
Cookie settings: We use cookies. Some of them are technically necessary (e.g. for the shopping cart), others help us to improve our offer and provide you with a better user experience. Edit your settings for cookie use on our site.
We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).
We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.
We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.
This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China's Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.
For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.
If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E..
In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.
The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.
We use the following terms, among others, in this Privacy Policy:
Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.
Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.
Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.
Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.
The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.
A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.
Consent is any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:
Interactive Scape GmbH
Wilhelmine-Gemberg-Weg 6
610179 Berlin
Phone.: +49 30 69 80 94 - 100
eMail: kontakt@interactive-scape.com
Website: https://www.interactive-scape.com
Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.
When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.
The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.
Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.
We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:
By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.
We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.
If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.
Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:
• the purposes of processing,
• the categories of Personal Data that are processed,
• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,
• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,
• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,
• the existence of a right to lodge a complaint with a supervisory authority,
• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,
• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.
Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:
• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.
• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.
• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.
• Personal Data was processed unlawfully.
• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.
• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.
If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.
If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.
Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:
• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.
• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.
• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.
• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.
If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.
Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.
Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.
In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.
If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.
In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.
If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.
Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, or (3) is based on the Data Subject's explicit Consent.
If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject's explicit Consent, we shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.
If a Data Subject wishes to exercise this right, he or she may contact us at any time.
The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.
The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.
A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.
Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.
In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.
If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.
Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).
If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.
We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.
Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.
The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.
We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.
As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:
Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.
In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.
Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.
According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.
The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.
Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.
In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.
Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.
As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.
We collect and process Personal Data of applicants in the application process. Processing may also take place electronically. This is particularly the case if an applicant submits relevant application documents to us electronically, for example by email or via a web form on our or third-party websites.
For applicant data, the purpose of data processing is to carry out a review of the application in the application process. For this purpose, we process all data provided by you. Based on the data submitted as part of the application, we check whether you will be invited to an interview (part of the selection process). Then, in the case of generally suitable applicants, in particular during the interview, we process certain other Personal Data provided by you that is essential for our selection decision.
The legal basis for data Processing is Art. 6 (1) (b) GDPR, Art. 9 (2) (b) and (h) GDPR, Art. 88 (1) GDPR and national legislation.
If we do not conclude an employment contract with the applicant, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the Controller stand in the way of deletion. Another legitimate interest in this sense is, for example, the provision of evidence in legal proceedings.
We use the Cookie Consent Manager (CCM19) to interactively offer visitors to our website an informed choice about data protection settings and cookie usage. The service supports us in obtaining, documenting and managing consent for different cookie categories, including functional, statistical and marketing cookies, in compliance with the law. Personal data is processed in the course of use - especially in connection with the collection of consent. The data processed includes the time of consent, selected categories, user IDs, IP address, browser information, device type, user preferences, and technical metadata for session processing.
Processing is automated via the CCM19 cloud infrastructure. Visitors can control their cookie settings via an embedded consent banner. The selection is logged and saved for later reference. The service manages the opt-in status and enables effective audit trails as well as updates or revocations of consent.
The company that operates the service and therefore the recipient of the personal data is: Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany.
Purposes for which the personal data are to be processed and the legal basis for the processing: The purpose of the processing is the legally compliant collection, storage, and management of user consents to cookies and cookie categories as well as the documentation of changes or revocations. The processing is carried out on the basis of Art. 6 (1) (c) GDPR, i.e., to fulfill legal obligations and Art. 6 (1) (f) GDPR. The legitimate interest lies in legal protection, transparency for visitors and the avoidance of data protection violations through comprehensible consent processes.
The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The use of Personal Data is required by law, as it is necessary to fulfill legal obligations in the area of data protection and Consent management. Users are required to indicate their cookie preferences or reject cookies, and this information must be stored to properly document the decision.
Further information and the applicable data protection provisions of Cookie consent Manager CCM19 can be found at https://www.ccm19.de/.
We organize webinars and invite customers, interested parties, service providers and suppliers as well as their and our employees to online meetings. We use various third-party providers (operators of online meeting applications, application providers). You can understand which third-party provider we use for a specific webinar or online meeting from the participation link. You can find the privacy policy and other legally required information on the website of the respective third-party provider.
