the collection of data by and the transmission to the Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of the Ireland Unlimited Company, which relates in particular to the transmission of the data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
  • X: Social network; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://x.com. Privacy policy: https://x.com/de/privacy.
  • YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://myadcenter.google.com/personalizationoff.
  • Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.xing.com/. Privacy policy: https://privacy.xing.com/de/datenschutzerklaerung.

Plug-ins and Embedded Functions and Content

We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). This may be, for example, graphics, videos or city maps (hereinafter uniformly referred to as "content").

The integration always requires that the third-party providers of this content process the user's IP address, since without the IP address they could not send the content to their browser. The IP address is thus required for the display of this content or these functions. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and contain, among other things, technical information on the browser and the operating system, on referring websites, on the time of visit as well as further details on the use of our online offering, but may also be combined with such information from other sources.

Notes on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis for data processing is the permission. Otherwise, the user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); master data (e.g. full name, residential address, contact information, customer number etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or time of creation).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness.
  • Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years.).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing operations, procedures and services:

  • Font Awesome (provided on our own server): Display of fonts and symbols; Service provider: The Font Awesome icons are hosted on our server; no data is transmitted to the provider of Font Awesome; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.

Amendment and Update

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or another individual notification.

Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, we ask you to note that the addresses may change over time and we ask you to check the details before making contact.

Supervisory authority responsible for us:
In Berlin, the competent supervisory authority is: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin.

Definitions of Terms

In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their legal definitions apply. The following explanations, on the other hand, are primarily intended to aid understanding.