When using systems for webinars and online meetings, personal data such as names, e-mail addresses, telephone numbers, sound recordings, film recordings, photographs, usage data (e.g., time and duration of meetings, chat logs), content data (e.g., files, notes, messages) and location data may be processed. This information is necessary to provide the services, improve the user experience, provide support and ensure the security and compliance of the services.
Purposes for which the personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use, provision and administration of systems for webinars and online meetings for communication. The processing is based on consent pursuant to Art. 6 (1) (a) GDPR, or explicit consent pursuant to Art. 49 (1) (1) (a) GDPR, the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, and legitimate interests (Art. 6 (1) (f) GDPR), such as the improvement of our services and the use and provision of modern communication tools.
For the processing of your personal data, we obtain your consent in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:
By registering, logging in and/or participating in a webinar or online meeting, you expressly agree that your personal data may be processed for the purposes of registration, planning, organization and implementation of the webinar or online meeting, which includes transmission to a third-party provider (possibly located in a third country), and that sound recordings, film recordings or photographs may be transmitted to other participants and/or published as part of the webinar or online meeting. You grant multiple consents with a single action. By registering, logging in and/or participating, you also voluntarily give your explicit consent in accordance with Art. 49 (1) (1) (a) GDPR for data transfers to third countries for the purposes of registration, planning, organization and implementation of the webinar or online meeting, in particular for such transfers to third countries for which there is or is not an adequacy decision of the EU/EEA and to companies or other entities that are not subject to an existing adequacy decision due to self-certification or other accession criteria, and in or for which there are significant risks and no appropriate safeguards for the protection of your personal data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). We hereby inform you in advance of giving your voluntary and explicit consent that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable, and that published personal data may not be deleted, modified or anonymized at all, only to a limited extent and/or with a time delay. You give your consent voluntarily. You are not obliged to give your consent and may choose not to attend or participate in the webinar or online meeting, which will be regarded by us as a refusal of our request for consent. You can withdraw your consent under data protection law in whole or in part at any time with effect for the future, in particular by deactivating or switching off your audio transmissions, video transmissions or photo transmissions during the webinar or online meeting or by not activating them in the beginning. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. By your act, you also confirm that you have read and acknowledged this privacy policy.
The company operating the service may be located in a third country. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company operating the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company operating the service or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us or the company operating the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Calendly offers a user-friendly online scheduling software that allows us to organize meetings and appointments efficiently. The platform helps us to synchronize the availability of all participants, send automatic reminders and integrate the planning of meetings directly into our calendars. Calendly significantly improves the coordination of internal and external meetings and helps to save time and increase productivity.
When using Calendly, Personal Data such as names, email addresses and calendar information are processed. This data enables us to automate appointment scheduling, send personalized invitations and maximize the efficiency of our appointment scheduling.
The company that operates the service and thus the recipient of personal data is: Calendly, Inc., 115 E Main St., Ste A1B, Buford, GA 30518, USA.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to optimize scheduling and improve organizational efficiency. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in simplifying and increasing the efficiency of planning processes for internal and external meetings.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Calendly, LLC, can be found at https://calendly.com.
Eventbrite is a global event management and ticketing platform that enables organizers to create, promote and sell tickets for events. The platform offers a comprehensive solution for planning online and live events of all kinds, from conferences and workshops to festivals and concerts. Participants can use Eventbrite to search for events, buy tickets and network with other event participants.
When using Eventbrite, Personal Data such as names, email addresses, payment information, and details of events attended are processed. This information is necessary to purchase tickets, carry out registrations, offer personalized recommendations, and facilitate communication between event organizers and participants.
The company that operates the service and thus the recipient of personal data is: Eventbrite, Inc., 95 Third Street, 2nd Floor, San Francisco, California, 94103, USA. For data subjects in the EU and EEA, Eventbrite Operations (IE) Limited, 97 South Mall Cork, T12 XV54, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Eventbrite UK Limited, The Pavilions, Bridgwater Road, Bristol, England, BS13 8FD, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of event management and ticketing services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in facilitating and improving the organization of and participation in events.
The company that operates the service is located in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Eventbrite may be retrieved under https://www.eventbrite.com.
We use Nextcloud as a cloud solution for storing, synchronizing and sharing files, calendars, contacts and other information within our company. Nextcloud enables us to operate a self-hosted cloud infrastructure in which all data is stored on servers that are controlled by us or by contracted hosting providers. Personal data may be processed during use, in particular when creating and managing user accounts, sharing files, calendar management and contact management as well as when using integrated functions such as comments, tasks or video conferences. Processed data includes names, usernames, email addresses, profile pictures, IP addresses, timestamps, uploaded or synchronized files, calendar events, contacts and communication content.
In addition, Nextcloud processes technical information about endpoints used, browsers used, operating systems and the type of use of the service. Data is processed to manage user access, to secure the transferred content, to version files and to enable real-time collaboration on shared content. Depending on the configuration of the Nextcloud instance, logs of user activity, file changes or error reports can also be saved. Processing takes place entirely within the environment controlled by us or a contracted hosting partner.
The company that operates the service and therefore the recipient of personal data is: Nextcloud GmbH, Albrechtstraße 14b, 10117 Berlin, Germany.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is the secure storage, synchronization and sharing of files and information, team collaboration and the central management of digital work resources. Processing is carried out on the basis of Art. 6 (1) (b) GDPR, i.e., for the performance of a contract to which the data subject is party, and Art. 6 (1) (f) GDPR. The legitimate interest lies in secure and efficient collaboration, self-determination over the data infrastructure and control over stored and processed content.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions of Nextcloud can be retrieved at https://nextcloud.com/privacy/.
TeamViewer is a software solution for remote access, remote control and online meetings that enable users worldwide to access, control and interact with computers, servers or mobile devices via the internet. Both private individuals and companies use the platform to provide IT support, work remotely and hold virtual meetings. When using TeamViewer, Personal Data such as names, email addresses, telephone numbers, IP addresses and device information are processed. This data enables TeamViewer to provide the services, manage user accounts, provide support and enable personalized experiences.
The company that operates the service and thus the recipient of personal data is: TeamViewer Germany GmbH, Bahnhofsplatz 2, 73033 Göppingen, Germany. The representative under national law in the United Kingdom is: TeamViewer UK Limited, 3rd Floor, 11-12 St. James's Square, London SW1Y 4LB, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of remote access and communication services. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient platform for IT support, the improvement of our services, the provision of customer support and the use of efficient SaaS applications.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable TeamViewer data protection provisions can be found at https://www.teamviewer.com.
Microsoft Teams is a communication and collaboration tool within the Microsoft 365 suite designed specifically for business use. It enables teams to work together effectively, no matter where they are, through features such as chat, video calls, meetings, file sharing and integration with other Microsoft products and services. Microsoft Teams promotes teamwork through digital spaces that enable seamless communication and collaboration, regardless of whether team members are in the same office or spread across various locations worldwide.
When using Microsoft Teams, Personal Data such as names, email addresses, telephone numbers, usage data (e.g., time and duration of meetings, chat logs), content data (e.g., files, notes, messages) and location data are processed. This information is necessary to provide the services, improve the user’s experience, provide support and ensure the security and compliance of the services.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use, provide, manage and improve Microsoft Teams for communication. Processing is based on the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as the improvement of our services and the use and provision of modern communication tools.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Microsoft Teams can be found at https://privacy.microsoft.com.
Zoom is a provider of video conferencing software that enables organizations and individuals to host and participate in virtual meetings, webinars, live chats, and collaborative workspaces. With features that include video and audio conferencing, screen sharing, and encryption, Zoom has established itself as an essential tool for remote work, distance learning, and virtual social gatherings.
When using Zoom services, Personal Data such as names, email addresses, telephone numbers, profile pictures and device information are processed. During meetings, content data such as video and audio streams, chat transcripts and shared content may be processed. This information is required to provide communication services, manage user accounts, operate the platform securely and efficiently and provide users with personalized experiences.