  • A/B tests: A/B tests serve to improve the user-friendliness and performance of online offerings. In this process, users are shown, for example, different versions of a website or its elements, such as input forms, on which the placement of the content or the labelling of the navigation elements may differ. Subsequently, on the basis of the behaviour of users, e.g. longer dwell time on the website or more frequent interaction with the elements, it can be determined which of these websites or elements better correspond to the needs of users.
  • Affiliate tracking: In the context of affiliate tracking, links by means of which the linking websites refer users to websites with product or other offers are logged. The operators of the respective linking websites can receive a commission if users follow these so-called affiliate links and subsequently take up the offers (e.g. buy goods or use services). For this it is necessary that the providers can track whether users who are interested in certain offers subsequently take them up at the instigation of the affiliate links. Therefore, for the functionality of affiliate links, it is necessary that they be supplemented with certain values that become a component of the link or are stored otherwise, e.g. in a cookie. The values include, in particular, the originating website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user as well as tracking-specific values, such as advertising media ID, partner ID and categorisations
  • Master data: Master data comprises essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, among other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between persons and services, institutions or systems by enabling a unique assignment and communication.
  • Content data: Content data comprises information generated in the course of the creation, editing and publication of content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content that is published on various platforms and media. Content data is not limited to the actual content but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication data
  • Click tracking: Click tracking allows the movements of users within an entire online offering to be surveyed. Since the results of these tests are more accurate if the interaction of users can be tracked over a certain period (e.g. so that we can find out whether a user likes to return), cookies are generally stored on users' computers for these test purposes.
  • Contact data: Contact data is essential information that enables communication with persons or organisations. It comprises, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.  
  • Conversion measurement: Conversion measurement (also referred to as "visit action evaluation") is a procedure by which the effectiveness of marketing measures can be determined. For this purpose, a cookie is generally stored on users' devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, in this way we can understand whether the advertisements placed by us on other websites were successful.
  • Artificial intelligence (AI): The purpose of the processing of data by artificial intelligence (AI) comprises the automated analysis and processing of user data in order to recognise patterns, make predictions and improve the efficiency as well as the quality of our services. This includes the collection, cleaning and structuring of the data, the training and application of AI models as well as the continuous review and optimisation of the results, and takes place exclusively with the consent of users or on the basis of legal grounds of permission.
  • Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Metadata, also known as data about data, comprises information that describes the context, origin and structure of other data. It can include details on the file size, the date of creation, the author of a document and the change histories. Communication data captures the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, logs of transactions and activities, as well as audit logs used for tracking and reviewing operations.
  • Usage data: Usage data refers to information that captures how users interact with digital products, services or platforms. This data comprises a wide range of information that shows how users use applications, which functions they prefer, how long they dwell on certain pages and via which paths they navigate through an application. Usage data may also include the frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. In addition, usage data plays a decisive role in recognising trends, preferences and possible problem areas within digital offerings
  • Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of "profiles with user-related information", or "profiles" for short, comprises any form of automated processing of personal data that consists in using this personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. the interests in certain content or products, the click behaviour on a website or the location). For the purposes of profiling, cookies and web beacons are frequently used.
  • Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used for the analysis of system problems, for security monitoring or for the creation of performance reports.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and can comprise the behaviour or interests of visitors in certain information, such as the content of websites. With the help of reach analysis, operators of online offerings can, for example, recognise at what time users visit their websites and which content they are interested in. As a result, they can, for example, better adapt the content of the websites to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used in order to recognise returning visitors and thus obtain more accurate analyses on the use of an online offering.
  • Tracking: "Tracking" is when the behaviour of users can be tracked across several online offerings. As a rule, with regard to the online offerings used, behaviour and interest information is stored in cookies or on servers of the providers of the tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
  • Controller: A "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: "Processing" is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether it is collecting, evaluating, storing, transmitting or erasing.
  • Contract data: Contract data is specific information relating to the formalisation of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This category of data is essential for the management and fulfilment of contractual obligations and comprises both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of services or products agreed, price agreements, payment terms, termination rights, renewal options and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is decisive for clarifying rights and obligations, enforcing claims and resolving disputes.
  • Payment data: Payment data comprises all information required to process payment transactions between buyers and sellers. This data is of decisive importance for e-commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and invoice information. Payment data may also contain information about the payment status, chargebacks, authorisations and fees.
  • Audience building: Audience building ("Custom Audiences" in English) is when target groups are determined for advertising purposes, e.g. the display of advertisements. For example, based on a user's interest in certain products or topics on the internet, it can be concluded that this user is interested in advertisements for similar products or the online shop in which they viewed the products. "Lookalike Audiences" (or similar target groups), in turn, is when the content assessed as suitable is displayed to users whose profiles or interests presumably correspond to the users for whom the profiles were built. For the purposes of building Custom Audiences and Lookalike Audiences, cookies and web beacons are generally used. 

Cookie Policy

  • Investing
  • Retirement Subsidised
  • Family
What you can do with us
  • Get your retirement subsidised
  • Open an individual account
  • Open a joint account
  • Open a children’s account
  • Open an instant-access account
  • Save with Cash-Invest
  • Invest sustainably
  • Invest in the Megatrends portfolio
  • Invest in themes
  • ETF savings plan
  • Retirement provision
Financial knowledge
  • quiPedia
  • quirion.ai
  • Calculator
  • ETF savings plan calculator
  • ETF savings plan calculator for children
  • Media library
  • Events
  • FAQ
  • Blog
  • What is a robo-advisor?
  • Frühstart-Rente (state child pension)
  • Investment concept
  • Performance
  • Podcast
The people behind quirion
  • About us
  • Quirin Privatbank
  • Awards
  • Security
  • Careers
  • Press
  • How quirion works
  • Partner program
Services
  • Contact and feedback
  • Portfolio check
  • Vouchers
  • Investment vouchers
  • Forms
  • Downloads
  • White paper
  • Give feedback
  • Newsletter
Legal
  • Imprint
  • Privacy
  • Accessibility
  • Terms and conditions
  • Price and services list
  • Sustainability disclosures
  • Whistleblower system
  • Whistleblower Protection Act FAQ
quirion

© 2026 quirion AG · A company of Quirin Privatbank

Legal notice Privacy policy

Get the quirion app

Scan the QR code with your phone to download the app.

Continue on the web