The company that operates the service and thus the recipient of personal data is: Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For data subjects in the EU and EEA, the Lionheart Squared (Europe) Limited, 2 Pembroke House, Upper Pembroke Street 28-32, Dublin, DO2 EK84, lreland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Lionheart Squared Limited, 17 Glasshouse Studios, Fryern Court Road, Fordingbridge, Hampshire, SP6 1QX, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of video communication services. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient platform, the improvement of our services and the guarantee of IT security.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Zoom may be retrieved under https://zoom.us.
Webflow is an innovative design and development platform that enables users to visually design professional websites without having to write code. Webflow offers a wide range of web design features, including responsive layouts, CMS, e-commerce and hosting services to meet the needs of designers, developers and businesses of all sizes.
When using Webflow services, Personal Data such as names, email addresses, payment information and professional information are processed. In addition, usage data such as information about websites created, interaction data and access statistics may be collected. This data is required to provide the services, manage user accounts, improve support and offer personalized experience.
The company that operates the service and thus the recipient of personal data is: Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. For data subjects in the EU and EEA, Webflow B.V., Zomerstraat 17-A, NL-5397 GH Lith, Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Webflow Europe UK Ltd., Birchin Court, 5th Floor, 19–25 Birchin Lane, London, EC3V 9DU, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of the web design and development platform. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b)GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient platform, the optimization of the user experience and the use of effective customer support.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Webflow may be retrieved under https://webflow.com.
Figma is an innovative design and prototyping software that enables teams to collaborate and create, test and share designs in real time. As a browser-based platform, Figma offers a wide range of tools for UI/UX design, graphic design, and wireframing that make the design process more efficient and interactive. Figma is used by designers, developers and product teams in various industries to create digital products and services.
When using Figma, Personal Data such as names, email addresses, job titles and usage data are processed. This information is necessary to create and manage user accounts, provide and personalize the service, make support requests and offer users a collaborative design environment.
The company that operates the service and thus the recipient of personal data is: Figma, Inc., 760 Market St, Floor 10, San Francisco, CA 94102, USA. For data subjects in the EU and EEA, Figma GmbH, Kurfürstendamm 15, 10719 Berlin acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Figma UK Ltd., 9 Devonshire Square, London, EC2M 4YF, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the design tool. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience and providing an effective and collaborative design tool.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Figma may be retrieved under https://www.figma.com.
Google Analytics is a tool from Google LLC that provides operators of websites and apps with detailed statistics on traffic and user behavior. It enables the collection and analysis of data on website visits, user interactions and conversion rates, which helps operators to understand and optimize their online presence. Google Analytics uses cookies to collect information about user behavior, including page views, time spent on the site and the paths users take on the site.
When using Google Analytics, Personal Data such as IP addresses, browser information and interaction data are processed. This data helps website operators to measure the performance of their website, improve the user experience and develop targeted marketing strategies.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the analysis and optimization of websites, apps, and advertising. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the website, increasing user-friendliness and the effectiveness of online marketing.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Analytics can be found at https://policies.google.com/privacy.
Mailchimp is a marketing automation platform and email marketing service that enables businesses to reach their target audience through personalized email campaigns and targeted promotions. The platform provides tools for segmenting contacts, designing email templates, analyzing campaign results and integrating with a variety of other services to support effective customer communication.
When using Mailchimp, Personal Data such as names, email addresses, usage data (e.g., interactions with emails, access times, preferences) and demographic information as well as purchase histories are processed. This data enables the creation of personalized marketing campaigns, the improvement of the user experience and the provision of relevant content for recipients.
The company that operates the service and therefore the recipient of the Personal Data is: The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of marketing automation and email marketing services. The Processing in the system is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective communication with customers and interested parties as well as in the optimization of our processes. The Processing of email addresses is based on the Consent of the recipient in accordance with Art. 6 (1) (a) GDPR, the explicit Consent of the recipient in accordance with Art. 49 (1) (1) (a) GDPR or on the performance of a contract or pre-contractual measures in accordance with Art. 6 (1) (b) GDPR.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Mailchimp may be retrieved under https://mailchimp.com.
The Google Marketing Platform is an integrated advertising and analytics platform from Google LLC that enables companies and advertisers to efficiently plan, implement and analyze their online marketing activities. It combines numerous services such as Google Analytics, Data Studio, Optimize, Tag Manager, Audience Center, Surveys, Campaign Manager and Display & Video 360 to support data-driven marketing and create personalized advertising campaigns across different channels and devices.
When using the Google Marketing Platform, Personal Data such as web usage data, including cookies, IP addresses, advertising IDs and interaction data with advertisements are processed. This information is necessary to manage advertising campaigns, carry out target group analyses, measure the effectiveness of marketing strategies and offer users relevant advertising content.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the analysis and optimization of online marketing and advertising activities. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective design and personalization of advertising campaigns to meet both our needs and the preferences of users.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of the Google Marketing Platform can be found at https://policies.google.com/privacy.
Google Ad Manager is an advertising platform from Google that allows us to serve ads and optimize ad performance. The service helps deliver the right ads to the right audience based on user behavior and interests. By using Google Ad Manager, personal data such as IP addresses, cookie IDs and information about user behavior, such as the frequency of page visits and interactions with the ads displayed, are processed. This data is used to optimize advertisements and analyze the performance of campaigns. Google uses this data to personalize ads and measure the success of advertising measures. In addition, Google Ad Manager helps us to maximize the reach and relevance of our ads by continuously evaluating the data on user interaction with the ads and making appropriate adjustments.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data is to be processed and the legal basis for the processing: The purpose of the processing is to optimize ad placement and analyze advertising campaign performance. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in improving the reach and relevance of advertising.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://admanager.google.com/.
Google AdSense is an advertising program from Google LLC that enables website operators and bloggers to generate revenue by placing targeted ads on their websites. These ads can include text, images, video or interactive media content and are selected based on the content of the website and the interests of the visitors. AdSense uses algorithms to determine the most relevant and best performing ads for each page, optimizing both the user experience and monetization opportunities for publishers.
When using Google AdSense, Personal Data such as IP addresses, cookies and other identifiers are processed, which originates from the interaction of users with the advertisements and the websites visited. This data helps to measure the effectiveness of advertising, personalizing ads and prevent fraud.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the AdSense service, the analysis and optimization of advertising campaigns and the generation of revenue for publishers. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective delivery and personalization of advertising, which is beneficial for advertisers as well as publishers and website visitors.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google AdSense may be retrieved under https://policies.google.com/privacy.
Google Ads, formerly known as Google AdWords, is an online advertising program from Google LLC that allows businesses to place targeted ads to increase their visibility on the internet. Google Ads offers various advertising formats, including search ads, display ads, YouTube video ads and more, which allow companies to reach potential customers on Google search results pages, partner websites and other platforms in the Google network.
When using Google Ads, Personal Data such as IP addresses, cookies and other identifiers resulting from interaction with advertisements are processed. This data helps to measure the effectiveness of advertising campaigns, to precisely address target groups and to personalize advertisements based on the interests and behaviour of users.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the analysis and optimization of online advertising campaigns. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective design and delivery of advertising campaigns that are relevant to both advertisers and users.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Ads can be found at https://policies.google.com/privacy.
Google Ads Conversion Tracking helps us to measure the effectiveness of our advertising campaigns by recording which users perform a desired action on our website after clicking on an ad, such as a purchase or registration. By using this tool, personal data such as IP addresses, click information and website views are processed. This data is used to evaluate and optimize the success of Google Ads campaigns by providing information about which ads and keywords lead to conversions. Google Ads Conversion Tracking helps us to use our marketing budget more efficiently and to plan targeted advertising measures in order to maximize the return on investment (ROI).
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to measure and optimize the advertising campaigns and to improve the marketing ROI. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the optimization of advertising measures and the efficient use of the budget.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://ads.google.com/.
Google Ads Enhanced Conversions allows us to measure the performance of our ad campaigns more accurately by identifying converted users using additional data points such as email addresses and phone numbers collected on our website. This service processes personal data, including contact information, and helps us improve the effectiveness of advertising and marketing efforts. By using Enhanced Conversions, we can ensure that our ads are more targeted by presenting them to relevant users who are most likely to convert.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to optimize the targeting of Google Ads campaigns and to measure conversion-relevant actions. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the improvement of the marketing strategy and the customization of advertisements.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Google Ads Optimized Targeting is a service that helps us target our ads to appropriate users by using algorithms and machine learning to select the best audience for an ad based on available user data. The service processes personal data, in particular about user behavior, such as visits to the website, interactions with ads and demographic data. The use of this data enables us to maximize the reach of our campaigns, by displaying ads to users who are most likely to interact with our content.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data is to be processed and the legal basis for the processing: The purpose of the processing is to optimize targeting and improve campaign performance. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the improvement of marketing strategies and the maximization of advertising success.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Google Ads Remarketing allows us to serve targeted ads to users who have already been in contact with our website or our products. This is done by using cookies and similar technologies to identify visitors and present them with more relevant ads. Personal data such as IP addresses and browsing behavior are collected and used to serve personalized ads tailored to the interests of users. Google Ads Remarketing helps us to improve user experience and target our marketing resources where they have the greatest impact.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the personalized targeting of users through advertising and the improvement of campaign performance. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the effective advertising of our products and the increase in reach.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Google Ads Smart Bidding is an automated bidding strategy from Google Ads that uses machine learning to optimize bids for ads based on conversion data and targets. By using Smart Bidding, personal data such as IP addresses, device information and information on past interactions with ads is collected and processed. This data is used to improve bid management and display ads to the most relevant users to increase the likelihood of conversion. Google Ads Smart Bidding helps us to increase the effectiveness of our advertising campaigns by continuously accessing user data and adjusting bids accordingly to achieve the desired results.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to optimize the bidding strategy for targeted advertisements and to maximize the conversion probability. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the optimization of the advertising campaigns and the achievement of a higher conversion.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Google Conversion Linker is a tool that is used in conjunction with Google Ads and Google Analytics to ensure that conversions are recorded correctly. This tool helps to improve the accuracy of conversion data by storing information for users about their clicks and interactions on the website and ensuring that these are correctly linked to the ads. Personal data such as IP addresses and click IDs are processed in order to correctly assign conversions and measure the effectiveness of the advertising campaigns.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the correct allocation of conversions and the improvement of the accuracy of conversion data. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the measurement and optimization of advertising effectiveness.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
We use Google Dynamic Remarketing to display personalized ads to visitors to our website based on their previous interactions with our web shop or our website. The service enables us to show product recommendations based on items viewed by the user, abandoned shopping baskets or other browsing behavior. Personal data may be processed during use - in particular technical and device-related information. Processed data includes IP address, browser data and operating system information, device type, pages visited, products viewed, click behavior, timestamps, subsequent conversions and anonymized user IDs generated by cookies or similar tracking technologies.
Processing is automated via Google's cloud services. When the website is visited, the integrated Google remarketing tag records data on user interactions and provides it with a cookie or device label. This data is then used to create an interest profile and enables relevant advertisements to be displayed on partner sites in the Google advertising network. Google also uses data to evaluate the effectiveness of the ads and to measure conversions.
The company that operates the service and therefore the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the personalized targeting of users through advertising and the improvement of campaign performance. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the effective advertising of our products and increasing our reach.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Remarketing in Google Analytics allows us to target advertising to users who have visited our website. The service processes personal data such as IP addresses and user interactions that allow us to present customized ads on other websites or social media. Remarketing with Google Analytics helps us to retarget users and reach them with relevant ads based on their previous interactions with our website.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the targeted addressing of users through personalized advertising. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in increasing the effectiveness of our marketing campaigns and the targeting of advertising.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://support.google.com.
Google Tag Manager is a tag management system from Google LLC that allows websites and app operators to easily implement and manage tags for web analytics and marketing optimization tools without having to change the source code of their websites or apps. Tags are small snippets of code that are used to analyze website data, understand user behavior, and monitor the effectiveness of online marketing campaigns. Google Tag Manager supports the integration of a variety of tags, including Google Analytics, Google Ads and many third-party tags.
The service allows users to manage and trigger tags that can collect data. This data is processed and stored by the respective tags and not by the Google Tag Manager.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Google Tag Manager is to simplify tag implementation and tag management. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in optimizing and increasing the efficiency of tag management and the associated web analysis and marketing activities.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Tag Manager can be found at https://policies.google.com/privacy.
Microsoft Advertising is an advertising platform that enables us to place online advertisements and optimize the performance of our advertising measures. By using Microsoft Advertising, personal data such as IP addresses, interaction data and information about websites visited are processed. This data helps us to show our ads to relevant users in a targeted manner and to analyze the performance of the campaigns. Microsoft uses this data to improve the display results and present targeted advertising based on user interactions. This precise targeting enables us to optimize our marketing strategies and increase conversion rates.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to improve targeting and advertising campaign performance. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in efficient and targeted advertising and the improvement of campaign effectiveness.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://ads.microsoft.com/.
Instagram is a widely used social network that allows users to share photos and videos, post stories, and interact with followers and friends. Instagram offers a variety of features, including direct messages, IGTV for longer videos, Instagram Live for real-time broadcasts and a Discover page to find added content and users.
When using Instagram, Personal Data such as names, email addresses, telephone numbers, user content (photos, videos, comments, etc.), location data, usage information and, in certain cases, payment information is processed. This data helps to provide the service, ensure the security of the platform, offer personalized advertising, and improve the user experience.
The company that operates the service and thus the recipient of personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the social network functions. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, where our legitimate interest lies in the improvement and personalization of the user experience, the provision of customer support and ensuring the security and integrity of the platform, as well as in the use of the platform and marketing.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Instagram can be viewed at https:// instagram.com.
LinkedIn is a social network for professional contacts and career development. The platform allows users to create a professional profile, network with colleagues, business partners and potential employers, share professional experiences and skills, and keep up to date with industry news. LinkedIn also provides tools for companies and recruiters to source talent, post job ads and build a brand presence.
When using LinkedIn, Personal Data such as names, email addresses, professional titles and experience, educational background, skills, interests, and platform usage data are processed. This information is necessary to provide and use the service to create networking opportunities, to present personalized content and job offers and to ensure the security of user data.
The company that operates the service and thus the recipient of the Personal Data is: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of network and career services. Processing is based on the Consent of the user (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as marketing and recruitment.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of LinkedIn Corporation can be found at https://www.linkedin.com.
X (formerly known as Twitter) is a global platform for public self-expression and real-time conversation. Users can create and share short messages, called tweets, which can include text, images, videos, and links. The platform allows users to follow breaking news, interact with others and participate in global discussions.
When using X, several types of Personal Data are processed, including usernames, email addresses, telephone numbers and location data. This information can be used for account creation, personalization of content, provision of advertising, security purposes and for analytical evaluations.
The company that operates the service and thus the recipient of personal data is: X Corp., 865 FM-1209, Building 2, Bastrop, TX 78602, USA. For data subjects in the EU and EEA, X Internet Unlimited Company, 1 Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: X Schweiz GmbH, c/o Wasag Treuhand AG, Normannenstrasse 8, 3018 Bern, Switzerland.
The Processing of Personal Data takes place, among other things, on the basis of the user's Consent (Art. 6 (1) (a) GDPR), for the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is a party, or on the basis of legitimate interests (Art. 6 (1) (f) GDPR), such as the use of the platform and the improvement of communication with the public.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of X can be found at https://twitter.com/.
YouTube is a video sharing and viewing platform used by individuals, artists, businesses, and media companies to publish a variety of content such as music videos, vlogs, educational material and much more. YouTube offers users the ability to upload, share, comment and interact with a broad community.
When using YouTube, Personal Data such as IP addresses, user interactions (e.g., videos viewed, comments), location data (if enabled for services) and information from linked Google accounts are processed. This information is required to provide personalized content and advertising, enable user interactions, keep the platform secure and improve the user experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of the video sharing services. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient video platform, the improvement of the user experience, the use of personalized advertising and the use of embedded videos on our website.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of YouTube can be found at https://policies.google.com.
The creation of this privacy policy was done with the help of a generator developed in cooperation with legal advisors for contract law, specialists in data protection auditing and the accredited certification body.
© 2026 interactive scape GmbH
Wilhelmine-Gemberg-Weg 6, 10179 Berlin
contact@interactive-scape.com
+49 30 69 80 94 - 100